๐ซ๐ฎ
bittiguru.fi
2026-09-24 04:33:41
(1 day ago)
45.80.104.14 - [24/Sep/2026:07:32:53 +0300] "POST /xmlrpc.php HTTP/2.0" 404 12529 "-" "Mozilla/5.0 ( ...
show more
45.80.104.14 - [24/Sep/2026:07:32:53 +0300] "POST /xmlrpc.php HTTP/2.0" 404 12529 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36" "4.66"
45.80.104.14 - [24/Sep/2026:07:33:41 +0300] "POST /xmlrpc.php HTTP/2.0" 404 12529 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0) Gecko/20100101 Firefox/133.0" "4.66"
...
show less
Hacking
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 01:45:06
(3 days ago)
[ti-01sc] WordPress XML-RPC abuse: 3 suspicious requests detected by fail2ban jail apache-xmlrpc. Ex ...
show more
[ti-01sc] WordPress XML-RPC abuse: 3 suspicious requests detected by fail2ban jail apache-xmlrpc. Example: 45.80.104.14 - - [22/Sep/2026:03:23:17 +0200] "POST /xmlrpc.php HTTP/2.0" 403 90 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0) Gecko/20100101 Firefox/133.0"
45.80.104.14 - - [22/Sep/2026:03:44:26 +0200] "POST /xmlrpc.php HTTP/2.0" 403 87 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0 Safari/605.1.15"
45.80.104.14 - - [22/Sep/2026:03:44:48 +0200] "POST /xmlrpc.php HTTP/2.0" 403 87 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0 Safari/605.1.15"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-15 12:58:27
(1 week ago)
Brute-force login attack detected by WordPress firewall.
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-04-22 22:30:09
(5 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-04-01 23:27:02
(5 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐ฎ๐น
[email protected]
2026-03-31 13:38:50
(5 months ago)
[Tue Mar 31 15:38:50.575896 2026] [authz_core:error] [pid 2071050:tid 2071128] [client 45.80.104.14: ...
show more
[Tue Mar 31 15:38:50.575896 2026] [authz_core:error] [pid 2071050:tid 2071128] [client 45.80.104.14:55721] AH01630: client denied by server configuration: /var/www/html/MyWeb/Wordpress_www/xmlrpc.php
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-21 13:20:56
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.80.104.14 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 45.80.104.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 21 09:20:49.146289 2025] [security2:error] [pid 3642:tid 3642] [client 45.80.104.14:50633] [client 45.80.104.14] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nancyscafeandcatering.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nancyscafeandcatering.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aAZGMeyLTPIoxTbsWXqYzQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-18 21:09:29
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.80.104.14 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 45.80.104.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 18 17:09:24.000621 2025] [security2:error] [pid 1124446:tid 1124446] [client 45.80.104.14:61947] [client 45.80.104.14] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||4115thewestford.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "4115thewestford.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aAK_g8eVfIucHmZLaRQKmQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-18 05:26:30
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.80.104.14 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 45.80.104.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 18 01:26:25.920237 2025] [security2:error] [pid 2503447:tid 2503447] [client 45.80.104.14:25777] [client 45.80.104.14] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kathydumesnilart.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kathydumesnilart.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aAHigbuArIqKTgF6qCI7xwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-13 14:47:10
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.80.104.14 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 45.80.104.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 13 10:47:06.205500 2025] [security2:error] [pid 1831927:tid 1831927] [client 45.80.104.14:34921] [client 45.80.104.14] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||webseographics.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "webseographics.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z_vOagJBGGljBHJE9DWfRgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-03-30 12:45:26
(1 year ago)
This IP was involved in an brute force and password spray attack on 2025/03/28 08:11:40
Port Scan
Brute-Force
Exploited Host
Web App Attack
Anonymous
2025-03-28 14:56:16
(1 year ago)
This IP was involved in an brute force and password spray attack on 2025/03/28 08:11:41
Port Scan
Brute-Force
Exploited Host
Web App Attack
Anonymous
2025-03-20 09:19:06
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-02-09 05:31:20
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 45.80.104.14 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.80.104.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 09 00:31:14.034389 2025] [security2:error] [pid 1316979:tid 1316979] [client 45.80.104.14:29265] [client 45.80.104.14] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aethena.thefitzgeralds.org"] [uri "/.env"] [unique_id "Z6g9osSKKiZiF-aZ9MVD0wAAAAA"], referer: https://a00025.tiiny.site/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-02-06 05:04:45
(1 year ago)
WP Login Scan Activities
Web App Attack