🇺🇸
TPI-Abuse
2026-07-28 05:46:08
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 45.132.225.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.225.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 01:46:02.334025 2026] [security2:error] [pid 3482903:tid 3482935] [client 45.132.225.65:48917] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.30acre.net"] [uri "/.git/HEAD"] [unique_id "amhCGmZ97n0jX-7lmO9GOwAAAJc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
4server
2026-07-27 12:10:53
(1 month ago)
[MonJul2714:10:49.9575122026][security2:error][pid2942795:tid2942908][client45.132.225.65:0]ModSecur ...
show more
[MonJul2714:10:49.9575122026][security2:error][pid2942795:tid2942908][client45.132.225.65:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(curl\|wget\|python\|nikto\|sqlmap\|acunetix\|fimap\|dirbuster\|cmsmap\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"217\"][id\"990210\"][msg\"Suspicioususer-agentblocked\"][hostname\"grigorov.ch.136-243-54-122.cpanel.site\"][uri\"/.git/HEAD\"][unique_id\"amdKySKIE_XUAWqzcdIE3wAAANU\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-07-26 22:23:37
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 45.132.225.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.225.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 18:23:29.170404 2026] [security2:error] [pid 14587:tid 14615] [client 45.132.225.65:30415] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.cargostuff.com"] [uri "/.git/HEAD"] [unique_id "amaI4eKkGj1JA-dOM7R_SgAAAJg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-07-26 22:00:09
(1 month ago)
Auto-ban: >3000 req/min op 2026-07-26
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-07-26 19:46:55
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 45.132.225.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.225.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 15:46:48.203364 2026] [security2:error] [pid 2384127:tid 2384127] [client 45.132.225.65:52233] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ilil.net.caonabo.com"] [uri "/.git/HEAD"] [unique_id "amZkKF-5VDzIj0tMk7YcUQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-26 17:47:05
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 45.132.225.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.225.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 13:46:46.447478 2026] [security2:error] [pid 2069078:tid 2069078] [client 45.132.225.65:36269] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.wedeliverstrippers.com"] [uri "/.env.production"] [unique_id "amZIBjfuiPsOKu_WRZFZmAAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-26 08:19:37
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 45.132.225.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.225.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 04:19:29.010796 2026] [security2:error] [pid 2146591:tid 2146591] [client 45.132.225.65:21111] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.l39capital.com"] [uri "/.git/HEAD"] [unique_id "amXDEXCcxV5p9me8hAbgTQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-26 07:16:05
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 45.132.225.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.225.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 03:15:54.214680 2026] [security2:error] [pid 3608624:tid 3608624] [client 45.132.225.65:62133] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.personalized-holiday-cards.com"] [uri "/.git/HEAD"] [unique_id "amW0KqTtLgvFIVTmy_EqIQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-26 04:17:34
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 45.132.225.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.225.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 00:17:27.213758 2026] [security2:error] [pid 6501:tid 6501] [client 45.132.225.65:34585] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.abeltours.com"] [uri "/.git/HEAD"] [unique_id "amWKV633wZ9JzAs0cGsykQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
vtchost.com
2026-07-26 02:45:17
(1 month ago)
minux.vtchost.com:80 45.132.225.65 - - [26/Jul/2026:04:45:16 +0200] "GET /.git/HEAD HTTP/1.1" 418 21 ...
show more
minux.vtchost.com:80 45.132.225.65 - - [26/Jul/2026:04:45:16 +0200] "GET /.git/HEAD HTTP/1.1" 418 215 "-" "Python-urllib/3.10"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-07-26 02:23:08
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 45.132.225.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.225.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 22:22:58.296680 2026] [security2:error] [pid 1854165:tid 1854165] [client 45.132.225.65:39079] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "triplejrealty.com.summithost.com"] [uri "/.git/HEAD"] [unique_id "amVvgrqt8ZehiZC-svSrIwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
4server
2026-07-25 23:43:57
(1 month ago)
[SunJul2601:43:49.8459912026][security2:error][pid1733869:tid1734064][client45.132.225.65:0]ModSecur ...
show more
[SunJul2601:43:49.8459912026][security2:error][pid1733869:tid1734064][client45.132.225.65:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"landingswiss.ch.81-17-25-250.cpanel.site\"][uri\"/.git/HEAD\"][unique_id\"amVKNWWft5tQfQ46k-7BvgAAAJA\"]
show less
Hacking
Web App Attack
🇬🇧
consul.to
2026-07-19 06:40:13
(1 month ago)
Web attack/malicious scanning detected
Web App Attack
🇫🇷
dynamix
2026-07-18 19:43:07
(1 month ago)
Multiple WAF Violations
Web App Attack
🇩🇪
Admin-Gito
2026-07-18 03:01:07
(1 month ago)
45.132.225.65 - - [18/Jul/2026:04:37:13 +0200] "GET /wp-includes/customize/class-wp-customize-nav-me ...
show more
45.132.225.65 - - [18/Jul/2026:04:37:13 +0200] "GET /wp-includes/customize/class-wp-customize-nav-menu-section-boolean.php HTTP/1.1" 404 356104 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0"
45.132.225.65 - - [18/Jul/2026:04:37:18 +0200] "GET /wp-includes/db.php HTTP/1.1" 404 356060 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36"
45.132.225.65 - - [18/Jul/2026:04:37:20 +0200] "GET /wp-includes/class-wp-dependency-float.php HTTP/1.1" 404 356071 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0"
45.132.225.65 - - [18/Jul/2026:04:37:24 +0200] "GET /wp-includes/PHPMailer/purna.php HTTP/1.1" 404 356073 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36"
45.132.225.65 - - [18/Jul/2026:04:37:27 +0200] "GET /wp-includes/interactivity-api/interactivity-api-class.php HTTP/1.1" 404 356094 "-" "Moz
...
show less
Web App Attack