45.148.10.120
Case file
First seen on 2026-09-09T01:30:51Z, most recently active on 2026-10-04T15:06:47Z.
Recorded 475 attack-shaped requests across 21 separate days.
Its traffic probed the WordPress REST API batch endpoint, often used to fingerprint or chain other WordPress vulnerabilities; it also matched a catalogue rule; it also probed for an exposed .git directory to download the site's source history and config.
Seen from 2 of our sensors: edge, nl4-web.
Scored into the "Wanted" level, carrying the badges Regular, Toolkit, Repeat Offender.
Routed via AS48090 (Techoff Srv Limited), an ASN we classify as hosting.
Blocked on every one of our hosts and at our edge since 2026-10-04T15:29:58Z, through 2027-10-04T15:29:58Z.
Enrichment
| rDNS | none |
|---|---|
| ASN | AS48090 — Techoff Srv Limited |
| ASN type | hosting |
| Country | The Netherlands (NL) |
| Flags | none observed |
Timeline
- 2026-09-095
- 2026-09-105
- 2026-09-1112
- 2026-09-1212
- 2026-09-1344
- 2026-09-142
- 2026-09-1558
- 2026-09-1735
- 2026-09-1818
- 2026-09-209
- 2026-09-225
- 2026-09-243
- 2026-09-2617
- 2026-09-2729
- 2026-09-2847
- 2026-09-2918
- 2026-09-3019
- 2026-10-0131
- 2026-10-0237
- 2026-10-036
- 2026-10-0463
Evidence (newest first, up to 50)
| Time (UTC) | Vantage | Site | Class | Status | Evidence |
|---|---|---|---|---|---|
| 2026-10-04T15:06:47Z | nl4-web | techauthors.eu | requested the .git directory itself, hoping it is exposed and browsable | 403 | [Sun Oct 04 18:06:47.735842 2026] [authz_core:error] AH01630: client denied by server configuration: <path> |
| 2026-10-04T15:06:47Z | nl4-web | techauthors.eu | probed for an exposed .git directory to download the site's source history and config | 403 | 45.148.10.120 - - [04/Oct/2026:18:06:47 +0300] "GET /.git/config HTTP/1.1" 403 239 "-" "Mozilla/5.0 (ZZ; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" |
| 2026-10-04T14:55:11Z | nl4-web | aeroways.eu | requested the .git directory itself, hoping it is exposed and browsable | 403 | [Sun Oct 04 17:55:11.293613 2026] [authz_core:error] AH01630: client denied by server configuration: <path> |
| 2026-10-04T14:55:11Z | nl4-web | aeroways.eu | probed for an exposed .git directory to download the site's source history and config | 403 | 45.148.10.120 - - [04/Oct/2026:17:55:11 +0300] "GET /.git/config HTTP/1.1" 403 239 "-" "Mozilla/5.0 (ZZ; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36" |
| 2026-10-04T14:50:11Z | nl4-web | stefanpetkov.day | matched a catalogue rule | 403 | [Sun Oct 04 17:50:11.915486 2026] [authz_core:error] AH01630: client denied by server configuration: <path> |
| 2026-10-04T14:50:11Z | nl4-web | stefanpetkov.day | probed for an exposed .git directory to download the site's source history and config | 403 | 45.148.10.120 - - [04/Oct/2026:17:50:11 +0300] "GET /.git/config HTTP/1.1" 403 239 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.13 Mobile/15E148 Safari/604.1" |
| 2026-10-04T14:36:29Z | nl4-web | bursukov.com | requested the .git directory itself, hoping it is exposed and browsable | 403 | [Sun Oct 04 17:36:29.381996 2026] [authz_core:error] AH01630: client denied by server configuration: <path> |
| 2026-10-04T14:36:29Z | nl4-web | bursukov.com | probed for an exposed .git directory to download the site's source history and config | 403 | 45.148.10.120 - - [04/Oct/2026:17:36:29 +0300] "GET /.git/config HTTP/1.1" 403 239 "-" "Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Safari/605.1.15" |
