๐ซ๐ท
j-tap
2026-10-04 09:34:13
(5 days ago)
WordPress honeypot: automated scanner (xmlrpc / installer / .env / direct login POST)
Web App Attack
๐ฆ๐บ
FEWA
2026-09-29 05:20:33
(1 week ago)
Fail2Ban Ban Triggered
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
koinkash.org
2026-08-23 11:19:55
(1 month ago)
They are fraudulent. Malicious threat actor requesting php file /wp-login.php
Web App Attack
๐ฉ๐ช
conseilgouz
2026-08-22 10:36:23
(1 month ago)
vee-6 : Trying access system files=>/wp-login.php(wp-login.php)
Hacking
๐ฑ๐ป
garmtech.com
2026-07-31 11:20:05
(2 months ago)
IM360 WAF: WordPress wp2shell REST batch endpoint before 7.0.2 or 6.9.5 (CVE-2026-63030) MV:0
Hacking
๐ช๐ธ
librebit
2026-06-24 03:30:49
(3 months ago)
RDWeb scan
Web App Attack
๐ฑ๐ป
garmtech.com
2026-03-30 06:21:08
(6 months ago)
IM360 WAF: WordPress plugin/theme auto install block
Web App Attack
Anonymous
2026-02-11 21:28:55
(7 months ago)
45.3.46.85 - - [11/Feb/2026:22:28:52 +0100] "GET /wp-login.php HTTP/1.1" 404 178 "https://www.google ...
show more
45.3.46.85 - - [11/Feb/2026:22:28:52 +0100] "GET /wp-login.php HTTP/1.1" 404 178 "https://www.google.com" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
45.3.46.85 - - [11/Feb/2026:22:28:53 +0100] "GET /wp-login.php HTTP/1.1" 404 178 "https://www.google.com" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-09 06:20:01
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.46.85 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.46.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 09 01:19:57.748845 2025] [security2:error] [pid 32020:tid 32020] [client 45.3.46.85:19789] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "swurgentvet.com"] [uri "/.svn/wc.db"] [unique_id "aTe_jTMSQ2xKy5yO7FF8YQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-08 10:41:30
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.46.85 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.46.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 08 05:41:27.276111 2025] [security2:error] [pid 11928:tid 11928] [client 45.3.46.85:35433] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shiverdigital.com"] [uri "/.git/HEAD"] [unique_id "aTarVxbX1fEUAoquz5ufVwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-07 18:12:18
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.46.85 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.46.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 13:12:13.965006 2025] [security2:error] [pid 14869:tid 14869] [client 45.3.46.85:14965] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "digbiellc.com"] [uri "/.env"] [unique_id "aTXDfV4rZKfGzhPAMgl-RgAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-06 12:59:42
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.46.85 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.46.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 06 07:59:39.078471 2025] [security2:error] [pid 11149:tid 11149] [client 45.3.46.85:53839] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "distilledwater.net"] [uri "/.svn/wc.db"] [unique_id "aTQouz4QrPRmKDCb_IzMdAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-05 11:38:44
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.46.85 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.46.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 06:38:37.166673 2025] [security2:error] [pid 20929:tid 20929] [client 45.3.46.85:25823] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sharawi-gum.com"] [uri "/.env"] [unique_id "aTLEPchG_mbmTtfmV7vSwwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-05 09:07:58
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.46.85 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.46.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 04:07:53.229378 2025] [security2:error] [pid 8156:tid 8199] [client 45.3.46.85:28513] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "billgiegold.com"] [uri "/.env"] [unique_id "aTKg6RvhP3RrMJs32ki-vgAAAY0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-05 08:12:52
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.46.85 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.46.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 03:12:50.310152 2025] [security2:error] [pid 24137:tid 24137] [client 45.3.46.85:60785] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "market1st.com"] [uri "/.env"] [unique_id "aTKUAsZDTZYScqI71KYaDAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack