๐ฎ๐น
VHosting
2026-08-24 16:00:10
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฉ๐ช
london2038.com
2026-08-24 13:28:43
(1 day ago)
Attacking WordPress
45.3.52.220 - - [24/Aug/2026:15:28:39 +0200] "POST /xmlrpc.php HTTP/1.1" 503 189 ...
show more
Attacking WordPress
45.3.52.220 - - [24/Aug/2026:15:28:39 +0200] "POST /xmlrpc.php HTTP/1.1" 503 18967 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Safari/605.1.15"
show less
Brute-Force
Web App Attack
๐ซ๐ท
Sklurk
2026-08-01 01:09:05
(3 weeks ago)
Web App Attack
Web App Attack
๐บ๐ธ
kbeezie
2026-05-06 03:37:46
(3 months ago)
2026/05/05 23:35:37 [error] 3375476#3375476: *6159 access forbidden by rule, client: 45.3.52.220, se ...
show more
2026/05/05 23:35:37 [error] 3375476#3375476: *6159 access forbidden by rule, client: 45.3.52.220, server: tmp.vangodelivery.com, request: "GET /info.php.bak HTTP/1.1", host: "tmp.vangodelivery.com"
2026/05/05 23:36:39 [error] 3375476#3375476: *6159 access forbidden by rule, client: 45.3.52.220, server: tmp.vangodelivery.com, request: "GET /bootstrap/.env HTTP/1.1", host: "tmp.vangodelivery.com"
2026/05/05 23:37:45 [error] 3375476#3375476: *6159 access forbidden by rule, client: 45.3.52.220, server: tmp.vangodelivery.com, request: "GET /pictures/.env HTTP/1.1", host: "tmp.vangodelivery.com"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-02-19 02:05:16
(6 months ago)
Too many Status 40X (12)
Scanning/Probing (12)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 20:23:14
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.52.220 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.52.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 15:23:09.665544 2026] [security2:error] [pid 21291:tid 21291] [client 45.3.52.220:64623] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "treadbox.net"] [uri "/api/.git/config"] [unique_id "aZYfrW-XOX22_D3_ZjxVRwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 12:43:21
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.52.220 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.52.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 07:43:17.720187 2026] [security2:error] [pid 11479:tid 11479] [client 45.3.52.220:47155] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "weirdlovemakers.com"] [uri "/app/.git/config"] [unique_id "aZWz5dXpe1BvHkYIDw5Z2AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-01-19 18:30:06
(7 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
Anonymous
2025-11-02 22:06:54
(9 months ago)
This IP was involved in an brute force and password spray attack on 2025/11/02 07:23:26
Port Scan
Brute-Force
Exploited Host
Web App Attack
Anonymous
2025-10-16 12:21:20
(10 months ago)
WordPress Brute Force
Brute-Force
๐ฎ๐น
Progetto1
2025-03-15 08:30:02
(1 year ago)
Mail - Multiple failed login attempts
Brute-Force
Exploited Host
๐บ๐ธ
TPI-Abuse
2025-03-10 06:10:49
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.3.52.220 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 45.3.52.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 10 02:10:42.192660 2025] [security2:error] [pid 23674:tid 23674] [client 45.3.52.220:28525] [client 45.3.52.220] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||indoorsfinishing.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "indoorsfinishing.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z86CYpAPbmqcAN-VJnTK3AAAAA8"], referer: https://indoorsfinishing.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-18 12:49:06
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.3.52.220 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 45.3.52.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 18 07:49:01.707914 2025] [security2:error] [pid 3491:tid 3491] [client 45.3.52.220:11945] [client 45.3.52.220] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sarcd.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sarcd.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z7SBvYixwNUhJ51j8_hfuAAAABs"], referer: https://sarcd.com
show less
Brute-Force
Bad Web Bot
Web App Attack