| 2026-10-04T11:45:48Z | edge | servbg.dev | was blocked at the edge without matching any specific attack signature | {"ts":"2026-10-04T11:45:48Z","ip":"45.148.10.120","zone":"servbg.dev","host":"servbg.dev","path":"/","method":"POST","query":"<truncated>","ua":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.7 Mobile/15E148 Safari/604.1","action":"block","source"… | |
| 2026-10-04T11:45:48Z | edge | servbg.dev | probed the WordPress REST API batch endpoint, often used to fingerprint or chain other WordPress vulnerabilities | {"ts":"2026-10-04T11:45:48Z","ip":"45.148.10.120","zone":"servbg.dev","host":"servbg.dev","path":"/wp-json/batch/v1","method":"POST","query":"","ua":"Mozilla/5.0 (Windows NT 10.0; rv:139.0) Gecko/20100101 Firefox/139.0","action":"block","source":"firewallManaged","rule_id":"<redacted>","country":"NL… | |
| 2026-10-04T11:09:05Z | nl4-web | mta-sts.servbg.com | probed the WordPress REST API batch endpoint, often used to fingerprint or chain other WordPress vulnerabilities | 404 | 45.148.10.120 - - [04/Oct/2026:14:09:05 +0300] "POST /wp-json/batch/v1 HTTP/1.1" 404 236 "-" "Mozilla/5.0 (X11; Linux i686; rv:1.9.6.20) Gecko/ Firefox/3.6.17" |
| 2026-10-04T10:21:41Z | edge | zmey.eu | was blocked at the edge without matching any specific attack signature | {"ts":"2026-10-04T10:21:41Z","ip":"45.148.10.120","zone":"zmey.eu","host":"zmey.eu","path":"/","method":"POST","query":"<truncated>","ua":"Mozilla/5.0 (Debian; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36","action":"block","source":"firewallManaged","rule_id":"… | |
| 2026-10-04T10:21:41Z | edge | zmey.eu | probed the WordPress REST API batch endpoint, often used to fingerprint or chain other WordPress vulnerabilities | {"ts":"2026-10-04T10:21:41Z","ip":"45.148.10.120","zone":"zmey.eu","host":"zmey.eu","path":"/wp-json/batch/v1","method":"POST","query":"","ua":"Mozilla/5.0 (X11; Linux i686; rv:1.9.6.20) Gecko/ Firefox/11.0","action":"block","source":"firewallManaged","rule_id":"<redacted>","country":"NL","asn_org":… | |
| 2026-10-04T10:41:35Z | edge | techwriters.eu | probed the WordPress REST API batch endpoint, often used to fingerprint or chain other WordPress vulnerabilities | {"ts":"2026-10-04T10:41:35Z","ip":"45.148.10.120","zone":"techwriters.eu","host":"techwriters.eu","path":"/wp-json/batch/v1","method":"POST","query":"","ua":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.127 Safari/537.36","action":"block","… | |
| 2026-10-04T10:41:35Z | edge | techwriters.eu | was blocked at the edge without matching any specific attack signature | {"ts":"2026-10-04T10:41:35Z","ip":"45.148.10.120","zone":"techwriters.eu","host":"techwriters.eu","path":"/","method":"POST","query":"<truncated>","ua":"Mozilla/5.0 (CentOS; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36","action":"block","source":"firewallManaged"… | |
| 2026-10-04T10:48:56Z | edge | bursukov.com | was blocked at the edge without matching any specific attack signature | {"ts":"2026-10-04T10:48:56Z","ip":"45.148.10.120","zone":"bursukov.com","host":"bursukov.com","path":"/","method":"POST","query":"<truncated>","ua":"Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:109.0) Gecko/20100101 Firefox/116.0","action":"block","source":"firewallManaged","rule_id":"<redacted>","co… | |
| 2026-10-04T10:48:56Z | edge | bursukov.com | probed the WordPress REST API batch endpoint, often used to fingerprint or chain other WordPress vulnerabilities | {"ts":"2026-10-04T10:48:56Z","ip":"45.148.10.120","zone":"bursukov.com","host":"bursukov.com","path":"/wp-json/batch/v1","method":"POST","query":"","ua":"Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/46.0.2486.0 Safari/537.36 Edge/13.10586","action":"block","source":"fi… | |
