🇹🇷
neron
2026-08-04 16:29:42
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
🇫🇷
mail.avx.gr
2026-07-27 22:17:42
(1 month ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default:80 45.132.225.86 - - [28/Jul/2026:01:17:4 ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default:80 45.132.225.86 - - [28/Jul/2026:01:17:41 +0300] "GET /.git/HEAD HTTP/1.1" 403 411 "-" "Python-urllib/3.10"
show less
Web App Attack
🇬🇧
sandra361
2026-07-27 17:49:33
(1 month ago)
Port scan detected: 195 attempts across 42 ports (81,82,83,84,85, ..., 8890,8899,9001). | Evidence: ...
show more
Port scan detected: 195 attempts across 42 ports (81,82,83,84,85, ..., 8890,8899,9001). | Evidence: GHOST_SCAN: IN=enp1s0f0 SRC=45.132.225.86 LEN=60 TOS=0x00 PREC=0x00 TTL=48 ID=26541 DF PROTO=TCP SPT=56710 DPT=8000 WINDOW=65500 RES=0x00 SYN URGP=0
show less
Port Scan
🇨🇭
ScanThe.Net
2026-07-27 17:20:41
(1 month ago)
ID: 5436405729 | PORT: 8800 | https://45-132-225-86.scanthe.net
Port Scan
🇱🇹
NotACaptcha
2026-07-27 14:40:52
(1 month ago)
webserver:80 [27/Jul/2026] "GET /.git/HEAD HTTP/1.1" 403 363 "-" "Python-urllib/3.10"
Web App Attack
🇨🇭
4server
2026-07-27 10:19:01
(1 month ago)
[MonJul2712:18:57.8447332026][security2:error][pid37690:tid38121][client45.132.225.86:0]ModSecurity: ...
show more
[MonJul2712:18:57.8447332026][security2:error][pid37690:tid38121][client45.132.225.86:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"ticino-host.ch.hosting-domini.ch\"][uri\"/\"][unique_id\"amcwkQ_ZkwV2n_vJI9yZ2wAAARc\"]
show less
Hacking
Web App Attack
🇲🇳
Public CSIRT/CC of Mongolia
2026-07-27 04:05:59
(1 month ago)
Honeypot hit: HTTP/1.1 request on 3001
GET /
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_ ...
show more
Honeypot hit: HTTP/1.1 request on 3001
GET /
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
Accept-Encoding: gzip; 3001 [3], 3000 [3], 3002 [3], 3003 [3], 3080 [3], 3005 [3] TCP
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-07-26 18:56:03
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 45.132.225.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.225.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 14:55:54.890301 2026] [security2:error] [pid 2760555:tid 2760555] [client 45.132.225.86:58845] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.canebrakes.com"] [uri "/.git/HEAD"] [unique_id "amZYOgD66E1cemtV5HV-EwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-26 17:39:11
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 45.132.225.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.225.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 13:39:05.252517 2026] [security2:error] [pid 204166:tid 204166] [client 45.132.225.86:46647] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.campfearnc.com"] [uri "/.git/HEAD"] [unique_id "amZGObXYFXl1JTAFEaCWMwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-26 16:13:57
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 45.132.225.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.225.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 12:13:49.031876 2026] [security2:error] [pid 25854:tid 25854] [client 45.132.225.86:55733] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.callalbany.com"] [uri "/.git/HEAD"] [unique_id "amYyPYr-RvtBoIfQ503VEgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-26 13:47:58
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 45.132.225.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.225.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 09:47:51.217690 2026] [security2:error] [pid 3074327:tid 3074327] [client 45.132.225.86:20713] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.cabwebs.com"] [uri "/.git/HEAD"] [unique_id "amYQBwL_x1JTI91kx1eLIwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
LiftUp Hosting
2026-07-26 10:55:10
(1 month ago)
Honeypot hit: Incoming HTTP traffic on port 81
Hacking
Bad Web Bot
🇺🇸
TPI-Abuse
2026-07-26 08:58:57
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 45.132.225.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.225.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 04:58:51.761070 2026] [security2:error] [pid 8804:tid 8908] [client 45.132.225.86:55629] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yt.kd9uri.com"] [uri "/.git/HEAD"] [unique_id "amXMS-DHHhLblc6AO9D0rQAAARA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-26 07:53:44
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 45.132.225.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.225.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 03:53:37.380387 2026] [security2:error] [pid 2729528:tid 2729528] [client 45.132.225.86:41371] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sp.cloudex.link"] [uri "/.git/HEAD"] [unique_id "amW9AaGqWnJ-nkY45NwOXAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-26 06:00:41
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 45.132.225.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.225.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 02:00:28.293875 2026] [security2:error] [pid 2343268:tid 2343268] [client 45.132.225.86:29219] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.zohartours.com"] [uri "/.git/HEAD"] [unique_id "amWifOnpf9L_i-qdZ8Wk0QAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack