๐ฉ๐ช
Admins@FBN
2026-07-25 11:59:00
(1 day ago)
FW-PortScan: Traffic Blocked srcport=40247 dstport=12234
Port Scan
๐บ๐ธ
anon333
2026-07-25 01:34:06
(2 days ago)
Hacker syslog review 1784943245
Hacking
๐ฉ๐ช
LRob
2026-07-24 02:21:10
(3 days ago)
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Jetpack by WordPress.co ...
show more
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Jetpack by WordPress.com
show less
Brute-Force
Web App Attack
Anonymous
2026-07-24 01:50:38
(3 days ago)
[da.kdns.gr] httpd-xmlrpc-post: sites=www.galanistherm.gr; logs=/var/log/httpd/domains/galanistherm. ...
show more
[da.kdns.gr] httpd-xmlrpc-post: sites=www.galanistherm.gr; logs=/var/log/httpd/domains/galanistherm.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 00:49:37
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 45.166.57.13 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 45.166.57.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 20:49:34.337519 2026] [security2:error] [pid 3775103:tid 3775103] [client 45.166.57.13:60655] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.166.57.13 (+1 hits since last alert)|mariettacaseyclub.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mariettacaseyclub.org"] [uri "/xmlrpc.php"] [unique_id "amK2ngZgPBwv4TznKp5C8wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
KnightIndustries
2026-07-24 00:17:21
(3 days ago)
2026-07-24T02:16:59.975547+02:00 milkyway wordpress(fawcettcomputerservices.com)[414248]: XML-RPC au ...
show more
2026-07-24T02:16:59.975547+02:00 milkyway wordpress(fawcettcomputerservices.com)[414248]: XML-RPC authentication failure for joshua from 45.166.57.13
2026-07-24T02:17:10.578427+02:00 milkyway wordpress(fawcettcomputerservices.com)[412904]: XML-RPC authentication failure for joshua from 45.166.57.13
2026-07-24T02:17:21.189331+02:00 milkyway wordpress(fawcettcomputerservices.com)[412268]: XML-RPC authentication failure for joshua from 45.166.57.13
...
show less
Brute-Force
Web App Attack
Anonymous
2026-07-23 07:16:13
(4 days ago)
denied traffic to a honeypot network. destination port 61488.
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-18 01:22:28
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 45.166.57.13 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 45.166.57.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 21:22:23.287419 2026] [security2:error] [pid 27596:tid 27596] [client 45.166.57.13:61112] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.166.57.13 (+1 hits since last alert)|riccardiagency.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "riccardiagency.com"] [uri "/xmlrpc.php"] [unique_id "alrVT8BrwSNKk72BEtbQjgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
cwytech
2026-07-18 01:20:12
(1 week ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-18 00:21:13
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 45.166.57.13 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 45.166.57.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 20:21:08.521882 2026] [security2:error] [pid 1086382:tid 1086382] [client 45.166.57.13:56231] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.166.57.13 (+1 hits since last alert)|drayvian.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "drayvian.com"] [uri "/xmlrpc.php"] [unique_id "alrG9C1Jxd17YoDdmtyREQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 23:50:09
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 45.166.57.13 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 45.166.57.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 19:50:05.559502 2026] [security2:error] [pid 11547:tid 11547] [client 45.166.57.13:57095] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.166.57.13 (+1 hits since last alert)|doctoredwinalvarez.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "doctoredwinalvarez.com"] [uri "/xmlrpc.php"] [unique_id "alq_rSiSHEvphW1YGD_azgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-12 03:12:50
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 45.166.57.13 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 45.166.57.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 11 23:12:42.766457 2026] [security2:error] [pid 21316:tid 21316] [client 45.166.57.13:49518] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.166.57.13 (+1 hits since last alert)|fernfield.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fernfield.com"] [uri "/xmlrpc.php"] [unique_id "alMGKg-8WW1An1wXgYK_uAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-30 01:58:40
(3 weeks ago)
(xmlrpc) Apache: Failed xmlrpc access from 45.166.57.13 (BR/Brazil/-): 10 in the last 3600 secs (0-2 ...
show more
(xmlrpc) Apache: Failed xmlrpc access from 45.166.57.13 (BR/Brazil/-): 10 in the last 3600 secs (0-201)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-29 22:39:53
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 45.166.57.13 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 45.166.57.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 18:39:46.103934 2026] [security2:error] [pid 2716:tid 2716] [client 45.166.57.13:62886] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.166.57.13 (+1 hits since last alert)|airdriedrivingschool.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "airdriedrivingschool.com"] [uri "/xmlrpc.php"] [unique_id "akL0MsMWGy8clQCcUwD1JAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
konseptit
2026-06-22 16:14:31
(1 month ago)
(wordpress) Failed wordpress login from 45.166.57.13 (BR/Brazil/-)
Brute-Force