๐ช๐ธ
librebit
2026-09-02 16:30:40
(2 weeks ago)
Brute force
Brute-Force
๐ฉ๐ช
4server
2026-09-01 22:19:53
(2 weeks ago)
[WedSep0200:19:46.3132072026][security2:error][pid573768:tid573857][client45.88.13.12:0]ModSecurity: ...
show more
[WedSep0200:19:46.3132072026][security2:error][pid573768:tid573857][client45.88.13.12:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"alessandrolucchini.ch\"][uri\"/xmlrpc.php\"][unique_id\"apdPgvfI4mpcwiqemSKMLgAAAQI\"]
show less
Port Scan
Brute-Force
Web App Attack
๐จ๐ญ
backslash
2026-08-28 14:57:04
(3 weeks ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
Anonymous
2026-08-06 18:34:53
(1 month ago)
Unauthorized access (443/tcp/https)
Port Scan
Web App Attack
๐จ๐ญ
Gygy
2026-08-01 12:32:00
(1 month ago)
Attaque dรฉbordement de pile !
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-03 15:38:48
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 45.88.13.12 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 45.88.13.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 11:38:43.271964 2026] [security2:error] [pid 5010:tid 5010] [client 45.88.13.12:39887] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||vigants.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "vigants.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ac_fAy1Ag5eptZIYYtXHDgAAAAg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 00:12:48
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 45.88.13.12 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 45.88.13.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 20:12:43.491714 2026] [security2:error] [pid 1219:tid 1219] [client 45.88.13.12:29149] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||prospecinspections.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "prospecinspections.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acsRe5Z4Yd5mXDon_8_8KgAAABM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-29 15:20:25
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 45.88.13.12 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 45.88.13.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 29 11:19:58.727012 2026] [security2:error] [pid 13102:tid 13102] [client 45.88.13.12:23525] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||butterfly-storm.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "butterfly-storm.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aclDHqG6Ph7zCy90twUCGQAAAAw"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-03-26 01:46:13
(5 months ago)
WordPress login attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-03-25 15:30:49
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 45.88.13.12 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 45.88.13.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 25 11:30:22.562153 2026] [security2:error] [pid 21958:tid 21958] [client 45.88.13.12:59603] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gonzalez.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gonzalez.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acP_jgPs2H2xlWWPaxBWFAAAABA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 22:57:04
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 45.88.13.12 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 45.88.13.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 18:56:57.739812 2026] [security2:error] [pid 4492:tid 4529] [client 45.88.13.12:54313] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bakmail.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bakmail.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ab8iORZavuFFYSrN-vBppwAAABY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Jason Howell
2026-03-20 00:51:50
(5 months ago)
45.88.13.12 - - [19/Mar/2026:19:51:33 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2728 "-" "Apache-HttpCl ...
show more
45.88.13.12 - - [19/Mar/2026:19:51:33 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2728 "-" "Apache-HttpClient/4.5.13 (Java/11.0.30)"
45.88.13.12 - - [19/Mar/2026:19:51:34 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2802 "-" "Apache-HttpClient/4.5.13 (Java/11.0.30)"
45.88.13.12 - - [19/Mar/2026:19:51:37 -0500] "GET /wp-login.php HTTP/1.1" 200 4504 "https://www.google.com" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
45.88.13.12 - - [19/Mar/2026:19:51:48 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2727 "-" "Apache-HttpClient/4.5.13 (Java/11.0.30)"
45.88.13.12 - - [19/Mar/2026:19:51:49 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2803 "-" "Apache-HttpClient/4.5.13 (Java/11.0.30)"
...
show less
Web App Attack
๐บ๐ธ
xmission.com
2026-03-03 21:27:57
(6 months ago)
45.88.13.12 - - [03/Mar/2026:14:27:56 -0700] "POST /wp-login.php HTTP/1.1" 200 2354 "https://dooce.c ...
show more
45.88.13.12 - - [03/Mar/2026:14:27:56 -0700] "POST /wp-login.php HTTP/1.1" 200 2354 "https://dooce.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
...
show less
Brute-Force
๐ฉ๐ช
kjaerulff
2025-10-18 10:01:02
(11 months ago)
Failed Wordpress login using wp-login.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-17 03:37:38
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 45.88.13.12 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 45.88.13.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 16 23:37:32.768519 2025] [security2:error] [pid 24676:tid 24676] [client 45.88.13.12:21885] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kawkacevents.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kawkacevents.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aPG5_H4GpLitRxLzaVq_gQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack