๐บ๐ธ
TPI-Abuse
2026-09-21 12:57:27
(3 days ago)
(mod_security) mod_security (id:240000) triggered by 45.132.224.40 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 45.132.224.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 08:57:20.708447 2026] [security2:error] [pid 10909:tid 10909] [client 45.132.224.40:45865] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||www.schonplanet.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "www.schonplanet.com"] [uri "/images/stories/themes.php"] [unique_id "arEpsCf9mfraK8rJtBXMIgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
NXTwoThou
2026-09-21 11:29:00
(3 days ago)
/wp-includes/js/tinymce/utils/
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 07:40:33
(4 days ago)
(mod_security) mod_security (id:240000) triggered by 45.132.224.40 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 45.132.224.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 03:40:29.073231 2026] [security2:error] [pid 20728:tid 20728] [client 45.132.224.40:38211] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||www.act-research.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "www.act-research.com"] [uri "/images/stories/themes.php"] [unique_id "arDfbQ0eYtP9amVEEhKtlgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
abivia
2026-09-20 18:04:57
(4 days ago)
Abivia WAF trigger: Rule not-wp: WP probing on non-WP site uri: /wp-content/
Hacking
Web App Attack
Anonymous
2026-09-20 00:39:33
(5 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-18 18:18:23
(6 days ago)
IP matched detection query many 3xx errors.
Brute-Force
๐ณ๐ฑ
Site.eu
2026-09-18 03:59:35
(1 week ago)
Excessive 404/403 errors
Brute-Force
๐ซ๐ท
dynamix
2026-09-17 23:25:43
(1 week ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
bescared
2026-09-16 15:15:28
(1 week ago)
F2B - Malicious activity detected. URL Probing. -8ff06ede-
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 13:19:05
(1 week ago)
(mod_security) mod_security (id:240000) triggered by 45.132.224.40 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 45.132.224.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 09:18:58.492825 2026] [security2:error] [pid 10508:tid 10508] [client 45.132.224.40:26017] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||hope4elsalvador.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "hope4elsalvador.org"] [uri "/images/stories/themes.php"] [unique_id "aqqXQhQA0wTdTtK0cTYPjQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-16 09:07:49
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-admin-interface-probing
Web App Attack
Hacking
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-13 12:28:31
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-12 20:09:51
(1 week ago)
(mod_security) mod_security (id:240000) triggered by 45.132.224.40 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 45.132.224.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 16:09:45.227406 2026] [security2:error] [pid 1375:tid 1375] [client 45.132.224.40:33043] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||www.mohsep-eg.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "www.mohsep-eg.com"] [uri "/images/stories/themes.php"] [unique_id "aqWxiQW2aW5JzWmofkZinAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-11 05:47:19
(2 weeks ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-10 12:19:20
(2 weeks ago)
(mod_security) mod_security (id:240000) triggered by 45.132.224.40 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 45.132.224.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 08:19:16.441024 2026] [security2:error] [pid 20083:tid 20083] [client 45.132.224.40:30511] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||wsdtc.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "wsdtc.net"] [uri "/images/stories/themes.php"] [unique_id "aqKgRPYAMq6AgLVf5LkAXwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack