π¨π
Origon
2026-05-19 19:42:52
(2 weeks ago)
http-bad-user-agent - IP: 45.66.209.243 - time="2026-05-19T21:42:52+02:00" level=info msg="(555f66b ...
show more
http-bad-user-agent - IP: 45.66.209.243 - time="2026-05-19T21:42:52+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-bad-user-agent by ip 45.66.209.243 (RU/35830) : 4h ban on Ip 45.66.209.243" module=db
show less
Bad Web Bot
πͺπΈ
el-brujo
2026-02-05 13:35:47
(4 months ago)
Cloudflare WAF: Request Path: /xmlrpc.php Request Query: Host: foro.elhacker.net userAgent: Mozilla ...
show more
Cloudflare WAF: Request Path: /xmlrpc.php Request Query: Host: foro.elhacker.net userAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:146.0) Gecko/20100101 Firefox/146.0 Action: managed_challenge Source: firewallManaged ASN Description: BTTGROUP-AS Country: US Method: POST Timestamp: 2026-02-05T13:35:47Z ruleId: 5de7edfa648c4d6891dc3e7f84534ffa. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
πͺπΈ
el-brujo
2026-02-04 12:26:10
(4 months ago)
Cloudflare WAF: Request Path: /xmlrpc.php Request Query: Host: foro.elhacker.net userAgent: Mozilla ...
show more
Cloudflare WAF: Request Path: /xmlrpc.php Request Query: Host: foro.elhacker.net userAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:146.0) Gecko/20100101 Firefox/146.0 Action: managed_challenge Source: firewallManaged ASN Description: BTTGROUP-AS Country: US Method: POST Timestamp: 2026-02-04T12:26:10Z ruleId: 5de7edfa648c4d6891dc3e7f84534ffa. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-22 16:24:33
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 45.66.209.243 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.66.209.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 11:24:26.926603 2026] [security2:error] [pid 32756:tid 32756] [client 45.66.209.243:13739] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||eta-mct.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "eta-mct.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "aXJPOr5PkUnT4ZVIQzpn6wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
Audir8 | RRHosting
2026-01-01 21:58:28
(5 months ago)
Triggered Cloudflare WAF (securitylevel) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/2 ( ...
show more
Triggered Cloudflare WAF (securitylevel) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/2 (GET method)
Endpoint: /auth/login
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:142.0) Gecko/20100101 Firefox/142.0
This report is using Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π©πͺ
Packets-Decreaser.NET
2025-12-10 14:34:34
(5 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
π§πͺ
voormedia
2025-08-20 01:00:41
(9 months ago)
Accessed trap at '/xmlrpc.php'
Web App Attack
Anonymous
2025-08-19 23:08:28
(9 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
π«π·
rellik
2025-08-19 22:26:00
(9 months ago)
POST on Critical File, Potential Part of BotNet
DDoS Attack
Hacking
Web App Attack
Anonymous
2025-08-15 01:27:49
(9 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
πΊπΈ
ne1for23
2025-03-28 19:08:03
(1 year ago)
45.66.209.243 - - [28/Mar/2025:19:08:03 +0000] "GET /wp-login.php HTTP/1.1" 403 555 "-" "Mozilla/5.0 ...
show more
45.66.209.243 - - [28/Mar/2025:19:08:03 +0000] "GET /wp-login.php HTTP/1.1" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36 Edg/115.0.1901.203"
show less
Web App Attack
Anonymous
2025-03-14 17:47:09
(1 year ago)
wordpress-trap
Web App Attack
π·πΊ
sms.ru
2024-09-22 10:20:07
(1 year ago)
SMS pumping attack from foreign country
DDoS Attack
π©πͺ
Admins@FBN
2024-06-11 02:14:13
(1 year ago)
VPN Logon Failed: AAA user authentication Rejected user = <print>
Brute-Force
Exploited Host
πΊπΈ
hostseries
2024-05-02 02:03:13
(2 years ago)
Trigger: LF_DISTATTACK
Brute-Force