Anonymous
2026-07-01 04:37:13
(2 months ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
π¦πΊ
2000cn.com.au
2026-07-01 00:37:32
(2 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-wordpress-scan
Web App Attack
Hacking
πΊπΈ
TAY
2026-06-14 16:59:07
(2 months ago)
45.130.202.50 - - [15/Jun/2026:00:53:18 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5874 "-" "Jetpack by ...
show more
45.130.202.50 - - [15/Jun/2026:00:53:18 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5874 "-" "Jetpack by WordPress.com"
45.130.202.50 - - [15/Jun/2026:00:57:00 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5874 "-" "Jetpack/12.1; WordPress/6.3; http://site69797897.com"
45.130.202.50 - - [15/Jun/2026:00:59:07 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5874 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.1)"
...
show less
Brute-Force
πͺπΈ
librebit
2026-06-14 08:42:34
(2 months ago)
Brute force
Brute-Force
πΊπΈ
TPI-Abuse
2026-06-13 21:53:18
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 45.130.202.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.202.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 17:53:11.798322 2026] [security2:error] [pid 29675:tid 29675] [client 45.130.202.50:34579] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.airei.com"] [uri "/.env.production"] [unique_id "ai3RR1B94u_mIQfGLWOzYgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-13 21:07:44
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 45.130.202.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.202.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 17:07:40.430338 2026] [security2:error] [pid 11358:tid 11361] [client 45.130.202.50:25727] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "afghanistantraveller.com.adetnw.com"] [uri "/.env"] [unique_id "ai3GnGWJ6EuAsd3pFVDOpwAAAMA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-13 19:46:24
(2 months ago)
45.130.202.50 - - [13/Jun/2026:21:46:00 +0200] "GET /wp-includes/file.php HTTP/1.1" 404 493 "-" "Moz ...
show more
45.130.202.50 - - [13/Jun/2026:21:46:00 +0200] "GET /wp-includes/file.php HTTP/1.1" 404 493 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95"
45.130.202.50 - - [13/Jun/2026:21:46:00 +0200] "GET /wp-content/themes.php HTTP/1.1" 404 493 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36"
45.130.202.50 - - [13/Jun/2026:21:46:01 +0200] "GET /wp-includes/block-patterns/about.php HTTP/1.1" 404 493 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36"
45.130.202.50 - - [13/Jun/2026:21:46:01 +0200] "GET /worm0.PhP7 HTTP/1.1" 404 493 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)"
45.130.202.50 - - [13/Jun/2026:21:46:01 +0200] "GET /wp-includes/load.php HTTP/1.1" 404 493 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0"
45.130
...
show less
DDoS Attack
π³π΄
jad-abuse
2026-06-13 09:59:23
(2 months ago)
ThreatFeed automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure ...
show more
ThreatFeed automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 1 hits.
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-13 09:32:17
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 45.130.202.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.202.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 05:32:14.804124 2026] [security2:error] [pid 27578:tid 27578] [client 45.130.202.50:45851] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.trhs70.rwcartoons.com"] [uri "/.git/HEAD"] [unique_id "ai0jntNfQ-FcuqFlnH69aQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-13 06:14:19
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 45.130.202.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.202.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 02:14:12.743862 2026] [security2:error] [pid 16295:tid 16295] [client 45.130.202.50:41381] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hello.fydelity.net"] [uri "/.git/HEAD"] [unique_id "aiz1NJ2NdCK7OSeKXWyrlwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-06-12 21:12:50
(2 months ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-12 18:51:52
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 45.130.202.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.202.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 14:51:48.856250 2026] [security2:error] [pid 1722:tid 1722] [client 45.130.202.50:57329] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bigislandhawaiirealty.com.kh6jim.com"] [uri "/.env"] [unique_id "aixVRB3Gh05SI9MVBh5gzQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
ghostwarriors
2026-06-12 18:20:13
(2 months ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-06-12 09:43:48
(2 months ago)
Multiple WAF Violations
Web App Attack
π©πͺ
YF
2026-06-12 05:00:29
(2 months ago)
Git HEAD exposure probe
Web App Attack