๐บ๐ธ
TPI-Abuse
2026-09-21 12:57:12
(1 week ago)
(mod_security) mod_security (id:240000) triggered by 45.132.224.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 45.132.224.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 08:57:07.421056 2026] [security2:error] [pid 4527:tid 4527] [client 45.132.224.45:43975] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||www.joshuashands.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "www.joshuashands.org"] [uri "/images/stories/themes.php"] [unique_id "arEpo2wMHpR94_AHnRD99AAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
NXTwoThou
2026-09-21 11:56:00
(1 week ago)
/wp-includes/js/tinymce/utils/
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 10:33:11
(1 week ago)
(mod_security) mod_security (id:240000) triggered by 45.132.224.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 45.132.224.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 06:33:06.519392 2026] [security2:error] [pid 12240:tid 12240] [client 45.132.224.45:40277] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "87"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||1healthplace.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "1healthplace.com"] [uri "/images/stories/themes.php"] [unique_id "arEH4mXpvsVFb28K16LskwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 02:58:26
(1 week ago)
IP matched detection query many 3xx errors.
Brute-Force
Anonymous
2026-09-20 19:36:09
(1 week ago)
45.132.224.45 - - [20/Sep/2026:16:35:58 -0300] "GET /wp-content/themes/news-portal/error.php HTTP/1. ...
show more
45.132.224.45 - - [20/Sep/2026:16:35:58 -0300] "GET /wp-content/themes/news-portal/error.php HTTP/1.1" 301 162 "-" "Go-http-client/1.1"
45.132.224.45 - - [20/Sep/2026:16:36:03 -0300] "GET /wp-content/themes/fukasawa/inc/classes/403.php HTTP/1.1" 301 162 "-" "Go-http-client/1.1"
45.132.224.45 - - [20/Sep/2026:16:36:08 -0300] "GET /wp-content/plugins/hello-plus/classes/ehp-sarang.php HTTP/1.1" 301 162 "-" "Go-http-client/1.1"
...
show less
Port Scan
๐ฏ๐ต
ki3
2026-09-20 17:30:25
(1 week ago)
Fail2Ban: Web App Attacks and Forum Spam 45.132.224.45 1789925424.0(JST)
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 15:35:26
(1 week ago)
(mod_security) mod_security (id:240000) triggered by 45.132.224.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 45.132.224.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:35:20.519579 2026] [security2:error] [pid 13013:tid 13013] [client 45.132.224.45:60399] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||www.sophcomp.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "www.sophcomp.com"] [uri "/images/stories/themes.php"] [unique_id "aq_9OIx6JGAcLEuBeYNzOwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 00:38:19
(1 week ago)
IP matched detection query many 3xx errors.
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-19 02:24:11
(1 week ago)
(mod_security) mod_security (id:240000) triggered by 45.132.224.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 45.132.224.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 22:24:05.850634 2026] [security2:error] [pid 14161:tid 14161] [client 45.132.224.45:44125] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||www.orlando-windsor-villa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "www.orlando-windsor-villa.com"] [uri "/images/stories/themes.php"] [unique_id "aq3yRVi9JwXP2nWACPbu_wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-18 18:18:34
(1 week ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ซ๐ท
dynamix
2026-09-17 23:27:54
(1 week ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 13:19:25
(1 week ago)
(mod_security) mod_security (id:240000) triggered by 45.132.224.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 45.132.224.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 09:19:19.265040 2026] [security2:error] [pid 9546:tid 9546] [client 45.132.224.45:45927] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||www.walkingwithghosts.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "www.walkingwithghosts.com"] [uri "/images/stories/themes.php"] [unique_id "aqqXV-IGW7PmdjiPnSPmcQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-16 09:11:30
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-13 12:29:44
(2 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-13 11:48:06
(2 weeks ago)
(mod_security) mod_security (id:240000) triggered by 45.132.224.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 45.132.224.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 07:47:45.075787 2026] [security2:error] [pid 26867:tid 26902] [client 45.132.224.45:54317] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||www.oftv.xyz|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "www.oftv.xyz"] [uri "/images/stories/themes.php"] [unique_id "aqaNYZSPq5ZGjW8naKHD2QAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack