๐บ๐ธ
derekgallardo01
2026-07-30 17:16:23
(3 weeks ago)
Auto-reported by Worker: AiTM toolkit UA fingerprint CRITICAL: auto-add to BadIPS Named Location + r ...
show more
Auto-reported by Worker: AiTM toolkit UA fingerprint CRITICAL: auto-add to BadIPS Named Location + report to AbuseIPDB.. Detection: AiTM toolkit UA fingerprint (Tycoon/EvilProxy portal-browser). Blocked at Conditional Access gate.
show less
Brute-Force
Web App Attack
๐บ๐ธ
derekgallardo01
2026-07-24 20:46:03
(4 weeks ago)
Auto-reported by Worker: AiTM toolkit UA fingerprint CRITICAL: auto-add to BadIPS Named Location + r ...
show more
Auto-reported by Worker: AiTM toolkit UA fingerprint CRITICAL: auto-add to BadIPS Named Location + report to AbuseIPDB.. Detection: AiTM toolkit UA fingerprint (Tycoon/EvilProxy portal-browser). Blocked at Conditional Access gate.
show less
Brute-Force
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-07-04 12:53:18
(1 month ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
NL/Netherlands/-
Web App Attack
Anonymous
2026-07-01 04:42:32
(1 month ago)
45.130.202.5 - - [01/Jul/2026:12:42:24 +0800] "GET /wp-content/plugins/dummyyummy/wp-signup.php HTTP ...
show more
45.130.202.5 - - [01/Jul/2026:12:42:24 +0800] "GET /wp-content/plugins/dummyyummy/wp-signup.php HTTP/1.1" 404 196 "http://nowbaogumovies.com/wp-content/plugins/dummyyummy/wp-signup.php" "Go-http-client/1.1"
45.130.202.5 - - [01/Jul/2026:12:42:25 +0800] "GET /wp-content/plugins/core/core.php HTTP/1.1" 404 196 "http://nowbaogumovies.com/wp-content/plugins/core/core.php" "Go-http-client/1.1"
45.130.202.5 - - [01/Jul/2026:12:42:26 +0800] "GET /wp-content/plugins/schema/yanz.php HTTP/1.1" 404 196 "http://nowbaogumovies.com/wp-content/plugins/schema/yanz.php" "Go-http-client/1.1"
45.130.202.5 - - [01/Jul/2026:12:42:27 +0800] "GET /wp-content/plugins/pwnd-1/pwnd.php HTTP/1.1" 404 196 "http://nowbaogumovies.com/wp-content/plugins/pwnd-1/pwnd.php" "Go-http-client/1.1"
45.130.202.5 - - [01/Jul/2026:12:42:27 +0800] "GET /wp-content/plugins/init-help/init.php HTTP/1.1" 404 196 "http://nowbaogumovies.com/wp-content/plugins/init-help/init.php" "Go-http-client/1.1"
45.130.202.5 - - [01/Jul/2026:12:42
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
AGEPCom
2026-07-01 01:06:50
(1 month ago)
Smart-Ban: IP bannie via score AbuseIPDB
Brute-Force
Web App Attack
๐บ๐ธ
TAY
2026-06-14 16:58:57
(2 months ago)
45.130.202.5 - - [15/Jun/2026:00:54:32 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5874 "-" "WordPress.co ...
show more
45.130.202.5 - - [15/Jun/2026:00:54:32 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5874 "-" "WordPress.com; https://wordpress.com"
45.130.202.5 - - [15/Jun/2026:00:55:36 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5874 "-" "Jetpack by WordPress.com"
45.130.202.5 - - [15/Jun/2026:00:58:57 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5874 "-" "Jetpack/12.5; WordPress/6.1; http://site45104056.com"
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-13 21:07:51
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 45.130.202.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.202.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 17:07:43.342185 2026] [security2:error] [pid 31816:tid 31856] [client 45.130.202.5:25267] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nomadic-welshman.adetnw.com"] [uri "/.env.production"] [unique_id "ai3Gn5RZE5denwmHnykAZwAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 10:29:55
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 45.130.202.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.202.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 06:29:47.766993 2026] [security2:error] [pid 9712:tid 9712] [client 45.130.202.5:54919] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ptr.dutchlake.com"] [uri "/.git/HEAD"] [unique_id "ai0xG9g_R_Gz1YZV22rbcgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 08:45:21
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 45.130.202.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.202.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 04:45:16.485562 2026] [security2:error] [pid 11767:tid 11767] [client 45.130.202.5:65147] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.perissosdigitalmarketing.com.kevinfranz.com"] [uri "/.git/HEAD"] [unique_id "ai0YnKwY3TO0a9_jelfQsAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 07:41:25
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 45.130.202.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.202.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 03:41:20.095068 2026] [security2:error] [pid 27100:tid 27100] [client 45.130.202.5:58051] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grayarea.us"] [uri "/wp-includes/wp-config.php"] [unique_id "ai0JoPdc302abXGVmU81XgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-06-12 18:20:27
(2 months ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 09:12:22
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 45.130.202.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.202.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 05:12:18.696501 2026] [security2:error] [pid 32398:tid 32398] [client 45.130.202.5:35755] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.studioyau.com"] [uri "/.git/HEAD"] [unique_id "aivNch_WBIRJjagFKN2_QwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 06:16:42
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 45.130.202.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.202.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 02:16:37.726525 2026] [security2:error] [pid 10301:tid 10301] [client 45.130.202.5:22691] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ace.jmnr.net"] [uri "/.git/HEAD"] [unique_id "aiukRdsZCrEb7ZMsj93VEwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
YF
2026-06-12 05:00:29
(2 months ago)
Git HEAD exposure probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 04:53:23
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 45.130.202.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.202.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 00:53:19.050517 2026] [security2:error] [pid 11303:tid 11303] [client 45.130.202.5:39903] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.aticom.es"] [uri "/.env.production"] [unique_id "aiuQv-llxgX0OaKsFuxz5gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack