๐บ๐ธ
TPI-Abuse
2026-05-01 17:20:42
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 45.66.209.36 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 45.66.209.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 01 13:20:38.565539 2026] [security2:error] [pid 31276:tid 31276] [client 45.66.209.36:29643] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||naominixon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "naominixon.com"] [uri "/wp-json/wp/v2/users"] [unique_id "afTg5miRcf0U7_5gUk6N5QAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-05-01 11:52:21
(1 month ago)
Web password guessing
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-04-29 00:14:06
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 45.66.209.36 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 45.66.209.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 20:13:58.475154 2026] [security2:error] [pid 18632:tid 18632] [client 45.66.209.36:30947] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||stormwlf.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "stormwlf.com"] [uri "/wp-json/wp/v2/users"] [unique_id "afFNRlHetXQREPp5_l4F0AAAAAM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-04-18 03:44:37
(1 month ago)
WordPress login attempt
Brute-Force
๐ซ๐ท
masterguru
2025-12-04 07:14:41
(6 months ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 45.66.209.36 (US/United States/-): 1 in the la ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 45.66.209.36 (US/United States/-): 1 in the last 3600 secs (0-196)
show less
Hacking
๐ซ๐ท
masterguru
2025-11-28 02:55:07
(6 months ago)
(FolderList) Hacking file access attemp in wordpress site from 45.66.209.36 (US/United States/-): 1 ...
show more
(FolderList) Hacking file access attemp in wordpress site from 45.66.209.36 (US/United States/-): 1 in the last 3600 secs (0-195)
show less
Hacking
๐จ๐ญ
backslash
2025-06-19 21:25:06
(11 months ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
๐ฎ๐ณ
wizard1411
2025-05-30 10:36:10
(1 year ago)
DDoS and brute force activity detected
Brute-Force
SSH
๐ฎ๐ณ
wizard1411
2025-05-30 10:36:10
(1 year ago)
DDoS and brute force activity detected
Brute-Force
SSH
๐ฎ๐ณ
wizard1411
2025-05-30 10:36:10
(1 year ago)
DDoS and brute force activity detected
Brute-Force
SSH
๐ฎ๐ณ
wizard1411
2025-05-30 10:36:10
(1 year ago)
DDoS and brute force activity detected
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-05-06 05:20:18
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 45.66.209.36 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.66.209.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 06 01:20:12.707489 2025] [security2:error] [pid 621210:tid 621210] [client 45.66.209.36:22841] [client 45.66.209.36] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Steelcase/pics/STLC-674791/JPEG (300 dpi)/Thumbs.db"] [unique_id "aBmcDL0kw89BXMe8x_aF3wAAAAA"], referer: https://vitalitywebb.com/backstore/Steelcase/pics/STLC-674791/JPEG%20(300%20dpi)/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2024-12-14 21:02:05
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-11-10 17:07:44
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 45.66.209.36 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.66.209.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 10 12:07:41.333171 2024] [security2:error] [pid 2351753:tid 2351753] [client 45.66.209.36:42797] [client 45.66.209.36] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Golden-Technologies/pics/Golden Technologies 2009 Marketing CD/Scooters/Avenger- 4 Wheel/Thumbs.db"] [unique_id "ZzDoXR3Ik4divV6sWqG-fAAAAA4"], referer: https://vitalitywebb.com/backstore/Golden-Technologies/pics/Golden%20Technologies%202009%20Marketing%20CD/Scooters/Avenger-%204%20Wheel/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-10-21 09:04:26
(1 year ago)
This IP was involved in an brute force and password spray attack on 2024/10/21 04:00:46
Port Scan
Brute-Force
Exploited Host
Web App Attack