๐บ๐ธ
TPI-Abuse
2025-12-03 02:58:41
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.132.225.254 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.225.254 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 21:58:36.888870 2025] [security2:error] [pid 12996:tid 12996] [client 45.132.225.254:38097] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "patrickjolly.us"] [uri "/.env"] [unique_id "aS-nXDrjFpKcIEMquUWaiwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2025-12-03 00:44:52
(6 months ago)
Blocking for trying to access an exploit file: /.env
Hacking
๐บ๐ธ
TPI-Abuse
2025-12-01 17:37:07
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.132.225.254 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.225.254 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 12:37:02.932956 2025] [security2:error] [pid 10418:tid 10418] [client 45.132.225.254:34049] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chefsuepong.com"] [uri "/.env"] [unique_id "aS3SPvEaL7nnQOlpx2qc7gAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-01 09:32:04
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.132.225.254 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.225.254 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 04:31:58.200649 2025] [security2:error] [pid 13880:tid 13893] [client 45.132.225.254:21957] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thebiglies.com"] [uri "/.env"] [unique_id "aS1gjtXrO2-Irj2IbK6msAAAAEs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2025-12-01 07:05:47
(6 months ago)
Too many Status 40X (16)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-01 05:54:04
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.132.225.254 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.225.254 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 00:53:58.398654 2025] [security2:error] [pid 8345:tid 8345] [client 45.132.225.254:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "uwsvita.org"] [uri "/.env"] [unique_id "aS0tdprSdSXZ_8yOI-DxSQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2025-11-25 08:29:00
(6 months ago)
IPBlock protected site ID [4055-d][s=01].
Persistent 404, vulnerability scanner
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2025-11-25 08:27:00
(6 months ago)
IPBlock protected site ID [4055-d][s=07].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2025-11-25 01:17:31
(6 months ago)
Malware host (X-Forwarded-For) detected by rbl.malware.expert. RBL lookup of 254.225.132.45.rbl.malw ...
show more
Malware host (X-Forwarded-For) detected by rbl.malware.expert. RBL lookup of 254.225.132.45.rbl.malware.expert succeeded at REQUEST_HEADERS:x-forwarded-for. (1001000-mnz6-1)
show less
Hacking
๐ฎ๐ฉ
Burayot
2025-11-13 09:55:54
(6 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 45.132.225.254 (AU/Australia/-): 1 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 45.132.225.254 (AU/Australia/-): 1 in the last 3600 secs
show less
Web App Attack
๐ฎ๐ฉ
sockominfo
2025-11-12 22:44:03
(6 months ago)
[WAZUH] Potential webshell scan access detected - Suspicious filename pattern
Hacking
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-11-12 20:17:58
(6 months ago)
TinyMCE Scan Activities
Web App Attack
๐จ๐ญ
backslash
2025-11-10 14:40:09
(6 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ฆ
URAN Publishing Service
2025-08-30 08:09:34
(9 months ago)
45.132.225.254 - - [30/Aug/2025:11:08:56 +0300] "GET //wp-content/admin.php HTTP/1.1" 404 276 "-" "G ...
show more
45.132.225.254 - - [30/Aug/2025:11:08:56 +0300] "GET //wp-content/admin.php HTTP/1.1" 404 276 "-" "Go-http-client/1.1"
45.132.225.254 - - [30/Aug/2025:11:09:33 +0300] "GET //wp-includes/mah.php HTTP/1.1" 404 276 "-" "Go-http-client/1.1"
...
show less
Web App Attack
Anonymous
2025-08-09 17:54:31
(9 months ago)
wordpress-trap
Web App Attack