| 2026-10-04T09:43:56Z | edge | urbanmoto.eu | probed the WordPress REST API batch endpoint, often used to fingerprint or chain other WordPress vulnerabilities | {"ts":"2026-10-04T09:43:56Z","ip":"45.148.10.120","zone":"urbanmoto.eu","host":"urbanmoto.eu","path":"/wp-json/batch/v1","method":"POST","query":"","ua":"Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:134.0) Gecko/20100101 Firefox/134.0","action":"block","source":"firewallManaged","rule_id":"<redacted>"… | |
| 2026-10-04T09:43:56Z | edge | urbanmoto.eu | was blocked at the edge without matching any specific attack signature | {"ts":"2026-10-04T09:43:56Z","ip":"45.148.10.120","zone":"urbanmoto.eu","host":"urbanmoto.eu","path":"/","method":"POST","query":"<truncated>","ua":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.1.3 Safari/605.1.15","action":"block","source":"fir… | |
| 2026-10-04T09:53:41Z | edge | foundyourjob.com | was blocked at the edge without matching any specific attack signature | {"ts":"2026-10-04T09:53:41Z","ip":"45.148.10.120","zone":"foundyourjob.com","host":"foundyourjob.com","path":"/","method":"POST","query":"<truncated>","ua":"Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Safari/605.1.15","action":"block","source… | |
| 2026-10-04T09:53:41Z | edge | foundyourjob.com | probed the WordPress REST API batch endpoint, often used to fingerprint or chain other WordPress vulnerabilities | {"ts":"2026-10-04T09:53:41Z","ip":"45.148.10.120","zone":"foundyourjob.com","host":"foundyourjob.com","path":"/wp-json/batch/v1","method":"POST","query":"","ua":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.10240","action… | |
| 2026-10-04T09:33:59Z | edge | aeroways.eu | was blocked at the edge without matching any specific attack signature | {"ts":"2026-10-04T09:33:59Z","ip":"45.148.10.120","zone":"aeroways.eu","host":"aeroways.eu","path":"/","method":"POST","query":"<truncated>","ua":"Mozilla/5.0 (Ubuntu; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36","action":"block","source":"firewallManaged","rule… | |
| 2026-10-04T09:33:59Z | edge | aeroways.eu | probed the WordPress REST API batch endpoint, often used to fingerprint or chain other WordPress vulnerabilities | {"ts":"2026-10-04T09:33:59Z","ip":"45.148.10.120","zone":"aeroways.eu","host":"aeroways.eu","path":"/wp-json/batch/v1","method":"POST","query":"","ua":"Mozilla/5.0 (Debian; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36","action":"block","source":"firewallManaged… | |
| 2026-10-04T08:17:10Z | edge | techauthors.eu | probed the WordPress REST API batch endpoint, often used to fingerprint or chain other WordPress vulnerabilities | {"ts":"2026-10-04T08:17:10Z","ip":"45.148.10.120","zone":"techauthors.eu","host":"techauthors.eu","path":"/wp-json/batch/v1","method":"POST","query":"","ua":"Mozilla/5.0 (X11; Linux x86_64; rv:1.9.5.20) Gecko/ Firefox/3.8","action":"block","source":"firewallManaged","rule_id":"<redacted>","country":… | |
| 2026-10-04T08:17:10Z | edge | techauthors.eu | was blocked at the edge without matching any specific attack signature | {"ts":"2026-10-04T08:17:10Z","ip":"45.148.10.120","zone":"techauthors.eu","host":"techauthors.eu","path":"/","method":"POST","query":"<truncated>","ua":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36","action":"block","source":"f… | |
