๐บ๐ธ
TPI-Abuse
2026-08-22 06:52:53
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 02:52:45.536898 2026] [security2:error] [pid 1603:tid 1603] [client 45.132.227.57:27289] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.141"] [uri "/library/.env"] [unique_id "aolHPQB1Ku8rKFDtruthCQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 04:41:16
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 00:40:32.540748 2026] [security2:error] [pid 1661:tid 1661] [client 45.132.227.57:50967] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.26"] [uri "/src/.env"] [unique_id "aokoQEM-piO7-a6zh9Z_KAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nyt
2026-08-21 22:20:26
(10 hours ago)
Repeated WordPress login POSTs blocked by WAF (3 in 6h)
Brute-Force
Web App Attack
Anonymous
2026-08-21 21:46:05
(10 hours ago)
Failed Wordpress Logins
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-08-21 19:02:56
(13 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
ipblock.com
2026-08-21 16:56:00
(15 hours ago)
IPBlock protected site ID [3192-af][s=06].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 13:04:27
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 09:04:08.973579 2026] [security2:error] [pid 4850:tid 4850] [client 45.132.227.57:22413] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.72"] [uri "/apps/.env"] [unique_id "aohMyEYWWUnind-JgrgAYQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 08:43:45
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 04:43:40.803437 2026] [security2:error] [pid 19702:tid 19702] [client 45.132.227.57:58823] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.97"] [uri "/conf/.env"] [unique_id "aogPvOhBXSPl0x3sWrxzWQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 06:26:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 02:26:04.109229 2026] [security2:error] [pid 24674:tid 24674] [client 45.132.227.57:28213] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.136"] [uri "/public/.env"] [unique_id "aofvfMFKUpiC28f1VJEyhAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 04:38:58
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 45.132.227.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 45.132.227.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 00:38:44.515949 2026] [security2:error] [pid 14231:tid 14231] [client 45.132.227.57:52433] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "192.64.150.240"] [uri "/storage/.env"] [unique_id "aofWVM9aMsA1PgJeya2sagAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-21 04:09:41
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-17 12:39:01
(4 days ago)
cloudlinux2 fail2ban: 2026-08-17 14:34:16,430 fail2ban.filter [1456]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-17 14:34:16,430 fail2ban.filter [1456]: INFO [plesk-wordpress] Found 45.132.227.57 - 2026-08-17 14:34:15cloudlinux2 fail2ban: 2026-08-17 14:34:16,296 fail2ban.filter [1456]: INFO [plesk-wordpress] Found 45.132.227.61 - 2026-08-17 14:34:15cloudlinux2 fail2ban: 2026-08-17 14:34:16,720 fail2ban.filter [1456]: INFO [plesk-wordpress] Found 45.132.227.67 - 2026-08-17 14:34:15cloudlinux2 fail2ban: 2026-08-17 14:34:16,399 fail2ban.filter [1456]: INFO [plesk-wordpress] Found 136.144.42.78 - 2026-08-17 14:34:15cloudlinux2 fail2ban: 2026-08-17 14:35:28,727 fail2ban.filter [1456]: INFO [plesk-wordpress] Found 45.132.227.53 - 2026-08-17 14:35:28cloudlinux2 fail2ban: 2026-08-17 14:35:58,814 fail2ban.filter [1456]: INFO [plesk-modsecurity] Found 34.136.64.164 - 2026-08-17 14:35:58cloudlinux2 fail2ban: 2026-08-17 14:35:58,834 fail2ban.filter [1456]: INFO [plesk-modsecurity] Found 34.136.64.164 - 2026-08-17 14:35:58cloud
show less
Web App Attack
Anonymous
2026-08-17 08:45:39
(4 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐น๐ท
neron
2026-08-15 23:06:48
(6 days ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐บ๐ธ
omc
2026-08-14 09:55:21
(1 week ago)
AH01797: Unauthorized file.
Bad Web Bot