🇩🇪
FeG Deutschland
2026-09-07 05:51:35
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇺🇸
ipblock.com
2026-09-05 04:20:00
(4 days ago)
IPBlock protected site ID [3390-wh].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
🇦🇺
afleventoffice.com.au
2026-08-31 20:15:23
(1 week ago)
GET /wp-login.php HTTP/1.1
Web App Attack
🇮🇹
CoreTech srl
2026-08-30 14:58:56
(1 week ago)
cloudlinux2 fail2ban: 2026-08-30 16:56:41,253 fail2ban.filter [1459]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-30 16:56:41,253 fail2ban.filter [1459]: INFO [plesk-wordpress] Found 185.251.19.32 - 2026-08-30 16:56:41cloudlinux2 fail2ban: 2026-08-30 16:56:36,918 fail2ban.filter [1459]: INFO [plesk-wordpress] Found 185.251.19.32 - 2026-08-30 16:56:36cloudlinux2 fail2ban: 2026-08-30 16:56:36,920 fail2ban.filter [1459]: INFO [plesk-wordpress] Found 45.132.227.168 - 2026-08-30 16:56:36cloudlinux2 fail2ban: 2026-08-30 16:56:46,558 fail2ban.filter [1459]: INFO [plesk-modsecurity] Found 103.86.139.29 - 2026-08-30 16:56:46cloudlinux2 fail2ban: 2026-08-30 16:56:53,183 fail2ban.filter [1459]: INFO [plesk-wordpress] Found 192.162.70.177 - 2026-08-30 16:56:52cloudlinux2 fail2ban: 2026-08-30 16:57:06,786 fail2ban.filter [1459]: INFO [plesk-modsecurity] Found 45.41.106.201 - 2026-08-30 16:57:06cloudlinux2 fail2ban: 2026-08-30 16:58:32,181 fail2ban.filter [1459]: INFO [plesk-modsecurity] Found 45.41.106.201 - 2026-08-30 16:58:32c
show less
Web App Attack
🇳🇴
jad-abuse
2026-08-30 06:23:34
(1 week ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_login. ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_login. Observed by 1 sensor(s); 1 hits.
show less
Brute-Force
Web App Attack
🇫🇷
tecnicorioja
2026-08-28 22:01:29
(1 week ago)
wp-login attack [28/Aug/2026:10:21:42
Brute-Force
Web App Attack
🇺🇸
nyt
2026-08-26 06:48:13
(2 weeks ago)
WP Author Enumeration, WP User Enumeration
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 02:42:00
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 22:41:36.881469 2026] [security2:error] [pid 17794:tid 17794] [client 45.132.227.168:41103] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.103"] [uri "/web103.dnchosting.com/.env"] [unique_id "ao5SYPElqmLIJFih-VJFDwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-22 02:25:43
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 22:25:22.088066 2026] [security2:error] [pid 21824:tid 21824] [client 45.132.227.168:58861] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.196"] [uri "/backend/.env"] [unique_id "aokIkvTP2FRvLPT4eGfUPAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
HamSammich
2026-08-03 07:40:41
(1 month ago)
Automated sensor: 3 HTTP connection/probe attempts over the last 24h (latest 2026-08-03T07:40Z).
Brute-Force
Web App Attack
🇺🇸
sailor
2026-08-02 16:02:00
(1 month ago)
WP login attack
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-07-31 02:46:47
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 45.132.227.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.132.227.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 22:46:39.938910 2026] [security2:error] [pid 2216827:tid 2216827] [client 45.132.227.168:22713] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||appalachianfieldstofamilies.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "appalachianfieldstofamilies.org"] [uri "/wp-json/wp/v2/users"] [unique_id "amwMj3_rt2qhLUErOEBGyAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
netclix.gr
2026-07-29 20:36:27
(1 month ago)
(wordpress) Failed wordpress login from 45.132.227.168 (US/United States/-): (CF_ENABLE)
Brute-Force
🇩🇪
tall1oN
2026-07-29 19:24:39
(1 month ago)
45.132.227.168 - - [29/Jul/2026:21:24:36 +0200] "POST /wp-login.php HTTP/2.0" 405 157 "-" "Mozilla/5 ...
show more
45.132.227.168 - - [29/Jul/2026:21:24:36 +0200] "POST /wp-login.php HTTP/2.0" 405 157 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:125.0) Gecko/20100101 Firefox/125.0" "exatek.de"
45.132.227.168 - - [29/Jul/2026:21:24:37 +0200] "POST /wp-login.php HTTP/2.0" 405 559 "-" "Mozilla/5.0 (Linux; Android 6.0.1; SM-G930F Build/MMB29K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.91 Mobile Safari/537.36" "exatek.de"
...
show less
Web App Attack
Port Scan
Hacking
🇩🇪
todix
2026-07-29 17:49:55
(1 month ago)
Wordpress brute force or spam attempt from 45.132.227.168
Brute-Force