| 2026-10-04T09:03:25Z | edge | stefanpetkov.day | probed the WordPress REST API batch endpoint, often used to fingerprint or chain other WordPress vulnerabilities | {"ts":"2026-10-04T09:03:25Z","ip":"45.148.10.120","zone":"stefanpetkov.day","host":"stefanpetkov.day","path":"/wp-json/batch/v1","method":"POST","query":"","ua":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.1 Safari/605.1.15","action":"block","s… | |
| 2026-10-04T09:03:25Z | edge | stefanpetkov.day | was blocked at the edge without matching any specific attack signature | {"ts":"2026-10-04T09:03:25Z","ip":"45.148.10.120","zone":"stefanpetkov.day","host":"stefanpetkov.day","path":"/","method":"POST","query":"<truncated>","ua":"Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/111.0","action":"block","source":"firewallManaged","rule_id":"<redac… | |
| 2026-10-04T08:56:15Z | edge | comops.eu | probed the WordPress REST API batch endpoint, often used to fingerprint or chain other WordPress vulnerabilities | {"ts":"2026-10-04T08:56:15Z","ip":"45.148.10.120","zone":"comops.eu","host":"comops.eu","path":"/wp-json/batch/v1","method":"POST","query":"","ua":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:124.0) Gecko/20100101 Firefox/124.0","action":"block","source":"firewallManaged","rule_id":"<redacted>"… | |
| 2026-10-04T08:56:15Z | edge | comops.eu | was blocked at the edge without matching any specific attack signature | {"ts":"2026-10-04T08:56:15Z","ip":"45.148.10.120","zone":"comops.eu","host":"comops.eu","path":"/","method":"POST","query":"<truncated>","ua":"Mozilla/5.0 (Macintosh; Intel Mac OS X 14) AppleWebKit/620.32 (KHTML, like Gecko) Version/17.1.10 Safari/620.32","action":"block","source":"firewallManaged",… | |
| 2026-10-04T08:08:38Z | edge | amosix.eu | probed the WordPress REST API batch endpoint, often used to fingerprint or chain other WordPress vulnerabilities | {"ts":"2026-10-04T08:08:38Z","ip":"45.148.10.120","zone":"amosix.eu","host":"amosix.eu","path":"/wp-json/batch/v1","method":"POST","query":"","ua":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.132 Safari/537.36","action":"block","source":"firewall… | |
| 2026-10-04T08:08:38Z | edge | amosix.eu | was blocked at the edge without matching any specific attack signature | {"ts":"2026-10-04T08:08:38Z","ip":"45.148.10.120","zone":"amosix.eu","host":"amosix.eu","path":"/","method":"POST","query":"<truncated>","ua":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.3 Mobile/15E148 Safari/604.1","action":"block","source":"… | |
| 2026-10-04T07:42:44Z | edge | servbg.com | probed the WordPress REST API batch endpoint, often used to fingerprint or chain other WordPress vulnerabilities | {"ts":"2026-10-04T07:42:44Z","ip":"45.148.10.120","zone":"servbg.com","host":"servbg.com","path":"/wp-json/batch/v1","method":"POST","query":"","ua":"Mozilla/5.0 (X11; Linux x86_64; rv:1.9.5.20) Gecko/ Firefox/15.0","action":"block","source":"firewallManaged","rule_id":"<redacted>","country":"NL","a… | |
| 2026-10-04T07:42:44Z | edge | servbg.com | was blocked at the edge without matching any specific attack signature | {"ts":"2026-10-04T07:42:44Z","ip":"45.148.10.120","zone":"servbg.com","host":"servbg.com","path":"/","method":"POST","query":"<truncated>","ua":"Mozilla/5.0 (SS; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36","action":"block","source":"firewallManaged","rule_id"… | |
| 2026-10-04T06:14:29Z | edge | schetio.com | was blocked at the edge without matching any specific attack signature | {"ts":"2026-10-04T06:14:29Z","ip":"45.148.10.120","zone":"schetio.com","host":"schetio.com","path":"/","method":"POST","query":"<truncated>","ua":"Mozilla/5.0 (Windows NT 10.0; WOW64; rv:70.0) Gecko/20100101 Firefox/70.0","action":"block","source":"firewallManaged","rule_id":"<redacted>","country":"… | |
