๐บ๐ธ
TPI-Abuse
2026-08-21 18:39:06
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.144 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 14:39:02.077419 2026] [security2:error] [pid 11927:tid 11927] [client 45.130.203.144:31309] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adampayments.com"] [uri "/.git/HEAD"] [unique_id "aoibRoqNboCoFIEr0GAyCQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐ท
bubausluge
2026-08-21 10:19:16
(11 hours ago)
Blocked by https://aegis.hr โ WAF ModSecurity Alert - (MITRE T1190), 3 attempts, Period: 2026-08-21 ...
show more
Blocked by https://aegis.hr โ WAF ModSecurity Alert - (MITRE T1190), 3 attempts, Period: 2026-08-21 10:01:07 to 2026-08-21 10:01:07
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-21 09:46:54
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.144 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 05:46:47.282849 2026] [security2:error] [pid 30708:tid 30708] [client 45.130.203.144:51761] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "laboquimia.es"] [uri "/.git/HEAD"] [unique_id "aogeh1bBJ8-i3n8ANl_oWwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-08-21 06:28:54
(15 hours ago)
Accessed trap at '/.git/HEAD'
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 04:31:34
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.144 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 00:31:27.486623 2026] [security2:error] [pid 24347:tid 24366] [client 45.130.203.144:20011] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "busybeerestaurant.com"] [uri "/.git/HEAD"] [unique_id "aofUn6GM9TT_YLVJc8FcwgAAAIM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
mscode.pl
2026-08-21 02:07:43
(19 hours ago)
Triggered Cloudflare WAF (bic) from DE.
Action taken: BLOCK
ASN: 137409 (GSL Networks Pty LTD)
Proto ...
show more
Triggered Cloudflare WAF (bic) from DE.
Action taken: BLOCK
ASN: 137409 (GSL Networks Pty LTD)
Protocol: HTTP/1.1 (GET method)
Zone: mscode.pl
Endpoint: /.git/HEAD
UA: Python-urllib/3.10
show less
Bad Web Bot
๐บ๐ฆ
URAN Publishing Service
2026-08-20 16:31:29
(1 day ago)
[20/Aug/2026:19:31:29 +0300] -- 45.130.203.144 Ban reason: User-Agent Python-urllib
Bad Web Bot
Web App Attack
Anonymous
2026-08-20 15:52:31
(1 day ago)
Reported from Nginx log analysis 6. Log: 45.130.203.144 - - [20/Aug/2026:xx:xx:xx 0200] "GET / HTTP ...
show more
Reported from Nginx log analysis 6. Log: 45.130.203.144 - - [20/Aug/2026:xx:xx:xx 0200] "GET / HTTP/1.1" xxx xxx "-" "Mozilla/5.0" "-" "DZ Algeria A\xC3\xAFn Taya" "AS137409" "GSL Networks Pty LTD"
show less
Port Scan
Brute-Force
SSH
๐ฆ๐บ
paulshipley.com.au
2026-08-18 03:33:33
(3 days ago)
[Tue Aug 18 13:33:33.523686 2026] [security2:error] [pid 196794] [client 45.130.203.144:64367] [clie ...
show more
[Tue Aug 18 13:33:33.523686 2026] [security2:error] [pid 196794] [client 45.130.203.144:64367] [client 45.130.203.144] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "iaki.com.au"] [uri "/.git/HEAD"] [unique_id "aoPSjTUvbsM_a6p9PTyo1wAAAAQ"]
...
show less
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-18 03:23:57
(3 days ago)
cloudlinux2 fail2ban: 2026-08-18 05:19:16,700 fail2ban.actions [1456]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-18 05:19:16,700 fail2ban.actions [1456]: NOTICE [plesk-modsecurity] Unban 35.192.122.10cloudlinux2 fail2ban: 2026-08-18 05:19:40,045 fail2ban.filter [1456]: INFO [plesk-modsecurity] Found 45.130.203.144 - 2026-08-18 05:19:39cloudlinux2 fail2ban: 2026-08-18 05:19:40,029 fail2ban.filter [1456]: INFO [plesk-modsecurity] Found 125.62.196.68 - 2026-08-18 05:19:39cloudlinux2 fail2ban: 2026-08-18 05:20:00,984 fail2ban.filter [1456]: INFO [plesk-modsecurity] Found 125.62.196.68 - 2026-08-18 05:20:00cloudlinux2 fail2ban: 2026-08-18 05:19:59,367 fail2ban.filter [1456]: INFO [plesk-modsecurity] Found 136.119.246.88 - 2026-08-18 05:19:59cloudlinux2 fail2ban: 2026-08-18 05:19:58,936 fail2ban.filter [1456]: INFO [plesk-modsecurity] Found 136.119.246.88 - 2026-08-18 05:19:58cloudlinux2 fail2ban: 2026-08-18 05:19:59,355 fail2ban.filter [1456]: INFO [plesk-modsecurity] Found 136.119.246.88 - 2026-08-18 05:19:59cloudlinux2 f
show less
Brute-Force
๐ฆ๐น
Renรฉ Hickersberger
2026-08-18 00:21:45
(3 days ago)
malicious bot detected: violations="hit-honeypot"; user_agent="Python-urllib/3.10"
Web App Attack
๐ฌ๐ง
myintarweb
2026-08-15 00:07:17
(6 days ago)
45.130.203.144 - - [15/Jul/2026:00:39:27 +0100] 80 "GET /.git/HEAD HTTP/1.1" 301 1641 "-" "Python-ur ...
show more
45.130.203.144 - - [15/Jul/2026:00:39:27 +0100] 80 "GET /.git/HEAD HTTP/1.1" 301 1641 "-" "Python-urllib/3.10"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐น๐ท
neron
2026-07-28 20:19:38
(3 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-07-28 12:54:30
(3 weeks ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 00:46:17
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.144 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 20:46:09.874163 2026] [security2:error] [pid 1669265:tid 1669265] [client 45.130.203.144:30205] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.csmedicalbilling.com"] [uri "/.env"] [unique_id "amFkUW69BtaIMia_Xv2AYQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack