π¬π§
Apache
2026-06-12 22:26:51
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 45.56.121.237 (US/United States/server2.buildin ...
show more
(mod_security) mod_security (id:225170) triggered by 45.56.121.237 (US/United States/server2.buildingbrandsmarketing.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-12 16:47:56
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 45.56.121.237 (server2.buildingbrandsmarketing. ...
show more
(mod_security) mod_security (id:225170) triggered by 45.56.121.237 (server2.buildingbrandsmarketing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 12:47:52.885100 2026] [security2:error] [pid 22311:tid 22311] [client 45.56.121.237:46644] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.intrinsicdiscovery.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.intrinsicdiscovery.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiw4OElPHLb0ogZ8Yo1aGAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-12 16:31:42
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 45.56.121.237 (server2.buildingbrandsmarketing. ...
show more
(mod_security) mod_security (id:225170) triggered by 45.56.121.237 (server2.buildingbrandsmarketing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 12:31:37.986408 2026] [security2:error] [pid 18827:tid 18827] [client 45.56.121.237:57888] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.havenlaneministries.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.havenlaneministries.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiw0aRTz0_8IK4fBfgsd3AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΉπ·
ycoskun41
2026-06-12 10:07:54
(1 day ago)
fail2ban: plesk-modsecurity jail on genckocaeli.com
Web App Attack
π³π±
debestelapp
2026-06-12 01:05:03
(2 days ago)
Exploited Host
πΊπΈ
TPI-Abuse
2026-06-11 16:48:33
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 45.56.121.237 (server2.buildingbrandsmarketing. ...
show more
(mod_security) mod_security (id:225170) triggered by 45.56.121.237 (server2.buildingbrandsmarketing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 12:48:26.500858 2026] [security2:error] [pid 31726:tid 31726] [client 45.56.121.237:42178] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.soundtrax.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.soundtrax.net"] [uri "/wp-json/wp/v2/users"] [unique_id "airm2qUhgFCGMUZEbmJIogAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-11 12:34:29
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 45.56.121.237 (server2.buildingbrandsmarketing. ...
show more
(mod_security) mod_security (id:225170) triggered by 45.56.121.237 (server2.buildingbrandsmarketing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 08:34:22.215165 2026] [security2:error] [pid 4990:tid 4990] [client 45.56.121.237:59090] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||stacyfarm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "stacyfarm.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiqrTpt1f4lTlMFDKwO1YAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
NicoID
2026-04-20 00:11:32
(1 month ago)
45.56.121.237 - - [19/Apr/2026:16:03:50 -0600] "POST /xmlrpc.php HTTP/1.1" 200 3071 "-" "Mozilla/5.0 ...
show more
45.56.121.237 - - [19/Apr/2026:16:03:50 -0600] "POST /xmlrpc.php HTTP/1.1" 200 3071 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36"
...
show less
Brute-Force
π·π΄
INTEQ
2026-04-15 16:21:53
(1 month ago)
Web attack from 45.56.121.237
Web App Attack
π§πΎ
lns.bz
2026-04-14 07:16:18
(2 months ago)
Banned for trying to access xmlrpc [BY]
Web App Attack
π·π΄
INTEQ
2026-04-13 22:52:31
(2 months ago)
Web attack from 45.56.121.237
Web App Attack
πΊπΈ
NicoID
2026-04-05 00:17:35
(2 months ago)
45.56.121.237 - - [04/Apr/2026:03:30:24 -0600] "POST /xmlrpc.php HTTP/1.1" 200 444 "-" "Mozilla/5.0 ...
show more
45.56.121.237 - - [04/Apr/2026:03:30:24 -0600] "POST /xmlrpc.php HTTP/1.1" 200 444 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.43 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 OPR/122.0.0.0"
...
show less
Brute-Force
πΊπΈ
n2nguyenn2nguyen
2026-04-04 04:36:44
(2 months ago)
Blocked by YFC Security on https://brixzly.com β type: xmlrpc_attempts
Brute-Force
Web App Attack
π«π·
masterguru
2026-04-03 06:44:33
(2 months ago)
wp-login request blocked, no referer. Pattern match "wp-login.php" at REQUEST_URI. (88020-197)
Hacking
π²πΉ
Malta
2026-04-02 13:06:42
(2 months ago)
45.56.121.237 - - [02/Apr/2026:15:06:41 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows N ...
show more
45.56.121.237 - - [02/Apr/2026:15:06:41 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack