🇨🇿
Countryman
2026-09-12 00:10:01
(3 days ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
🇸🇪
OnTheEdge
2026-09-09 15:17:25
(5 days ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
🇺🇸
nationaleventpros.com
2026-09-05 07:08:20
(1 week ago)
WordPress login attempt
Brute-Force
🇺🇸
TPI-Abuse
2026-09-04 20:14:28
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 45.80.105.199 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.80.105.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 16:14:23.420155 2026] [security2:error] [pid 15815:tid 15815] [client 45.80.105.199:54303] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||yogitunes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "yogitunes.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apsmn-zjf2Z2k7oKG6foawAAABk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
nationaleventpros.com
2026-09-03 02:22:04
(1 week ago)
WordPress login attempt
Brute-Force
🇨🇭
backslash
2026-08-27 07:39:00
(2 weeks ago)
probe wp2shell
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 03:01:35
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 45.80.105.199 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.80.105.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 23:01:32.457329 2026] [security2:error] [pid 25591:tid 25591] [client 45.80.105.199:50131] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||willymoc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "willymoc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ao-ojF1n9T2Hw2Wg5SIEAQAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-08-13 11:10:04
(1 month ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
🇮🇩
Burayot
2026-08-10 07:48:39
(1 month ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 45.80.105.199 (IL/Israel/-): 1 in t ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 45.80.105.199 (IL/Israel/-): 1 in the last 3600 secs
show less
Web App Attack
🇮🇩
Burayot
2026-08-07 19:07:57
(1 month ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 45.80.105.199 (IL/Israel/-): 1 in t ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 45.80.105.199 (IL/Israel/-): 1 in the last 3600 secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-06 16:00:52
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 45.80.105.199 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.80.105.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 12:00:44.169651 2026] [security2:error] [pid 585035:tid 585035] [client 45.80.105.199:19769] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||geofreightint.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "geofreightint.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anSvrP1aO2gt-nb_M2YcMgAAAAs"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-05 19:21:10
(1 month ago)
FPROCO WEBEXPLOIT 45.80.105.199 (45.80.105.199)
Web App Attack
Anonymous
2026-08-05 16:10:20
(1 month ago)
Web Spam
🇺🇸
TPI-Abuse
2026-08-04 03:46:46
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 45.80.105.199 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.80.105.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 23:46:42.498773 2026] [security2:error] [pid 2693829:tid 2693829] [client 45.80.105.199:57981] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rogerandcarol.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rogerandcarol.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anFgomzho2D72MhZCMhobQAAACA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-03 00:25:00
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 45.80.105.199 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.80.105.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 02 20:24:54.576719 2026] [security2:error] [pid 28097:tid 28097] [client 45.80.105.199:61525] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lsippell.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lsippell.com"] [uri "/wp-json/wp/v2/users"] [unique_id "am_f1t3OYdCXpKHSzhBmVwAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack