๐บ๐ธ
TPI-Abuse
2026-08-25 00:07:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.242 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 20:06:55.770418 2026] [security2:error] [pid 659202:tid 659205] [client 45.130.203.242:21813] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "staging.torreydc.com"] [uri "/.git/HEAD"] [unique_id "aozcn5RRQG83ATpa4pKMMwAAAUE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-24 23:07:12
(1 day ago)
Automated web scanner. Requested suspicious paths: /.git/HEAD. UTC: 2026-08-24 22:50:26.
Web App Attack
Anonymous
2026-08-24 21:52:49
(1 day ago)
Reported from Nginx log analysis 16. Log: 45.130.203.242 - - [24/Aug/2026:xx:xx:xx 0200] "GET /www/ ...
show more
Reported from Nginx log analysis 16. Log: 45.130.203.242 - - [24/Aug/2026:xx:xx:xx 0200] "GET /www/ HTTP/1.1" xxx xxx "-" "Mozilla/5.0" "-" "DZ Algeria A\xC3\xAFn Taya" "AS137409" "GSL Networks Pty LTD"
show less
Port Scan
Brute-Force
SSH
๐บ๐ธ
jkhorvath.com
2026-08-24 20:24:02
(1 day ago)
Request for URL /www/
Phishing
Brute-Force
Web App Attack
๐บ๐ธ
azminawwar
2026-08-24 14:53:10
(1 day ago)
[45.130.203.242] triggered by honeypot on port [80], Timestamp [2026-08-24T14:53:10Z]METHOD=GET PATH ...
show more
[45.130.203.242] triggered by honeypot on port [80], Timestamp [2026-08-24T14:53:10Z]METHOD=GET PATH=/www/ HTTP=HTTP/1.1 UA="Mozilla/5.0" HOST="95.182.92.103:80" REF="-"
show less
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-24 09:42:24
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.242 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 05:42:10.741969 2026] [security2:error] [pid 27298:tid 27298] [client 45.130.203.242:60525] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.productosdelimpiezamagiccleannayarit.com.spyasociados.com"] [uri "/.git/HEAD"] [unique_id "aowR8sjD1lmcIZrQ1i-7bQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 02:56:59
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.242 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 22:56:56.005955 2026] [security2:error] [pid 6742:tid 6742] [client 45.130.203.242:49795] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rimaine.org"] [uri "/.git/HEAD"] [unique_id "aouy-GOxXStsshYd5uUs4AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
mnazibo
2026-08-24 00:45:24
(2 days ago)
Date: Aug 24 03:42:22 2026 EAT | Reported IP: 45.130.203.242 mod_security | id: 920350 953100 959100 ...
show more
Date: Aug 24 03:42:22 2026 EAT | Reported IP: 45.130.203.242 mod_security | id: 920350 953100 959100 | DE/usernameab.my_domain/- | Connections: 1 | Blocked: Permanent Block: [LF_MODSEC] | Logs: ; Host header is a numeric IP address; PHP Information Leakage; Outbound Anomaly Score Exceeded (Total Score: 4)
show less
SQL Injection
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-23 19:56:48
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.242 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 15:56:42.650180 2026] [security2:error] [pid 31656:tid 31656] [client 45.130.203.242:22693] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.advancedmotorsports.com"] [uri "/.git/HEAD"] [unique_id "aotQeoobMUncDwWIG6Yx_AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-23 15:41:20
(2 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 11:15:00
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.242 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 07:14:35.736941 2026] [security2:error] [pid 29280:tid 29280] [client 45.130.203.242:35199] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.kh6jim.com"] [uri "/.git/HEAD"] [unique_id "aorWG7X-lm3sT4JDAPIzHwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-08-23 00:11:52
(3 days ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 45.130.203.242 - - [18/Aug/2026:04:12:39 +0300] " ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 45.130.203.242 - - [18/Aug/2026:04:12:39 +0300] "GET /.git/HEAD HTTP/1.1" 301 162 "-" "Python-urllib/3.10"
show less
Web App Attack
๐ต๐ฑ
miriks
2026-08-22 21:28:17
(3 days ago)
Automated scan detected: GET /.git/HEAD โ UA: Python-urllib/3.10
Port Scan
Web App Attack
๐ฏ๐ต
knock
2026-08-22 18:18:38
(3 days ago)
Knock-Knock honeypot brute-force: proto8 (1 total hits)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-22 13:51:27
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 45.130.203.242 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 45.130.203.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 09:51:23.976763 2026] [security2:error] [pid 10121:tid 10121] [client 45.130.203.242:29257] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "hamiltonbookings.com"] [uri "/.git/HEAD"] [unique_id "aompW1_6L9uI1RA0-IvPvAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack