๐ฉ๐ช
wpadm4
2026-07-28 04:49:18
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 05:04:23
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 45.132.225.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.225.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 01:04:16.792462 2026] [security2:error] [pid 1321782:tid 1321839] [client 45.132.225.67:38617] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.metabotic.com"] [uri "/.git/HEAD"] [unique_id "ambm0Juj45GPMlSxTxrUjQAAAZM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 22:34:29
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 45.132.225.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.225.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 18:34:19.119371 2026] [security2:error] [pid 3552039:tid 3552039] [client 45.132.225.67:53657] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.carinsteen.com"] [uri "/.git/HEAD"] [unique_id "amaLa_Qem_Dd-m8WLqtGTwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-26 21:59:56
(3 days ago)
Auto-ban: >3000 req/min op 2026-07-26
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-26 20:37:26
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 45.132.225.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.225.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 16:37:20.884087 2026] [security2:error] [pid 7352:tid 7396] [client 45.132.225.67:45001] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.captechinc.com"] [uri "/.git/HEAD"] [unique_id "amZwAPYJL7JvgrvjilbPzgAAAcw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
lolyay
2026-07-26 18:29:48
(3 days ago)
45.132.225.67 - - [26/Jul/2026:18:29:45 +0000] "GET /.git/HEAD HTTP/1.1" 301 178 "-" "Python-urllib/ ...
show more
45.132.225.67 - - [26/Jul/2026:18:29:45 +0000] "GET /.git/HEAD HTTP/1.1" 301 178 "-" "Python-urllib/3.10"
45.132.225.67 - - [26/Jul/2026:18:29:47 +0000] "GET /.git/HEAD HTTP/1.1" 404 192 "-" "Python-urllib/3.10"
...
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-26 16:15:08
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 45.132.225.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.225.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 12:14:57.376025 2026] [security2:error] [pid 9349:tid 9349] [client 45.132.225.67:24651] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.callbobh.com"] [uri "/.git/HEAD"] [unique_id "amYygbTl77uVTKDAs679kwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 13:36:30
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 45.132.225.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.225.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 09:36:10.843774 2026] [security2:error] [pid 4046252:tid 4046252] [client 45.132.225.67:46957] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.vegasweddingvacation.com"] [uri "/.env.production"] [unique_id "amYNSpNLzGYrwc9OinpwIwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 10:04:23
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 45.132.225.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.225.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 06:04:15.849143 2026] [security2:error] [pid 12330:tid 12330] [client 45.132.225.67:54087] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.theaccents.mainstreetofficesuites.com"] [uri "/.git/HEAD"] [unique_id "amXbn44U04pO7T_ycGApEgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure
2026-07-26 09:16:14
(3 days ago)
csagent: score 18.7: secrets grab x2, 404 noise floor x2; 2 domain(s) in 33s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 04:36:46
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 45.132.225.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.225.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 00:36:38.571674 2026] [security2:error] [pid 3066919:tid 3066919] [client 45.132.225.67:56193] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.e-ntourage.com"] [uri "/.git/HEAD"] [unique_id "amWO1tApEhnO45pipTrKSAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-19 15:19:50
(1 week ago)
Multiple WAF Violations
Web App Attack
๐ฌ๐ง
consul.to
2026-07-19 06:42:23
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
dynamix
2026-07-15 17:41:24
(2 weeks ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
Epimetheus
2026-07-14 21:38:03
(2 weeks ago)
Zombie network / Bot scanner detected:
[GET] /.well-known/acme-challenge/plugins.php
[GET] /webadmi ...
show more
Zombie network / Bot scanner detected:
[GET] /.well-known/acme-challenge/plugins.php
[GET] /webadmin.php
[GET] /edit.php
[GET] /assets/images/doc.php
[GET] /file2.php
[GET] /css/index.php
[GET] /wp-content/plugins/dummyyummy/wp-signup.php
[GET] /radio.php
[GET] /wp-class.php
[GET] /wp-content/themes/admin.php
[GET] /wp.php
[GET] /.well-known/pki-validation/index.php
[GET] /bypass.php
[GET] /wp-content/product.php
[GET] /default.php
[GET] /wp-blog.php
[GET] /wp-includes/PHPMailer/wp-conflg.php
[GET] /admin/function.php
[GET] /wp-includes/js/index.php
[GET] /wp-admin/images/wp-conflg.php
[GET] /vendor/phpunit/phpunit/src/Util/PHP/kill.php
[GET] /wp-content/themes/pridmag/db.php
[GET] /images/upload.php
[GET] /file5.php
[GET] /inputs.php
[GET] /.wp/wso.php
UA: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36
show less
Bad Web Bot
Exploited Host
Web App Attack