|
๐ซ๐ท
tilellit.pro
|
|
Fail2Ban banned 45.159.22.193 for security violations in jail wp-armour. Log: 2026/05/02 19:03:19 [e ...
show more
Fail2Ban banned 45.159.22.193 for security violations in jail wp-armour. Log: 2026/05/02 19:03:19 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 45.159.22.193 | Target: wplogin" , client: 45.159.22.193, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
|
Web Spam
|
|
|
๐จ๐ญ
backslash
|
|
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
|
Bad Web Bot
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 45.159.22.193 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.159.22.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 16:41:52.893327 2026] [security2:error] [pid 20138:tid 20138] [client 45.159.22.193:29763] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||primacomm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "primacomm.com"] [uri "/wp-json/wp/v2/users"] [unique_id "afEbkBDT7yyTW8-cxDNouQAAAAE"], referer: https://www.google.com
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 45.159.22.193 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.159.22.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 00:56:07.730202 2026] [security2:error] [pid 24474:tid 24474] [client 45.159.22.193:47633] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fitzmail.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fitzmail.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ab4k5zsIwVKBQIzDrHxVrQAAAAQ"], referer: https://www.google.com
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฌ๐ง
Bytemark
|
|
45.159.22.193 - - [17/Mar/2026:22:52:11 +0000] "POST /xmlrpc.php HTTP/1.1" 404 47 "-" "curl/8.6.0"
4 ...
show more
45.159.22.193 - - [17/Mar/2026:22:52:11 +0000] "POST /xmlrpc.php HTTP/1.1" 404 47 "-" "curl/8.6.0"
45.159.22.193 - - [17/Mar/2026:22:52:11 +0000] "POST /xmlrpc.php HTTP/1.1" 404 47 "-" "curl/7.88.1"
45.159.22.193 - - [17/Mar/2026:22:52:12 +0000] "POST /xmlrpc.php HTTP/1.1" 404 47 "-" "curl/8.6.0"
show less
|
Brute-Force
Web App Attack
|
|
|
๐ณ๐ฟ
Tripwire
|
|
Wordpress login attempts
|
Brute-Force
Web App Attack
|
|
|
Anonymous
|
|
Attempted WordPress login:
45.159.22.193 - - [28/Dec/2025:07:54:43 +0000] "GET /wp-login.php HTTP/1 ...
show more
Attempted WordPress login:
45.159.22.193 - - [28/Dec/2025:07:54:43 +0000] "GET /wp-login.php HTTP/1.1" 200 234 "http://[sub domain]/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:138.0) Gecko/20100101 Firefox/138.0"
show less
|
Hacking
Web App Attack
|
|
|
๐ฎ๐น
VHosting
|
|
Detected WordPress attack from 4 different servers
|
Brute-Force
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 45.159.22.193 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.159.22.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 06:11:19.437752 2025] [security2:error] [pid 6675:tid 6675] [client 45.159.22.193:56943] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.stalbansparish.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.stalbansparish.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "aU--136a-kEf3UWS7AFUrwAAABY"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฉ๐ช
mxbl
|
|
Scanning for CMS vulnerabilities on a non-CMS system: /wp-login.php
|
Web App Attack
|
|
|
Anonymous
|
|
[26/Dec/2025:10:59:46 +1100] "GET /wp-login.php HTTP/1.1" 301 293 "Mozilla/5.0 (Windows NT 10.0; Win ...
show more
[26/Dec/2025:10:59:46 +1100] "GET /wp-login.php HTTP/1.1" 301 293 "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:138.0) Gecko/20100101 Firefox/138.0"
show less
|
Hacking
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 45.159.22.193 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.159.22.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 25 11:33:00.670709 2025] [security2:error] [pid 23508:tid 23508] [client 45.159.22.193:35381] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.idmadventures.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.idmadventures.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aU1nPK7cEZCwV8Y2W-Bd_AAAAAU"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 45.159.22.193 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.159.22.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 24 09:20:09.403918 2025] [security2:error] [pid 31887:tid 31887] [client 45.159.22.193:22763] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.manaplas.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.manaplas.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aUv2mQFD-WSbOFLUxlmKkQAAAAw"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฉ๐ช
Packets-Decreaser.NET
|
|
Incoming Layer 7 Flood Detected
|
DDoS Attack
Web Spam
|
|
|
๐บ๐ธ
dot.mg
|
|
"Russian spam"
|
Web Spam
Blog Spam
|
|