Anonymous
2026-06-16 14:22:32
(9 hours ago)
Web attack blocked by Wordfence on heemkundesjin.nl (1 hit). Reported by CRMON.
Web App Attack
๐ฆ๐บ
oncord
2026-06-07 01:36:27
(1 week ago)
Form spam
Web Spam
๐บ๐ธ
[email protected]
2026-05-19 20:42:37
(4 weeks ago)
FreePBX [auth_failure] detected in security log. Reported by M C Boyd Services MSP.
Brute-Force
Web App Attack
๐บ๐ธ
itsnixk
2026-05-18 21:14:43
(4 weeks ago)
(mod_security) mod_security (id:920350) triggered by 45.132.227.55 (US/United States/-): 1 in the la ...
show more
(mod_security) mod_security (id:920350) triggered by 45.132.227.55 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Mon May 18 17:14:36.698308 2026] [security2:error] [pid 428019:tid 428108] [client 45.132.227.55:25015] ModSecurity: Access denied with code 406 (phase 1). Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "774"] [id "920350"] [msg "Host header is a numeric IP address"] [redacted] [severity "WARNING"] [ver "OWASP_CRS/4.25.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/admin/.env"] [unique_id "aguBPD7KZgdktDsOl4JG-wAAABY"]
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-17 08:04:01
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.55 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 04:03:24.958480 2026] [security2:error] [pid 25948:tid 25948] [client 45.132.227.55:28969] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.53"] [uri "/.env"] [unique_id "agl2TNGTOpZbLPsbdwWmgAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 23:57:39
(1 month ago)
(mod_security) mod_security (id:240000) triggered by 45.132.227.55 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 45.132.227.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 19:57:32.361970 2026] [security2:error] [pid 28429:tid 28429] [client 45.132.227.55:26959] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||carphotoframes.biz|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "carphotoframes.biz"] [uri "/images/stories/themes.php"] [unique_id "agJs7OMm4KP2pBH7az7S1QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ecs.ge
2026-05-11 07:23:09
(1 month ago)
Automatic Fail2Ban report from jail plesk-modsecurity: multiple matching events detected.
Web App Attack
Hacking
๐ฉ๐ช
ecs.ge
2026-05-07 09:36:34
(1 month ago)
Automatic Fail2Ban report from jail plesk-modsecurity: multiple matching events detected.
Web App Attack
Hacking
๐ซ๐ท
Octopuce
2026-03-13 12:32:26
(3 months ago)
Aggressive web search of vulnerable pages: /bless.php /lock.php /tiny.php /themes.php /wp-good.php / ...
show more
Aggressive web search of vulnerable pages: /bless.php /lock.php /tiny.php /themes.php /wp-good.php /ioxi-o.php /wp.php /about.php /adminfuns.ph ...
show less
Web App Attack
๐จ๐ณ
ThreatBook.io
2026-03-08 23:02:47
(3 months ago)
ThreatBook Intelligence: Zombie,Dynamic IP more details on https://threatbook.io/ip/45.132.227.55
20 ...
show more
ThreatBook Intelligence: Zombie,Dynamic IP more details on https://threatbook.io/ip/45.132.227.55
2026-03-08 02:00:21 /__tests__/test-become/.env
2026-03-08 02:01:29 /settings.json
show less
Web App Attack
๐ฎ๐ณ
Starburst SysOp Team
2026-03-07 17:00:13
(3 months ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-bom2-2)
Hacking
Bad Web Bot
๐จ๐ญ
zynex
2026-03-06 15:41:05
(3 months ago)
URL Probing: /wp-includes/id3/license.txt/wp1/wp-includes/wlwmanifest.xml
Web App Attack
Anonymous
2026-03-04 08:43:26
(3 months ago)
This IP was involved in an brute force and password spray attack on 2026/03/04 02:41:34
Port Scan
Brute-Force
Exploited Host
Web App Attack
๐จ๐ฆ
Mediashaker
2026-03-02 18:14:12
(3 months ago)
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 45.132.227.55 (US/United ...
show more
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 45.132.227.55 (US/United States/-)
show less
Port Scan
๐บ๐ฆ
URAN Publishing Service
2026-03-02 06:19:58
(3 months ago)
45.132.227.55 - - [02/Mar/2026:08:19:57 +0200] "GET /wp-admin/css/autoload_classmap.php HTTP/1.1" 40 ...
show more
45.132.227.55 - - [02/Mar/2026:08:19:57 +0200] "GET /wp-admin/css/autoload_classmap.php HTTP/1.1" 404 277 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3"
45.132.227.55 - - [02/Mar/2026:08:19:58 +0200] "GET /wp-admin/js/wp-conflg.php HTTP/1.1" 404 277 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95"
...
show less
Web App Attack