🇺🇸
TPI-Abuse
2026-09-12 07:55:04
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.138.12.9 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.138.12.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 03:54:57.545906 2026] [security2:error] [pid 23941:tid 24034] [client 45.138.12.9:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.humanet.io"] [uri "/.git/HEAD"] [unique_id "aqUFUWmozhmNSp9dTcDtPwAAAcc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
zynex
2026-09-12 07:50:50
(3 hours ago)
URL Probing: /phpinfo.php
Web App Attack
🇦🇺
rubixstudios
2026-09-12 07:29:02
(4 hours ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 07:26:30
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.138.12.9 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.138.12.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 03:26:25.931033 2026] [security2:error] [pid 9542:tid 9554] [client 45.138.12.9:34708] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webcraftestudio.com"] [uri "/.git/HEAD"] [unique_id "aqT-oZzBdKxjmd2wMqBomQAAAUE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
oh.mg
2026-09-12 07:09:38
(4 hours ago)
[Sat Sep 12 09:09:38.185631 2026] [security2:error] [pid 3476535:tid 3476556] [client 45.138.12.9:53 ...
show more
[Sat Sep 12 09:09:38.185631 2026] [security2:error] [pid 3476535:tid 3476556] [client 45.138.12.9:53358] [client 45.138.12.9] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "vms.mrman.net"] [uri "/.env"] [unique_id "aqT6stS06pZIhRSejXIpwgAAAFM"]
...
show less
Web App Attack
Bad Web Bot
Anonymous
2026-09-12 06:49:17
(4 hours ago)
"GET /.git/HEAD HTTP/2.0"
Hacking
Web App Attack
🇳🇱
debestelapp
2026-09-12 06:35:13
(4 hours ago)
Web App Attack
🇩🇪
ghostwarriors
2026-09-12 06:20:19
(5 hours ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
maxpower
2026-09-12 06:16:01
(5 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 45.138.12.9 (LT/Lithuania/-): 1 in the l ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 45.138.12.9 (LT/Lithuania/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 45.138.12.9 - - [12/Sep/2026:08:15:56 +0200] "GET /api/shared/config/config.env HTTP/2.0" 200 4811 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36" "45.138.12.9" host=villapardi.it
show less
Port Scan
🇬🇧
consul.to
2026-09-12 05:40:38
(5 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-12 05:09:42
(6 hours ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: HK, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: HK, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 05:06:53
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.138.12.9 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.138.12.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 01:06:47.778015 2026] [security2:error] [pid 31721:tid 31721] [client 45.138.12.9:56972] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.bnotlea.com"] [uri "/.git/HEAD"] [unique_id "aqTd5yVAxMGXKABttliGTwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-12 04:48:09
(6 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-12 04:20:38
(7 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
🇪🇸
elcruzado.es
2026-09-12 04:12:38
(7 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 45.138.12.9 (LT/Lithuania/-)
SQL Injection