| 2026-10-04T06:14:29Z | edge | schetio.com | probed the WordPress REST API batch endpoint, often used to fingerprint or chain other WordPress vulnerabilities | {"ts":"2026-10-04T06:14:29Z","ip":"45.148.10.120","zone":"schetio.com","host":"schetio.com","path":"/wp-json/batch/v1","method":"POST","query":"","ua":"Mozilla/5.0 (SS; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36","action":"block","source":"firewallManaged","r… | |
| 2026-10-04T06:41:55Z | edge | recmydays.com | probed the WordPress REST API batch endpoint, often used to fingerprint or chain other WordPress vulnerabilities | {"ts":"2026-10-04T06:41:55Z","ip":"45.148.10.120","zone":"recmydays.com","host":"recmydays.com","path":"/wp-json/batch/v1","method":"POST","query":"","ua":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36","action":"block","source":"firewallManage… | |
| 2026-10-04T06:41:55Z | edge | recmydays.com | was blocked at the edge without matching any specific attack signature | {"ts":"2026-10-04T06:41:55Z","ip":"45.148.10.120","zone":"recmydays.com","host":"recmydays.com","path":"/","method":"POST","query":"<truncated>","ua":"Mozilla/5.0 (Fedora; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36","action":"block","source":"firewallManaged"… | |
| 2026-10-04T06:28:50Z | edge | homocontinum.org | probed the WordPress REST API batch endpoint, often used to fingerprint or chain other WordPress vulnerabilities | {"ts":"2026-10-04T06:28:50Z","ip":"45.148.10.120","zone":"homocontinum.org","host":"homocontinum.org","path":"/wp-json/batch/v1","method":"POST","query":"","ua":"Mozilla/5.0 (Knoppix; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36","action":"block","source":"fire… | |
| 2026-10-04T06:28:50Z | edge | homocontinum.org | was blocked at the edge without matching any specific attack signature | {"ts":"2026-10-04T06:28:50Z","ip":"45.148.10.120","zone":"homocontinum.org","host":"homocontinum.org","path":"/","method":"POST","query":"<truncated>","ua":"Mozilla/5.0 (X11; Linux x86_64; rv:1.9.7.20) Gecko/ Firefox/3.6.7","action":"block","source":"firewallManaged","rule_id":"<redacted>","country"… | |
| 2026-10-04T06:00:56Z | edge | victorantonov.com | probed the WordPress REST API batch endpoint, often used to fingerprint or chain other WordPress vulnerabilities | {"ts":"2026-10-04T06:00:56Z","ip":"45.148.10.120","zone":"victorantonov.com","host":"victorantonov.com","path":"/wp-json/batch/v1","method":"POST","query":"","ua":"Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0","action":"block","source":"firewallManaged","rule_id":"<… | |
| 2026-10-04T06:00:56Z | edge | victorantonov.com | was blocked at the edge without matching any specific attack signature | {"ts":"2026-10-04T06:00:56Z","ip":"45.148.10.120","zone":"victorantonov.com","host":"victorantonov.com","path":"/","method":"POST","query":"<truncated>","ua":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36","action":"block","source":"firewallMan… | |
| 2026-10-04T05:59:27Z | edge | svestnik.com | probed the WordPress REST API batch endpoint, often used to fingerprint or chain other WordPress vulnerabilities | {"ts":"2026-10-04T05:59:27Z","ip":"45.148.10.120","zone":"svestnik.com","host":"svestnik.com","path":"/wp-json/batch/v1","method":"POST","query":"","ua":"Mozilla/5.0 (Windows NT 10.0; WOW64; rv:70.0) Gecko/20100101 Firefox/70.0","action":"block","source":"firewallManaged","rule_id":"<redacted>","cou… | |
