๐ณ๐ฑ
Site.eu
2026-09-20 18:27:49
(1 hour ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-20 15:38:11
(4 hours ago)
(mod_security) mod_security (id:240000) triggered by 45.132.224.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 45.132.224.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:38:06.954570 2026] [security2:error] [pid 6943:tid 6943] [client 45.132.224.48:65495] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||aticom.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "aticom.net"] [uri "/images/stories/themes.php"] [unique_id "aq_93kS8PvXDWp6r1uh40AAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 14:52:10
(5 hours ago)
Fail2Ban nginx-scanner-sweep: web scanner activity
Bad Web Bot
๐ณ๐ฑ
Alt255
2026-09-20 14:37:41
(5 hours ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 45.132.224.48 - - [20/Sep/2026:16:37:30 +0200] "GET /de/wp-content/plugins/buddypress/alfa.php HTTP/2.0" 403 369 "http://marvoparts.de/wp-content/plugins/buddypress/alfa.php" "Go-http-client/2.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 11:33:13
(8 hours ago)
(mod_security) mod_security (id:240000) triggered by 45.132.224.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 45.132.224.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 07:33:08.875856 2026] [security2:error] [pid 21449:tid 21449] [client 45.132.224.48:20625] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||www.sunsettrailsardmore.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "www.sunsettrailsardmore.com"] [uri "/images/stories/themes.php"] [unique_id "aq_EdHpAoUDdCzPjc_sLBwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-18 18:20:02
(2 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ซ๐ท
dynamix
2026-09-17 23:21:36
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-17 22:52:19
(2 days ago)
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 45.132.224.48 - - [18/Sep/2026:00:52:10 +0200] "GET /wp-admin/css/colors/blue/alfa.php HTTP/1.1" 403 463 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 13:24:38
(4 days ago)
(mod_security) mod_security (id:240000) triggered by 45.132.224.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 45.132.224.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 09:24:34.690425 2026] [security2:error] [pid 24175:tid 24175] [client 45.132.224.48:21609] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||thebronsons.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "thebronsons.com"] [uri "/images/stories/themes.php"] [unique_id "aqqYkgcMZh4KKrmnFjpcVwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 16:55:08
(5 days ago)
(mod_security) mod_security (id:240000) triggered by 45.132.224.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 45.132.224.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 12:55:01.598688 2026] [security2:error] [pid 3700:tid 3766] [client 45.132.224.48:62119] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||www.conceptsinammunition.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "www.conceptsinammunition.com"] [uri "/images/stories/themes.php"] [unique_id "aql4ZWFlZeJD14UgMpwzagAAAcU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-13 12:29:51
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ซ๐ท
dynamix
2026-09-12 23:51:49
(1 week ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
dynamix
2026-09-11 05:43:41
(1 week ago)
Multiple WAF Violations
Web App Attack
๐น๐ท
neron
2026-08-07 13:37:17
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-06 18:38:58
(1 month ago)
(mod_security) mod_security (id:240000) triggered by 45.132.224.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 45.132.224.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 14:38:54.943697 2026] [security2:error] [pid 3235593:tid 3235593] [client 45.132.224.48:33623] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||weddingcocktailnapkins.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "weddingcocktailnapkins.com"] [uri "/images/stories/themes.php"] [unique_id "anTUvh44-8hYm8czBFn-jgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack