๐ง๐ช
taivas.nl
2026-02-18 19:32:12
(3 months ago)
Wordpress_xmlrpc_attack
Bad Web Bot
๐จ๐ฆ
SSH-Admin
2026-02-07 17:12:28
(3 months ago)
Probing for Exploits
Exploited Host
Web App Attack
๐จ๐ฆ
SSH-Admin
2025-12-27 13:45:08
(5 months ago)
Probing for Exploits
Exploited Host
Web App Attack
๐ณ๐ฑ
GabrielJST
2025-12-23 05:12:33
(5 months ago)
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 45.3.32.245 (US/United S ...
show more
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 45.3.32.245 (US/United States/-)
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2025-11-02 03:46:43
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 45.3.32.245 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 45.3.32.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 01 23:46:36.496079 2025] [security2:error] [pid 21295:tid 21295] [client 45.3.32.245:44597] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||darrenpeck.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "darrenpeck.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQbUHOqAcpgRkZXAMJsxnQAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-02 02:33:42
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 45.3.32.245 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 45.3.32.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 01 22:33:35.887270 2025] [security2:error] [pid 22566:tid 22566] [client 45.3.32.245:17375] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kevinfranz.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kevinfranz.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQbC_00rapkn9w3JidLYrwAAABI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-02 01:44:44
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 45.3.32.245 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 45.3.32.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 01 21:44:41.104343 2025] [security2:error] [pid 3243:tid 3243] [client 45.3.32.245:52059] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||christianebooks.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "christianebooks.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQa3iWDXCibBOISfPyRFJQAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-01 23:29:31
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 45.3.32.245 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 45.3.32.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 01 19:29:24.396168 2025] [security2:error] [pid 17145:tid 17145] [client 45.3.32.245:14233] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||evelynkay.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "evelynkay.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQaX1DuAJEjngvAwhhBAJgAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-01 21:45:29
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 45.3.32.245 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 45.3.32.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 01 17:45:26.051404 2025] [security2:error] [pid 12588:tid 12588] [client 45.3.32.245:18199] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mcdevittlawfirm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mcdevittlawfirm.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQZ_dnvhGzaNE3zfekKo6gAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-29 01:18:23
(7 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
Anonymous
2025-10-18 05:02:52
(7 months ago)
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.10.18 is noted in report tim ...
show more
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.10.18 is noted in report timestamp
show less
Hacking
Brute-Force
๐จ๐ฆ
wil.com
2025-10-17 13:09:18
(7 months ago)
GlobalProtect login attempts with user buonomano.
VPN IP
Brute-Force
Anonymous
2025-10-17 12:50:03
(7 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.17 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.17 is noted in report timestamp
show less
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-10-14 22:00:17
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 45.3.32.245 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 45.3.32.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 14 18:00:04.056547 2025] [security2:error] [pid 25166:tid 25166] [client 45.3.32.245:29327] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||geckoturner.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "geckoturner.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aO7H5CjROb8vKZxlzZUAbQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
london2038.com
2025-10-13 04:45:50
(7 months ago)
Connection atttempts against closed TCP ports
Oct 13 06:45:47 BLOCK SRC=45.3.32.245 LEN=60 TOS=0x00 ...
show more
Connection atttempts against closed TCP ports
Oct 13 06:45:47 BLOCK SRC=45.3.32.245 LEN=60 TOS=0x00 PREC=0x00 TTL=54 ID=6447 DF PROTO=TCP SPT=20081 DPT=22 WINDOW=64240 RES=0x00 SYN
Oct 13 06:45:48 BLOCK SRC=45.3.32.245 LEN=60 TOS=0x00 PREC=0x00 TTL=54 ID=6448 DF PROTO=TCP SPT=20081 DPT=22 WINDOW=64240 RES=0x00 SYN
Oct 13 06:45:49 BLOCK SRC=45.3.32.245 LEN=60 TOS=0x00 PREC=0x00 TTL=54 ID=6449 DF PROTO=TCP SPT=20081 DPT=22 WINDOW=64240 RES=0x00 SYN
show less
Port Scan