๐บ๐ธ
TPI-Abuse
2026-08-23 02:38:32
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.218 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 22:38:15.847552 2026] [security2:error] [pid 444:tid 444] [client 45.132.227.218:47515] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.214"] [uri "/admin/.env"] [unique_id "aopdFxAuOCBfdooPUBBoyAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 21:48:37
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.218 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 17:48:08.526489 2026] [security2:error] [pid 27488:tid 27488] [client 45.132.227.218:33661] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.35"] [uri "/admin/.env"] [unique_id "aooZGJcBRYhmu1koN97o0wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
hidemail.app
2026-08-22 21:40:50
(15 hours ago)
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto ...
show more
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto-banned by fail2ban.
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-22 20:05:30
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.218 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 16:05:03.948493 2026] [security2:error] [pid 11021:tid 11021] [client 45.132.227.218:54481] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.114"] [uri "/wp-content/.env"] [unique_id "aooA7xqxzn4lULY7YKG5VQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 19:26:50
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.218 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 15:26:26.559380 2026] [security2:error] [pid 23078:tid 23078] [client 45.132.227.218:39361] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.180"] [uri "/wp-admin/.env"] [unique_id "aon34gk0xbvUT0KKAbhHBAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-08-17 06:32:38
(6 days ago)
[redacted] 45.132.227.218 - - [17/Aug/2026:07:32:30 +0100] "GET /[redacted] HTTP/1.1" 302 6783 0/388 ...
show more
[redacted] 45.132.227.218 - - [17/Aug/2026:07:32:30 +0100] "GET /[redacted] HTTP/1.1" 302 6783 0/388159 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 Version/17.0 Safari/605.1.15" [redacted] 45.132.227.218 - - [17/Aug/2026:07:32:36 +0100] "GET /wp-admin/ HTTP/1.1" 301 5837 0/551 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; rv:143.0) Gecko/20100101 Firefox/143.0"
show less
Bad Web Bot
Web App Attack
๐น๐ท
neron
2026-08-15 23:06:48
(1 week ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-15 18:33:56
(1 week ago)
cloudlinux2 fail2ban: 2026-08-15 20:28:53,435 fail2ban.filter [1695]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-15 20:28:53,435 fail2ban.filter [1695]: INFO [plesk-wordpress] Found 193.56.116.42 - 2026-08-15 20:28:52cloudlinux2 fail2ban: 2026-08-15 20:29:24,253 fail2ban.filter [1695]: INFO [plesk-modsecurity] Found 197.235.211.15 - 2026-08-15 20:29:24cloudlinux2 fail2ban: 2026-08-15 20:29:47,234 fail2ban.filter [1695]: INFO [plesk-wordpress] Found 45.132.227.218 - 2026-08-15 20:29:46cloudlinux2 fail2ban: 2026-08-15 20:30:27,848 fail2ban.filter [1695]: INFO [plesk-modsecurity] Found 35.192.16.172 - 2026-08-15 20:30:27cloudlinux2 fail2ban: 2026-08-15 20:31:09,381 fail2ban.filter [1695]: INFO [plesk-modsecurity] Found 39.154.11.19 - 2026-08-15 20:31:09cloudlinux2 fail2ban: 2026-08-15 20:31:21,559 fail2ban.filter [1695]: INFO [plesk-wordpress] Found 45.131.193.103 - 2026-08-15 20:31:20cloudlinux2 fail2ban: 2026-08-15 20:31:28,118 fail2ban.filter [1695]: INFO [plesk-modsecurity] Found 197.235.211.15 - 2026-08-15 20:31:
show less
Web App Attack
๐ฌ๐ง
sleepingcat1714
2026-08-15 06:35:05
(1 week ago)
15-08-2026:06:35:05UTC [Web Server] Suspicious web request: path:/wp-login.php (1 request(s)).
Bad Web Bot
Web App Attack
๐ฉ๐ช
london2038.com
2026-08-14 06:17:00
(1 week ago)
Attacking WordPress
45.132.227.218 - - [14/Aug/2026:08:16:55 +0200] "POST /wp-login.php HTTP/1.1" 50 ...
show more
Attacking WordPress
45.132.227.218 - - [14/Aug/2026:08:16:55 +0200] "POST /wp-login.php HTTP/1.1" 503 19309 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/129.0.0.0 Safari/537.36"
show less
Brute-Force
Web App Attack
๐ซ๐ฎ
YF
2026-08-14 02:00:34
(1 week ago)
WordPress author enumeration
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-08-12 05:51:13
(1 week ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐น๐ท
neron
2026-08-07 09:37:17
(2 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐น๐ท
neron
2026-07-31 17:06:18
(3 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-29 18:33:57
(3 weeks ago)
cloudlinux2 fail2ban: 2026-07-29 20:28:52,047 fail2ban.filter [1584]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-07-29 20:28:52,047 fail2ban.filter [1584]: INFO [plesk-modsecurity] Found 34.9.250.245 - 2026-07-29 20:28:52cloudlinux2 fail2ban: 2026-07-29 20:29:38,135 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 27.255.172.6 - 2026-07-29 20:29:37cloudlinux2 fail2ban: 2026-07-29 20:29:35,337 fail2ban.filter [1584]: INFO [plesk-modsecurity] Found 45.243.42.102 - 2026-07-29 20:29:35cloudlinux2 fail2ban: 2026-07-29 20:29:59,725 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 45.132.227.218 - 2026-07-29 20:29:58cloudlinux2 fail2ban: 2026-07-29 20:29:59,725 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 45.132.227.219 - 2026-07-29 20:29:58cloudlinux2 fail2ban: 2026-07-29 20:30:50,638 fail2ban.filter [1584]: INFO [plesk-modsecurity] Found 45.243.42.102 - 2026-07-29 20:30:50cloudlinux2 fail2ban: 2026-07-29 20:31:11,691 fail2ban.actions [1584]: NOTICE [plesk-modsecurity] Ban 45.243.42.102cloudlinux2 fail2ban: 202
show less
Web App Attack