๐บ๐ธ
TPI-Abuse
2026-07-23 05:29:43
(4 weeks ago)
(mod_security) mod_security (id:225170) triggered by 45.80.104.102 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.80.104.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 01:29:36.054104 2026] [security2:error] [pid 2042211:tid 2042211] [client 45.80.104.102:61225] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pardescommunications.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pardescommunications.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amGmwGQ52cFmzur3id57wgAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Major Hostility
2026-07-22 19:23:20
(1 month ago)
"POST /xmlrpc.php HTTP/1.1" 403
"GET /wp-login.php HTTP/1.1" 404
"GET /wp-login.php HTTP/1.1" 404
"G ...
show more
"POST /xmlrpc.php HTTP/1.1" 403
"GET /wp-login.php HTTP/1.1" 404
"GET /wp-login.php HTTP/1.1" 404
"GET /wp-json/wp/v2/users HTTP/1.1" 404
"POST /xmlrpc.php HTTP/1.1" 403
show less
Web App Attack
๐จ๐ฆ
electronico
2026-06-22 21:02:45
(2 months ago)
45.80.104.102 - - [23/Jun/2026:08:02:44 +1100] "POST /xmlrpc.php HTTP/1.1" 404 5866 "-" "Wget/1.21.4 ...
show more
45.80.104.102 - - [23/Jun/2026:08:02:44 +1100] "POST /xmlrpc.php HTTP/1.1" 404 5866 "-" "Wget/1.21.4"
...
show less
Brute-Force
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-05-25 09:45:10
(2 months ago)
[Mon May 25 19:45:08.610059 2026] [security2:error] [pid 114530] [client 45.80.104.102:63919] [clien ...
show more
[Mon May 25 19:45:08.610059 2026] [security2:error] [pid 114530] [client 45.80.104.102:63919] [client 45.80.104.102] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "levellagiftware.com.au"] [uri "/xmlrpc.php"] [unique_id "ahQaJClSgBMOXBlZyH45PQAAACw"]
...
show less
Web App Attack
๐ฎ๐น
VHosting
2026-03-26 20:22:00
(4 months ago)
Detected attack and reported by a human
Brute-Force
Web App Attack
SSH
DDoS Attack
Exploited Host
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-20 00:24:44
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 45.80.104.102 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.80.104.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 20:24:38.052827 2026] [security2:error] [pid 27920:tid 27920] [client 45.80.104.102:53291] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||clowaterart.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "clowaterart.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abyTxtNgfg8DnVHdf185XwAAAA8"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-16 20:43:46
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 45.80.104.102 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.80.104.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 16 16:43:38.809732 2026] [security2:error] [pid 26574:tid 26586] [client 45.80.104.102:46431] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sattraffic.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sattraffic.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abhremStRKRQXG7MWwnSiwAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-12 16:40:18
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 45.80.104.102 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.80.104.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 12 12:39:43.671773 2026] [security2:error] [pid 6064:tid 6064] [client 45.80.104.102:23511] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gonzalez.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gonzalez.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abLsTwLbi6DdB9NwlrqzoAAAADk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
kjaerulff
2026-03-11 14:57:16
(5 months ago)
Failed Wordpress login using wp-login.php
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-29 14:02:27
(7 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐ป๐ณ
Xuan Can
2025-01-31 05:17:44
(1 year ago)
(mod_security) mod_security (id:6) triggered by 45.80.104.102 (IL/Israel/-): 1 in the last 3600 secs ...
show more
(mod_security) mod_security (id:6) triggered by 45.80.104.102 (IL/Israel/-): 1 in the last 3600 secs; Ports: 80,443; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 31 12:17:38.210250 2025] [security2:error] [pid 17549:tid 17576] [client 45.80.104.102:0] [client 45.80.104.102] ModSecurity: Access denied with connection close (phase 2). Pattern match "wp-login.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "62"] [id "6"] [severity "CRITICAL"] [hostname "kb.sieuthimaychu.vn"] [uri "/wp-login.php"] [unique_id "Z5xc8gZT5SyDAyigNZmkOAAAAIA"]
show less
Brute-Force
SSH
๐บ๐ธ
octageeks.com
2025-01-18 05:07:16
(1 year ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐ช๐ธ
el-brujo
2024-06-09 21:23:00
(2 years ago)
DDoS Attack Layer 7 - REQUESTS / HTTP/2.0
DDoS Attack
๐ต๐ฑ
rafix
2023-11-03 06:30:17
(2 years ago)
Scrapping website, using diffrent useragents, not wait for response, #botnet20231026
DDoS Attack
Bad Web Bot