๐ซ๐ท
Jean Valjean
2026-07-21 22:26:14
(3 days ago)
Fail2ban Caboom : wp-login.php Bruteforce
Brute-Force
Web App Attack
๐ง๐ท
SOC PR
2026-06-11 05:57:56
(1 month ago)
IPS: WordPress HTTP Brute Force Login Attempt.
Brute-Force
๐บ๐ธ
ipblock.com
2026-06-10 22:10:00
(1 month ago)
IPBlock protected site ID [4055-d][s=01].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 21:38:15
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 45.80.107.224 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.80.107.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 17:38:07.521508 2026] [security2:error] [pid 15214:tid 15214] [client 45.80.107.224:39513] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||calvarycavaliers.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "calvarycavaliers.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aiSTP0ybpvN6u1q7eFRcqwAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-06 10:17:56
(2 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 13-17.45.80.107.224.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 13-17.45.80.107.224.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ง๐ช
voormedia
2026-02-09 05:09:14
(5 months ago)
Accessed trap at '/xmlrpc.php'
Web App Attack
๐ฉ๐ช
MusicLibrary
2026-02-08 21:09:43
(5 months ago)
Attempted access to non existent wordpress urls
Bad Web Bot
๐ช๐ธ
el-brujo
2026-02-05 13:35:47
(5 months ago)
Cloudflare WAF: Request Path: /xmlrpc.php Request Query: Host: foro.elhacker.net userAgent: Mozilla ...
show more
Cloudflare WAF: Request Path: /xmlrpc.php Request Query: Host: foro.elhacker.net userAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:146.0) Gecko/20100101 Firefox/146.0 Action: managed_challenge Source: firewallManaged ASN Description: BTTGROUP-AS Country: US Method: POST Timestamp: 2026-02-05T13:35:47Z ruleId: 5de7edfa648c4d6891dc3e7f84534ffa. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-13 02:48:09
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 45.80.107.224 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 45.80.107.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 12 21:47:30.060492 2026] [security2:error] [pid 5821:tid 5821] [client 45.80.107.224:52095] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.nwtree.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.nwtree.com"] [uri "/blog/hire-certified-arborist"] [unique_id "aWWyQZbmeJPoDkXjjzgl_gAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-01-02 13:54:28
(6 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 45.80.107.224 (IL/Israel/-): 1 in t ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 45.80.107.224 (IL/Israel/-): 1 in the last 3600 secs
show less
Web App Attack
๐ฎ๐ฉ
Burayot
2025-12-30 16:14:13
(6 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 45.80.107.224 (IL/Israel/-): 1 in t ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 45.80.107.224 (IL/Israel/-): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-27 10:00:38
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 45.80.107.224 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 45.80.107.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 05:00:34.072109 2025] [security2:error] [pid 22180:tid 22180] [client 45.80.107.224:59349] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||corepest.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "corepest.com"] [uri "/"] [unique_id "aU-uQj1BuXe72MswQxSUkgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nowyouknow
2025-12-19 03:10:37
(7 months ago)
(From [email protected] ) Hi Team,
I typed your main service keywords into Google today, a ...
show more
(From [email protected] ) Hi Team,
I typed your main service keywords into Google today, and I noticed something frustrating. Your website is professionally designed, but itโs buried on Page 2.
Meanwhile, 2 or 3 of your direct competitors, who frankly have weaker websites than youโare sitting at the top of Page 1.
They are effectively "stealing" leads that were looking for you. They aren't better than you; they just have better SEO signals.
Iโve already analyzed exactly what they are doing differently.
If you want to see the comparison report, just reply "Yes" and Iโll send it over.
Cheers,
QIK
show less
Phishing
Web Spam
๐ฉ๐ช
Ba-Yu
2025-11-01 12:59:14
(8 months ago)
WordPress bruteforce
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-23 21:31:36
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 45.80.107.224 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 45.80.107.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 23 17:31:30.128871 2025] [security2:error] [pid 22797:tid 22797] [client 45.80.107.224:54393] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.heinzmail.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.heinzmail.com"] [uri "/utility-bill-energy-management-software/"] [unique_id "aPqesmPDID_D1rJgp3BcMgAAAAQ"], referer: https://www.facebook.com/
show less
Brute-Force
Bad Web Bot
Web App Attack