| 2026-10-04T05:59:27Z | edge | svestnik.com | was blocked at the edge without matching any specific attack signature | {"ts":"2026-10-04T05:59:27Z","ip":"45.148.10.120","zone":"svestnik.com","host":"svestnik.com","path":"/","method":"POST","query":"<truncated>","ua":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2.1 Safari/605.1.15","action":"block","source":"fir… | |
| 2026-10-04T05:57:43Z | edge | servmoto.com | probed the WordPress REST API batch endpoint, often used to fingerprint or chain other WordPress vulnerabilities | {"ts":"2026-10-04T05:57:43Z","ip":"45.148.10.120","zone":"servmoto.com","host":"servmoto.com","path":"/wp-json/batch/v1","method":"POST","query":"","ua":"Mozilla/5.0 (Knoppix; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36","action":"block","source":"firewallMana… | |
| 2026-10-04T05:57:43Z | edge | servmoto.com | was blocked at the edge without matching any specific attack signature | {"ts":"2026-10-04T05:57:43Z","ip":"45.148.10.120","zone":"servmoto.com","host":"servmoto.com","path":"/","method":"POST","query":"<truncated>","ua":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1 Mobile/15E148 Safari/604.1","action":"block","sou… | |
| 2026-10-04T06:04:02Z | edge | odor-ex.com | was blocked at the edge without matching any specific attack signature | {"ts":"2026-10-04T06:04:02Z","ip":"45.148.10.120","zone":"odor-ex.com","host":"odor-ex.com","path":"/","method":"POST","query":"<truncated>","ua":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.10 Safari/605.1.1","action":"block","source":"firewal… | |
| 2026-10-04T06:04:02Z | edge | odor-ex.com | probed the WordPress REST API batch endpoint, often used to fingerprint or chain other WordPress vulnerabilities | {"ts":"2026-10-04T06:04:02Z","ip":"45.148.10.120","zone":"odor-ex.com","host":"odor-ex.com","path":"/wp-json/batch/v1","method":"POST","query":"","ua":"Mozilla/5.0 (Knoppix; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36","action":"block","source":"firewallManaged"… | |
| 2026-10-04T05:57:54Z | edge | obdebug.com | was blocked at the edge without matching any specific attack signature | {"ts":"2026-10-04T05:57:54Z","ip":"45.148.10.120","zone":"obdebug.com","host":"obdebug.com","path":"/","method":"POST","query":"<truncated>","ua":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.75 Safari/537.36","action":"block","source":"firewallM… | |
| 2026-10-04T05:57:54Z | edge | obdebug.com | probed the WordPress REST API batch endpoint, often used to fingerprint or chain other WordPress vulnerabilities | {"ts":"2026-10-04T05:57:54Z","ip":"45.148.10.120","zone":"obdebug.com","host":"obdebug.com","path":"/wp-json/batch/v1","method":"POST","query":"","ua":"Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Safari/605.1.15","action":"block","source":"fi… | |
| 2026-10-04T05:56:34Z | edge | neutralizatori.com | was blocked at the edge without matching any specific attack signature | {"ts":"2026-10-04T05:56:34Z","ip":"45.148.10.120","zone":"neutralizatori.com","host":"neutralizatori.com","path":"/","method":"POST","query":"<truncated>","ua":"Mozilla/5.0 (X11; Linux x86_64; rv:1.9.6.20) Gecko/ Firefox/3.6.3","action":"block","source":"firewallManaged","rule_id":"<redacted>","coun… |
Report history
No abuse report sent for this address yet.
Not currently correlated with any campaign.
Dispute or removal: [email protected] — reference 45.148.10.120 (mailbox goes live with phase 3). See /threats/about for the method and the 7-day review window.
card.svg (used as this page's og:image)