Anonymous
2026-09-04 17:46:14
(2 days ago)
(caddyscan) Scanner path probe from 45.159.22.221 (DE/Germany/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 45.159.22.221 (DE/Germany/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 45.159.22.221 - - [04/Sep/2026:17:46:07 +0000] "POST /xmlrpc.php HTTP/1.1"
[REDACTED] 200 2627 45.159.22.221 - - [04/Sep/2026:17:46:07 +0000] "GET /wp-login.php HTTP/1.1"
[REDACTED] 200 2627 45.159.22.221 - - [04/Sep/2026:17:46:08 +0000] "GET /wp-login.php HTTP/1.1"
[REDACTED] 200 2627 45.159.22.221 - - [04/Sep/2026:17:46:10 +0000] "POST /xmlrpc.php HTTP/1.1"
[REDACTED] 200 2627 45.159.22.221 - - [04/Sep/2026:17:46:11 +0000] "GET /wp-login.php HTTP/1.1"
show less
Port Scan
🇺🇸
TRoden
2026-09-04 04:53:16
(3 days ago)
Geo Block Plugin: Escalation flag(s): rce_attempt
Hacking
🇧🇪
cmbplf
2026-08-24 08:08:26
(2 weeks ago)
191 querystring crawling (29m59s)
Brute-Force
Bad Web Bot
🇮🇹
VHosting
2026-08-18 21:30:06
(2 weeks ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-18 19:05:00
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 45.159.22.221 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.159.22.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 15:04:51.898355 2026] [security2:error] [pid 24872:tid 24872] [client 45.159.22.221:13489] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kennedysplace.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kennedysplace.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoSs03NX5rpCk7clb1lAwAAAAA0"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-08-17 19:49:47
(2 weeks ago)
Web password guessing
Brute-Force
Anonymous
2026-07-29 18:09:50
(1 month ago)
Fail2Ban - Nginx Bot Probes
Web App Attack
🇨🇦
DRI
2026-07-28 16:19:45
(1 month ago)
Web attack/Malicious activity detected
Web App Attack
🇬🇧
consul.to
2026-07-26 00:56:31
(1 month ago)
Web attack/malicious scanning detected
Web App Attack
🇩🇪
LRob
2026-07-17 14:47:35
(1 month ago)
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Apache-HttpClient/4.5.1 ...
show more
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Apache-HttpClient/4.5.13 (Java/17.0.18)
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-07-08 06:39:21
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 45.159.22.221 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.159.22.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 08 02:39:16.609299 2026] [security2:error] [pid 2374:tid 2374] [client 45.159.22.221:20565] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||yeswedeliver.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "yeswedeliver.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ak3wlBI7UHcLdOqIqBwFIgAAABM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Tilellit.PRO
2026-07-05 04:03:28
(2 months ago)
WP Armour Plugin detection
Web Spam
Brute-Force
🇫🇷
Tilellit.PRO
2026-06-29 12:01:15
(2 months ago)
Fail2Ban banned 45.159.22.221 for security violations in jail wp-armour. Log: 2026/06/29 12:01:15 [e ...
show more
Fail2Ban banned 45.159.22.221 for security violations in jail wp-armour. Log: 2026/06/29 12:01:15 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 45.159.22.221 | Target: wplogin" , client: 45.159.22.221, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
🇫🇷
Tilellit.PRO
2026-06-28 08:56:35
(2 months ago)
Fail2Ban banned 45.159.22.221 for security violations in jail wp-armour. Log: 2026/06/28 08:56:34 [e ...
show more
Fail2Ban banned 45.159.22.221 for security violations in jail wp-armour. Log: 2026/06/28 08:56:34 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 45.159.22.221 | Target: wplogin" , client: 45.159.22.221, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
🇫🇷
Tilellit.PRO
2026-06-27 12:49:55
(2 months ago)
Fail2Ban banned 45.159.22.221 for security violations in jail wp-armour. Log: 2026/06/27 12:49:54 [e ...
show more
Fail2Ban banned 45.159.22.221 for security violations in jail wp-armour. Log: 2026/06/27 12:49:54 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 45.159.22.221 | Target: wplogin" , client: 45.159.22.221, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam