๐บ๐ธ
kadour
2026-06-17 11:52:22
(3 days ago)
[Wed Jun 17 06:52:12.740236 2026] [proxy_fcgi:error] [pid 1771417:tid 1771529] [client 45.88.13.116: ...
show more
[Wed Jun 17 06:52:12.740236 2026] [proxy_fcgi:error] [pid 1771417:tid 1771529] [client 45.88.13.116:35109] AH01071: Got error 'Primary script unknown', referer: https://www.google.com
[Wed Jun 17 06:52:14.292446 2026] [proxy_fcgi:error] [pid 1771416:tid 1771521] [client 45.88.13.116:24849] AH01071: Got error 'Primary script unknown', referer: https://www.google.com
[Wed Jun 17 06:52:15.689471 2026] [proxy_fcgi:error] [pid 1771417:tid 1771591] [client 45.88.13.116:61963] AH01071: Got error 'Primary script unknown', referer: https://www.google.com
[Wed Jun 17 06:52:20.130539 2026] [proxy_fcgi:error] [pid 1771417:tid 1771592] [client 45.88.13.116:40559] AH01071: Got error 'Primary script unknown', referer: https://www.google.com
[Wed Jun 17 06:52:21.478482 2026] [proxy_fcgi:error] [pid 1771416:tid 1771528] [client 45.88.13.116:15875] AH01071: Got error 'Primary script unknown', referer: https://www.google.com
...
show less
Web App Attack
๐บ๐ธ
rsiddall
2026-06-16 08:02:28
(5 days ago)
45.88.13.116 - - [16/Jun/2026:04:02:24 -0400] "POST /xmlrpc.php HTTP/1.1" 404 - "-" "Apache-HttpClie ...
show more
45.88.13.116 - - [16/Jun/2026:04:02:24 -0400] "POST /xmlrpc.php HTTP/1.1" 404 - "-" "Apache-HttpClient/4.5.13 (Java/17.0.18)"
45.88.13.116 - - [16/Jun/2026:04:02:27 -0400] "POST /xmlrpc.php HTTP/1.1" 404 - "-" "Apache-HttpClient/4.5.13 (Java/17.0.18)"
...
show less
Brute-Force
๐บ๐ธ
kosada.com
2026-06-07 17:00:17
(1 week ago)
Web password guessing
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-03 14:52:18
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 45.88.13.116 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 45.88.13.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 10:52:13.532725 2026] [security2:error] [pid 2081:tid 2081] [client 45.88.13.116:41837] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||paintriver.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "paintriver.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiA_nWcMb5qAX8_D__sW6QAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-05-30 12:51:21
(3 weeks ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-30 05:21:54
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 45.88.13.116 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 45.88.13.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 01:21:48.787180 2026] [security2:error] [pid 17611:tid 17611] [client 45.88.13.116:21855] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mbnetworking.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mbnetworking.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahpz7DrlTxVP5Ug7T0T1SgAAAIs"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-05-22 16:19:40
(4 weeks ago)
Web password guessing
Brute-Force
๐ฌ๐ง
poundawebsiteltd
2026-04-30 04:25:11
(1 month ago)
Web App Attack (ModSecurity Block). Evidence: [REDACTED_DOMAIN]:443 45.88.13.116 - - [30/Apr/2026:05 ...
show more
Web App Attack (ModSecurity Block). Evidence: [REDACTED_DOMAIN]:443 45.88.13.116 - - [30/Apr/2026:05:25:09 +0100] GET / HTTP/1.1 403 2814 - Mozilla/5.0 (Android; Linux armv7l; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Fennec/2.0.1
show less
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-03-26 02:02:50
(2 months ago)
WordPress login attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-03-26 00:55:57
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 45.88.13.116 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 45.88.13.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 25 20:55:50.584823 2026] [security2:error] [pid 31010:tid 31010] [client 45.88.13.116:62543] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dudleyanddudley.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dudleyanddudley.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acSEFnF6Vvcn27kjrDFFLQAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-25 17:07:07
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 45.88.13.116 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 45.88.13.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 25 13:07:00.262689 2026] [security2:error] [pid 1882806:tid 1882806] [client 45.88.13.116:27449] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gotdt.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gotdt.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acQWNKlAFeEpdJSOVM0OYAAAAAU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-25 16:16:53
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 45.88.13.116 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 45.88.13.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 25 12:16:19.947828 2026] [security2:error] [pid 3384:tid 3384] [client 45.88.13.116:50815] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mithryl.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mithryl.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acQKUzX_BjXicSYSEMWbUQAAAAo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-25 04:41:04
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 45.88.13.116 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 45.88.13.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 25 00:40:57.240305 2026] [security2:error] [pid 27134:tid 27134] [client 45.88.13.116:63689] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||edensgroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "edensgroup.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acNnWfEwr21MmbpTNWaIiwAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-23 14:03:02
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 45.88.13.116 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 45.88.13.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 23 10:02:29.367379 2026] [security2:error] [pid 1871:tid 1871] [client 45.88.13.116:11723] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||k-h-w.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "k-h-w.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acFH9QEfVzzBNk-e4RwxEAAAAF8"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ambor
2026-03-22 13:03:18
(2 months ago)
Honeypot access: WordPress admin access attempt. Path: /wp-login.php
Brute-Force
Web App Attack