๐ฎ๐น
VHosting
2026-08-05 20:00:05
(3 weeks ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
Anonymous
2026-07-08 18:37:04
(1 month ago)
45.95.243.57 - - [08/Jul/2026:20:34:56 +0200] "POST /wp-login.php HTTP/1.1" 200 2702 "-" "Mozilla/5. ...
show more
45.95.243.57 - - [08/Jul/2026:20:34:56 +0200] "POST /wp-login.php HTTP/1.1" 200 2702 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 Version/17.0 Safari/605.1.15"
45.95.243.57 - - [08/Jul/2026:20:34:56 +0200] "POST /wp-login.php HTTP/1.1" 200 2183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 Version/17.0 Safari/605.1.15"
45.95.243.57 - - [08/Jul/2026:20:36:00 +0200] "POST /wp-login.php HTTP/1.1" 200 2702 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; rv:143.0) Gecko/20100101 Firefox/143.0"
45.95.243.57 - - [08/Jul/2026:20:36:00 +0200] "POST /wp-login.php HTTP/1.1" 200 2183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; rv:143.0) Gecko/20100101 Firefox/143.0"
45.95.243.57 - - [08/Jul/2026:20:37:03 +0200] "POST /wp-login.php HTTP/1.1" 200 2702 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/129.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐ซ๐ท
Octopuce
2026-05-09 00:47:06
(3 months ago)
Aggressive web search of vulnerable pages: /wp-content/plugins/ubh/up.php /wp-admin/images/bootstrap ...
show more
Aggressive web search of vulnerable pages: /wp-content/plugins/ubh/up.php /wp-admin/images/bootstrap.php /images/upload.php /wp-content/plugins ...
show less
Web App Attack
๐บ๐ธ
nyt
2026-04-20 17:30:57
(4 months ago)
Empty UA + POST
Web App Attack
๐ซ๐ท
dynamix
2026-04-17 16:35:24
(4 months ago)
Multiple WAF Violations
Web App Attack
๐ฑ๐ป
garmtech.com
2026-04-11 08:19:21
(4 months ago)
IM360 WAF: Interaction with fake plugin MV:/wp-content/plugins/ioptimization/
Web App Attack
๐ฑ๐ป
garmtech.com
2026-04-11 08:18:48
(4 months ago)
IM360 WAF: Interaction with fake plugin MV:/wp-content/plugins/pwnd/
Web App Attack
๐ฑ๐ป
garmtech.com
2026-04-11 08:18:42
(4 months ago)
IM360 WAF: Block interaction with malicious plugin
Web App Attack
๐บ๐ธ
mnsf
2026-03-25 01:05:34
(5 months ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐บ๐ธ
myagent.site
2026-03-24 22:22:20
(5 months ago)
Blocking for trying to access an exploit file: //chosen.php
Hacking
๐ซ๐ท
Octopuce
2026-03-24 18:34:49
(5 months ago)
Aggressive web search of vulnerable pages: /wp-includes/assets/index.php //wp-admin/fmadmin.php //wp ...
show more
Aggressive web search of vulnerable pages: /wp-includes/assets/index.php //wp-admin/fmadmin.php //wp-content/admin.php //wp-content/about.php / ...
show less
Web App Attack
๐บ๐ธ
Penny Packer
2026-03-10 10:41:34
(5 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-03 22:05:44
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 45.95.243.57 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.95.243.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 03 17:05:37.955949 2026] [security2:error] [pid 5839:tid 5839] [client 45.95.243.57:56789] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||phantomkennels.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "phantomkennels.com"] [uri "/bak/wallet.dat"] [unique_id "aadbMfAlP7toIJC898hqvgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-01 20:27:13
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 45.95.243.57 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.95.243.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 01 15:27:07.015226 2026] [security2:error] [pid 22964:tid 22964] [client 45.95.243.57:24501] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nationalenq.com"] [uri "/backups/sftp-config.json"] [unique_id "aaShG4m53IlBmpAhhC6KDwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-28 21:15:47
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 45.95.243.57 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.95.243.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 28 16:15:41.441182 2026] [security2:error] [pid 8185:tid 8185] [client 45.95.243.57:39311] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||asiabeef.network|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "asiabeef.network"] [uri "/backups/mysql.sql"] [unique_id "aaNa_ar44HCR35DU_YtIFAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack