Anonymous
2026-07-29 06:08:00
(3 weeks ago)
Blocked: Reason='Suspicious traffic score=60 (review-based detection)'; Requests=4
Hacking
๐บ๐ธ
Jason Howell
2026-07-29 05:31:03
(3 weeks ago)
45.157.112.18 - - [29/Jul/2026:00:30:37 -0500] "GET /wp-login.php HTTP/1.1" 200 6835 "https://wordpr ...
show more
45.157.112.18 - - [29/Jul/2026:00:30:37 -0500] "GET /wp-login.php HTTP/1.1" 200 6835 "https://wordpress.org/" "Mozilla/5.0 (Windows NT 11.0; Win64; x64; rv:119.0) Gecko/20100101 Firefox/119.0"
45.157.112.18 - - [29/Jul/2026:00:30:49 -0500] "POST /wp-login.php HTTP/1.1" 503 19533 "https://gannonpool.com/wp-login.php" "Mozilla/5.0 (Windows NT 11.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
45.157.112.18 - - [29/Jul/2026:00:30:53 -0500] "GET /wp-admin/index.php HTTP/1.1" 503 23410 "https://gannonpool.com/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2 Safari/605.1.15"
45.157.112.18 - - [29/Jul/2026:00:30:55 -0500] "GET /wp-admin/profile.php HTTP/1.1" 503 23411 "https://gannonpool.com/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2 Safari/605.1.15"
45.157.112.18 - - [29/Jul/2026:00:31:03 -0500] "GET /wp-admin/edit.php HTTP/1.1" 503 23409 "https
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 05:16:50
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 45.157.112.18 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.157.112.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 01:16:42.965264 2026] [security2:error] [pid 2081990:tid 2081990] [client 45.157.112.18:44703] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lukeschicago.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lukeschicago.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ammMussVU0h9le-20yDVbgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
solution.it
2026-07-28 18:25:38
(3 weeks ago)
[Tue Jul 28 20:25:38.252703 2026] [php7:error] [pid 1224026:tid 1224026] [client 45.157.112.18:24297 ...
show more
[Tue Jul 28 20:25:38.252703 2026] [php7:error] [pid 1224026:tid 1224026] [client 45.157.112.18:24297] script '/var/www/html/blog.solution.it/wp-login.php' not found or unable to stat, referer: https://t.co/
show less
Web App Attack
๐ซ๐ท
dynamix
2026-07-26 07:13:11
(3 weeks ago)
WordPress wp-login.php Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-07-26 06:43:21
(3 weeks ago)
45.157.112.18 - - [26/Jul/2026:09:43:14 +0300] "GET /wp-login.php HTTP/1.1" 404 4220 "https://t.co/" ...
show more
45.157.112.18 - - [26/Jul/2026:09:43:14 +0300] "GET /wp-login.php HTTP/1.1" 404 4220 "https://t.co/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15"
45.157.112.18 - - [26/Jul/2026:09:43:17 +0300] "GET /wp-login.php HTTP/1.1" 200 318 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-07-21 14:25:51
(1 month ago)
(Kingcopy.org-AI-IDS-Report):IP automatically blocked after obfuscated encoding / deep attack. Vegas ...
show more
(Kingcopy.org-AI-IDS-Report):IP automatically blocked after obfuscated encoding / deep attack. Vegas Security
show less
DDoS Attack
Hacking
Exploited Host
๐ฉ๐ช
Vegascosmetics
2026-07-21 06:02:57
(1 month ago)
(Kingcopy.org-AI-IDS-Report):IP automatically blocked after obfuscated redirect. Vegas Security
DDoS Attack
Hacking
Exploited Host
Anonymous
2026-07-07 15:58:06
(1 month ago)
(wordpress) Failed wordpress login from 45.157.112.18 (FR/France/-)
Brute-Force
๐ซ๐ท
dynamix
2026-07-07 15:01:06
(1 month ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-07 14:29:42
(1 month ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ซ๐ท
francoisunix
2026-07-07 14:17:06
(1 month ago)
45.157.112.18 - - [07/Jul/2026:16:16:29 +0200] "POST //xmlrpc.php HTTP/1.1" 401 422 "-" "Mozilla/5.0 ...
show more
45.157.112.18 - - [07/Jul/2026:16:16:29 +0200] "POST //xmlrpc.php HTTP/1.1" 401 422 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_2_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Safari/605.1.15" "45.157.112.18" "www.eco-conscient.com" sn="www.eco-conscient.com" rt=0.426 ua="unix:/var/run/php/php8.2-fpm.sock" us="401" ut="0.425" ul="427" cs=-cf_country="FR" cf_region="\xC3\x8Ele-de-France" cf_city="Paris"rip=127.0.0.1 cf_ip=45.157.112.18 xff="45.157.112.18" p_xff="45.157.112.18, 45.157.112.18"
45.157.112.18 - - [07/Jul/2026:16:16:29 +0200] "POST //xmlrpc.php HTTP/1.1" 401 422 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2 Mobile/15E148 Safari/604.1" "45.157.112.18" "www.eco-conscient.com" sn="www.eco-conscient.com" rt=0.537 ua="unix:/var/run/php/php8.2-fpm.sock" us="401" ut="0.536" ul="427" cs=-cf_country="FR" cf_region="\xC3\x8Ele-de-France" cf_city="Paris"rip=127.0.0.1 cf_ip=45.157.112.18 xff="45.157.112.1
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-29 22:21:55
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 45.157.112.18 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.157.112.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 18:21:52.410897 2026] [security2:error] [pid 9507:tid 9507] [client 45.157.112.18:22301] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||easterbilby.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "easterbilby.net"] [uri "/wp-json/wp/v2/users"] [unique_id "akLwADMR5qFwqK2_NQrF6AAAAAk"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-06-27 20:57:52
(1 month ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
๐ซ๐ท
EDSL
2026-06-27 08:24:00
(1 month ago)
[mail.edsl.fr] Blocked by SysWarden Firewall (Web Attack)
Web App Attack
Hacking
Port Scan