Anonymous
2026-03-20 18:06:13
(5 months ago)
Trying to access config files
Web App Attack
Anonymous
2026-03-04 21:35:29
(5 months ago)
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show more
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in printer-friendly.asp
show less
Exploited Host
Bad Web Bot
๐จ๐ฟ
ddw
2025-11-11 06:51:05
(9 months ago)
WordPress XMLRPC.PHP Access Attempt.
Hacking
Web App Attack
Anonymous
2025-11-11 03:12:29
(9 months ago)
xmlrpc.php trap
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-10 07:33:11
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 45.181.58.112 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.181.58.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 10 02:33:07.926938 2025] [security2:error] [pid 15845:tid 15868] [client 45.181.58.112:46259] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||maryschalkdesign.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "maryschalkdesign.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aRGVM9jhqJ0My_9BsN5Z1gAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-09 18:42:02
(9 months ago)
(wordpress) Failed wordpress login from 45.181.58.112 (BR/Brazil/Sรฃo Paulo/Campinas/-/[redacted])
Brute-Force
๐ฉ๐ช
rh24
2025-11-08 15:33:01
(9 months ago)
(wordpress) Failed wordpress login from 45.181.58.112 (BR/Brazil/-): (CF_ENABLE)
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-11-08 15:19:22
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 45.181.58.112 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.181.58.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 08 10:19:19.114725 2025] [security2:error] [pid 27321:tid 27321] [client 45.181.58.112:45790] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||alpha-hk.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "alpha-hk.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQ9fdw2ACbOrhaLgTVquBwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
stinpriza
2025-11-08 03:52:22
(9 months ago)
Web App Attack
Web App Attack
Anonymous
2025-11-08 03:13:36
(9 months ago)
[redacted] 45.181.58.112 - - [08/Nov/2025:04:12:16 +0100] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "M ...
show more
[redacted] 45.181.58.112 - - [08/Nov/2025:04:12:16 +0100] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; x86) AppleWebKit/537.36 (KHTML, like Gecko) Safari/12.0.0.0 Safari/537.36"
[redacted] 45.181.58.112 - - [08/Nov/2025:04:12:17 +0100] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Mozilla/5.0 (Linux; Android 10; x86) AppleWebKit/537.36 (KHTML, like Gecko) Edge/89.0.0.0 Safari/537.36"
[redacted] 45.181.58.112 - - [08/Nov/2025:04:13:33 +0100] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Mozilla/5.0 (Linux; Android 10; x64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/76.0.0.0 Safari/537.36"
[redacted] 45.181.58.112 - - [08/Nov/2025:04:13:34 +0100] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Mozilla/5.0 (Windows NT 10.0; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36"
[redacted] 45.181.58.112 - - [08/Nov/2025:04:13:35 +0100] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Mozilla/5.0 (Windows NT 6.3; arm64
...
show less
Hacking
Web App Attack
๐จ๐ญ
rt
2025-11-07 18:11:17
(9 months ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-07 05:28:00
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 45.181.58.112 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.181.58.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 07 00:27:56.784582 2025] [security2:error] [pid 24460:tid 24460] [client 45.181.58.112:45469] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||feiz.church|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "feiz.church"] [uri "/wp-json/wp/v2/users"] [unique_id "aQ2DXBBRRCm5It7GExnQ8wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-06 23:26:22
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 45.181.58.112 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.181.58.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 06 18:26:17.808604 2025] [security2:error] [pid 8553:tid 8553] [client 45.181.58.112:46122] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cosplayculture.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cosplayculture.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQ0umT6RVLSNy7BH1eDTnQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-06 09:12:06
(9 months ago)
(wordpress) Failed wordpress login from 45.181.58.112 (BR/Brazil/-)
Brute-Force
๐ฎ๐น
mgarofano80
2025-11-06 09:03:51
(9 months ago)
Brute-Force
Web App Attack