Anonymous
2026-04-23 23:41:19
(1 month ago)
Automated bot traffic โ residential proxy, fake browser fingerprint. UA="Mozilla/5.0 (X11; CrOS x86_ ...
show more
Automated bot traffic โ residential proxy, fake browser fingerprint. UA="Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
Anonymous
2026-04-09 04:06:26
(1 month ago)
Forum/form spam
Web Spam
๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(2 months ago)
"DDoS against public endpoint"
DDoS Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 05:14:46
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.51.216 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.51.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:14:37.829309 2025] [security2:error] [pid 3965258:tid 3965279] [client 45.3.51.216:60165] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.truthjusticecommission.com"] [uri "/.svn/wc.db"] [unique_id "aSPpvchgZFlRjqvFboiDNgAAAQg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-14 00:21:13
(6 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐ฉ๐ช
kjaerulff
2025-11-06 16:40:06
(6 months ago)
Failed Wordpress login using xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-06 14:40:28
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 45.3.51.216 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 45.3.51.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 06 09:40:23.198544 2025] [security2:error] [pid 9569:tid 9569] [client 45.3.51.216:43355] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||silsby.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "silsby.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQyzV6RTncD5xp5ijeGnPgAAABM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-06 13:48:13
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 45.3.51.216 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 45.3.51.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 06 08:48:08.374398 2025] [security2:error] [pid 31435:tid 31435] [client 45.3.51.216:13943] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||towardthesky.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "towardthesky.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQynGGkdwRNayWoFizga_gAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-06 10:50:14
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 45.3.51.216 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 45.3.51.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 06 05:50:10.975408 2025] [security2:error] [pid 8002:tid 8002] [client 45.3.51.216:48885] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tanny.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tanny.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQx9Yl3mnV0a0ii1fEcY5gAAABs"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-06 10:05:40
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 45.3.51.216 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 45.3.51.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 06 05:05:35.107833 2025] [security2:error] [pid 3669:tid 3669] [client 45.3.51.216:13377] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||puoci.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "puoci.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQxy75olVRGcp35cRCi54QAAABU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2025-11-04 16:29:33
(7 months ago)
Web App Attack
Anonymous
2025-11-02 20:09:35
(7 months ago)
This IP was involved in an brute force and password spray attack on 2025/11/02 06:56:46
Port Scan
Brute-Force
Exploited Host
Web App Attack
Anonymous
2025-11-01 22:50:19
(7 months ago)
[redacted] 45.3.51.216 - - [01/Nov/2025:23:49:59 +0100] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" "Moz ...
show more
[redacted] 45.3.51.216 - - [01/Nov/2025:23:49:59 +0100] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
[redacted] 45.3.51.216 - - [01/Nov/2025:23:50:02 +0100] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_2_6 like Mac OS X) AppleWebKit/604.5.6 (KHTML, like Gecko) Version/11.0 Mobile/15D100 Safari/604.1"
[redacted] 45.3.51.216 - - [01/Nov/2025:23:50:05 +0100] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_5_6; en-us) AppleWebKit/525.27.1 (KHTML, like Gecko) Version/3.2.1 Safari/525.27.1"
[redacted] 45.3.51.216 - - [01/Nov/2025:23:50:07 +0100] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" "Mozilla/5.0 (Linux; Android 5.0.1; ALE-L23 Build/HuaweiALE-L23) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Mobile Safari/537.36"
[redacted] 45.3.51.216 - - [01/Nov/2025:23:50:09 +0100] "POST /xmlr
...
show less
Hacking
Web App Attack
๐ฆ๐บ
AWW-Admin
2025-10-29 14:01:04
(7 months ago)
(wordpress) Failed wordpress login from 45.3.51.216 (US/United States/-)
Brute-Force
Anonymous
2025-10-18 08:40:41
(7 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.18 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.18 is noted in report timestamp
show less
Hacking
Brute-Force