๐บ๐ธ
TPI-Abuse
2026-08-02 23:16:53
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 45.157.112.223 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.157.112.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 02 19:16:47.725108 2026] [security2:error] [pid 2736105:tid 2736105] [client 45.157.112.223:47063] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jbernsteinpc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jbernsteinpc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "am_P3z-07A4XUjUD3RWGNAAAAAU"], referer: https://duckduckgo.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 22:09:59
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 45.157.112.223 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.157.112.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 18:09:53.564335 2026] [security2:error] [pid 3775098:tid 3775098] [client 45.157.112.223:56841] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.abundancecompany.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.abundancecompany.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amaFsVptnUgHG9Nt8DdetQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 21:37:13
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 45.157.112.223 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.157.112.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 17:37:07.491191 2026] [security2:error] [pid 3373110:tid 3373110] [client 45.157.112.223:47345] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.riser-astrology.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.riser-astrology.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amZ-A5uIZNTCFRofD8-X1wAAAAY"], referer: https://duckduckgo.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-07-26 21:33:00
(3 weeks ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐ฉ๐ช
bescared
2026-07-26 21:26:00
(3 weeks ago)
WAF (2) - Malicious activity detected: URL probing.
Bad Web Bot
Web App Attack
Hacking
Anonymous
2026-07-26 21:05:26
(3 weeks ago)
Blocked: Reason='Suspicious traffic score=60 (review-based detection)'; Requests=4
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-26 20:53:32
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 45.157.112.223 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.157.112.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 16:53:24.267065 2026] [security2:error] [pid 495077:tid 495077] [client 45.157.112.223:48753] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||isslv.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "isslv.net"] [uri "/wp-json/wp/v2/users"] [unique_id "amZzxKQJ-g1bt4VvNki3uQAAAAE"], referer: https://wordpress.org/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-26 20:09:24
(3 weeks ago)
(wordpress) Failed wordpress login from 45.157.112.223 (FR/France/-)
Brute-Force
๐ฌ๐ง
Yosi
2026-07-26 19:53:10
(3 weeks ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐จ๐ฆ
Dolphi
2026-07-26 19:50:02
(3 weeks ago)
Excessive POST /wp-login.php requests
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2026-07-12 23:34:35
(1 month ago)
614 requests with user_agent.original Dalvik/2.1.0 (Linux; U; Android 11; Tibuta_MasterPad-E100 Bui ...
show more
614 requests with user_agent.original Dalvik/2.1.0 (Linux; U; Android 11; Tibuta_MasterPad-E100 Build/RP1A.201005.006)
603 requests with user_agent.original Mozilla/5.0 (X11; U; Linux i586; en-US; rv:1.0.0) Gecko/20020623 Debian/1.0.0-0.woody.1
580 requests with user_agent.original Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.2.1) Gecko/20021208 Debian/1.2.1-2
568 requests with user_agent.original Mozilla/5.0 (iPhone; CPU iPhone OS 15_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/19G82 Instagram 306.0.0.20.118 (iPhone12,1; iOS 15_6_1; en_GB; en; scale=2.00; 828x1792; 529083166) NW/3
558 requests with user_agent.original AppleCoreMedia/1.0.0.23A344 (Macintosh; U; Intel Mac OS X 14_0; da_dk)
556 requests with user_agent.original Mozilla/5.0 (Macintosh; U; PPC Mac OS X Mach-O; en-US; rv:1.7.6) Gecko/20050319
555 requests with user_agent.original Mozilla/5.0 (Macintosh; U; PPC; en-US; rv:0.9.3) Gecko/20010802
547 requests with user_agent.original Mozilla/5.0 (iPhone; CPU iPhone OS 16_
show less
Brute-Force
Bad Web Bot
๐ซ๐ฎ
bittiguru.fi
2026-07-01 23:49:19
(1 month ago)
45.157.112.223 - - \[02/Jul/2026:02:49:04 +0300\] "POST /wp-login.php HTTP/1.1" 404 191 "https://ekc ...
show more
45.157.112.223 - - \[02/Jul/2026:02:49:04 +0300\] "POST /wp-login.php HTTP/1.1" 404 191 "https://ekcos.fi/wp-login.php" "Mozilla/5.0 \(Macintosh\; Intel Mac OS X 10_15_7\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/120.0.0.0 Safari/537.36" "3.13"
45.157.112.223 - - \[02/Jul/2026:02:49:06 +0300\] "POST /wp-login.php HTTP/1.1" 404 162 "https://ekcos.fi/wp-login.php" "Mozilla/5.0 \(Macintosh\; Intel Mac OS X 13_6_1\; rv:120.0\) Gecko/20100101 Firefox/120.0" "-"
45.157.112.223 - - \[02/Jul/2026:02:49:10 +0300\] "POST /wp-login.php HTTP/1.1" 404 162 "https://ekcos.fi/wp-login.php" "Mozilla/5.0 \(Macintosh\; Intel Mac OS X 13_6_1\) AppleWebKit/605.1.15 \(KHTML, like Gecko\) Version/17.2 Safari/605.1.15" "-"
45.157.112.223 - - \[02/Jul/2026:02:49:13 +0300\] "POST /wp-login.php HTTP/1.1" 404 191 "https://ekcos.fi/wp-login.php" "Mozilla/5.0 \(Windows NT 11.0\; Win64\; x64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/118.0.0.0 Safari/537.36" "3.13"
45.157.112.223 - - \[02/Jul/2026:02:4
...
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
nyt
2026-07-01 19:31:57
(1 month ago)
Brute-Force, Web App Attack, 503 on login page
Brute-Force
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-07-01 17:09:54
(1 month ago)
45.157.112.223 - - [01/Jul/2026:20:09:52 +0300] "GET /wp-login.php HTTP/1.1" 404 4732 "https://www.g ...
show more
45.157.112.223 - - [01/Jul/2026:20:09:52 +0300] "GET /wp-login.php HTTP/1.1" 404 4732 "https://www.google.com/search?q=wordpress" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1; rv:120.0) Gecko/20100101 Firefox/120.0"
45.157.112.223 - - [01/Jul/2026:20:09:54 +0300] "GET /wp-admin/ HTTP/1.1" 404 705 "https://www.bing.com/" "Mozilla/5.0 (Windows NT 11.0; Win64; x64; rv:118.0) Gecko/20100101 Firefox/118.0"
...
show less
Web App Attack
Anonymous
2026-06-30 15:59:13
(1 month ago)
Web App Attack