🇭🇺
bcsaba
2026-08-30 18:05:07
(19 minutes ago)
CMS (WordPress or Joomla) login attempt.
45.3.38.143 - - [30/Aug/2026:20:05:04 +0200] "POST /wp-logi ...
show more
CMS (WordPress or Joomla) login attempt.
45.3.38.143 - - [30/Aug/2026:20:05:04 +0200] "POST /wp-login.php HTTP/1.1" 200 3503 "https://*REDACTED*/wp-login.php" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
show less
Hacking
Brute-Force
Web App Attack
🇩🇪
F242
2026-08-29 19:48:43
(22 hours ago)
Wordpress Login or XMLRPC abuse
Web App Attack
Anonymous
2026-08-29 05:45:31
(1 day ago)
Network service scanning detected by FortiGate; source quarantined.
Port Scan
🇫🇷
ELYAZ
2026-08-28 19:09:47
(1 day ago)
(wordpress) Failed wordpress login from 45.3.38.143 (US/United States/-): (CF_ENABLE)
Brute-Force
🇮🇹
VHosting
2026-08-28 17:30:04
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇩🇪
F242
2026-08-28 13:14:06
(2 days ago)
Wordpress Login or XMLRPC abuse
Web App Attack
🇫🇷
Sklurk
2026-07-08 01:33:13
(1 month ago)
Web App Attack
Web App Attack
🇪🇸
masterguru
2026-03-27 02:17:53
(5 months ago)
Restricted File Access Attempt. Matched phrase "/.git/" at REQUEST_FILENAME. (930130-122)
Hacking
Web App Attack
🇦🇺
2000cn.com.au
2026-02-11 21:04:20
(6 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Hacking
Web App Attack
🇳🇱
jjnxpct
2026-02-11 04:52:57
(6 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /.env.save (Rule ID: 920440) - URL file extension is restricted by policy
show less
Hacking
SQL Injection
Web App Attack
🇳🇱
homeshowdomain.nl
2026-02-10 22:59:43
(6 months ago)
Auto-ban: >3000 req/min op 2026-02-10
Hacking
Web App Attack
SSH
🇺🇸
TPI-Abuse
2026-02-10 17:12:51
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.38.143 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.38.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 12:12:43.604494 2026] [security2:error] [pid 9447:tid 9447] [client 45.3.38.143:9159] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "18mstudio.com"] [uri "/new/.git/config"] [unique_id "aYtnC1TNcq3Ao3WcuxgWiAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mind5t0rm
2026-02-10 16:56:18
(6 months ago)
(WPLOGIN) WP Login Attack 45.3.38.143 (US/United States/-): 3 in the last 3600 secs; Ports: *; Direc ...
show more
(WPLOGIN) WP Login Attack 45.3.38.143 (US/United States/-): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: 45.3.38.143 - - [10/Feb/2026:23:56:06 +0700] "GET /wp-login.php HTTP/2.0" 200 2454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:127.0) Gecko/20100101 Firefox/127.0"
45.3.38.143 - - [10/Feb/2026:23:56:11 +0700] "GET /wp-login.php?wp_lang=en_US HTTP/2.0" 200 2454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.6367.207 Safari/537.36"
45.3.38.143 - - [10/Feb/2026:23:56:16 +0700] "POST /wp-login.php?wp_lang=en_US HTTP/2.0" 302 0 "https://zerowaterthailand.com/wp-login.php?wp_lang=en_US" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.6367.207 Safari/537.36"
show less
Port Scan
🇳🇱
ParaBug
2026-02-10 15:32:53
(6 months ago)
45.3.38.143 - - [10/Feb/2026:16:32:52 +0100] "GET /test/.git/config HTTP/1.1" 301 557 "-" "Mozilla/5 ...
show more
45.3.38.143 - - [10/Feb/2026:16:32:52 +0100] "GET /test/.git/config HTTP/1.1" 301 557 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Phishing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-02-10 05:03:10
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.38.143 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.38.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 00:02:55.129124 2026] [security2:error] [pid 15343:tid 15343] [client 45.3.38.143:53833] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "idledog.com"] [uri "/v2/.git/config"] [unique_id "aYq7_9KT2lJEaWIEpJeSlwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack