๐จ๐ฟ
ptlab
2026-06-26 14:46:08
(7 hours ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 17:26:14
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 45.80.105.237 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.80.105.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 13:26:11.335360 2026] [security2:error] [pid 7860:tid 7895] [client 45.80.105.237:54181] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jd-web-designs.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jd-web-designs.com"] [uri "/wp-json/wp/v2/users"] [unique_id "airvsyDO7htn3lU9hjJGlwAAAFg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 09:17:11
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 45.80.105.237 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.80.105.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 05:17:05.284912 2026] [security2:error] [pid 20066:tid 20066] [client 45.80.105.237:51385] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||laughingthunder.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "laughingthunder.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aifaEaevqb6SXkwMqxAftwAAAAg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Lino Project
2026-06-08 18:54:40
(2 weeks ago)
45.80.105.237 - - [08/Jun/2026:20:54:40 +0200] "POST /xmlrpc.php HTTP/1.1" 403 3987 "-" "Mozilla/5.0 ...
show more
45.80.105.237 - - [08/Jun/2026:20:54:40 +0200] "POST /xmlrpc.php HTTP/1.1" 403 3987 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_5_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.1.1 Mobile/15E148 Safari/604.1,gzip(gfe)"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-25 00:58:59
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 45.80.105.237 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.80.105.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 24 20:58:55.274491 2026] [security2:error] [pid 17025:tid 17025] [client 45.80.105.237:39551] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nighthawklabs.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nighthawklabs.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahOezyi9_dJ2erD8SySFBQAAAA8"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ambor
2026-05-21 21:55:57
(1 month ago)
Honeypot access: WordPress admin access attempt. Path: /wp-login.php
Brute-Force
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-05-20 04:24:03
(1 month ago)
WordPress login attempt
Brute-Force
๐ฉ๐ช
stinpriza
2026-04-06 01:22:39
(2 months ago)
Web App Attack
Web App Attack
Anonymous
2026-04-05 22:26:48
(2 months ago)
2026-04-06T00:26:48.514099+02:00 zanati wp(www.sahpa.co.za)[3849338]: Blocked authentication attempt ...
show more
2026-04-06T00:26:48.514099+02:00 zanati wp(www.sahpa.co.za)[3849338]: Blocked authentication attempt for [email protected] from 45.80.105.237
...
show less
Web App Attack
๐ฉ๐ช
stinpriza
2026-04-05 01:01:36
(2 months ago)
Web App Attack
Web App Attack
๐ฉ๐ช
stinpriza
2026-04-03 06:17:02
(2 months ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-02 17:13:09
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 45.80.105.237 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.80.105.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 13:13:01.247001 2026] [security2:error] [pid 29540:tid 29540] [client 45.80.105.237:20901] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tidarat.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tidarat.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ac6jnftbeS05UpeOgyylyQAAABA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
stinpriza
2026-04-01 23:00:17
(2 months ago)
Web App Attack
Web App Attack
๐ฉ๐ช
stinpriza
2026-03-31 06:11:40
(2 months ago)
Web App Attack
Web App Attack
๐ฉ๐ช
stinpriza
2026-03-30 06:04:15
(2 months ago)
Web App Attack
Web App Attack