๐ช๐ธ
librebit
2026-06-26 08:26:36
(10 hours ago)
Brute force
Brute-Force
๐จ๐ญ
4server
2026-06-25 15:31:54
(1 day ago)
[ThuJun2517:31:48.9772492026][security2:error][pid4001491:tid4001500][client45.140.206.217:0]ModSecu ...
show more
[ThuJun2517:31:48.9772492026][security2:error][pid4001491:tid4001500][client45.140.206.217:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"368\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"leonitraslochi.ch\"][uri\"/xmlrpc.php\"][unique_id\"aj1J5OA_1MdRdMvLz710YQAAAIc\"]
show less
Hacking
Web App Attack
๐ฉ๐ช
LRob.fr
2026-05-25 16:45:04
(1 month ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐ณ๐ฑ
jjnxpct
2026-04-30 03:49:04
(1 month ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /.aws/credentials (Rule ID: 930130) - Restricted File Access Attempt
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-27 04:24:21
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 45.140.206.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 45.140.206.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 27 00:24:15.717774 2026] [security2:error] [pid 321:tid 321] [client 45.140.206.217:29545] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.deals.directnic-support.rocks|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.deals.directnic-support.rocks"] [uri "/s3cmd.ini"] [unique_id "ae7k707ipbvq4SDlF5I-iAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-26 00:54:14
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 45.140.206.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.140.206.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 25 20:54:09.835192 2026] [security2:error] [pid 3327:tid 3497] [client 45.140.206.217:51575] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||killyourattitude.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "killyourattitude.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ae1iMSvtPxzhHEnZZLbNCwAAAFA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-14 11:16:42
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 45.140.206.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.140.206.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 14 07:16:35.588495 2026] [security2:error] [pid 558981:tid 558981] [client 45.140.206.217:19019] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||seagrovesrealty.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "seagrovesrealty.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ad4iE0NWe9adWnr_TqQQMwAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
www.winos.me
2026-03-05 18:46:37
(3 months ago)
Banned due to high error rate on HTTP/1.1 protocol
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-01-18 00:55:10
(5 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-14 23:26:24
(5 months ago)
(mod_security) mod_security (id:240335) triggered by 45.140.206.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 45.140.206.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 14 18:26:18.308627 2026] [security2:error] [pid 26832:tid 26832] [client 45.140.206.217:13275] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.140.206.217 (+1 hits since last alert)|bernsteinip.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bernsteinip.com"] [uri "/xmlrpc.php"] [unique_id "aWgmGkKwx9zUsr-jRYXvIgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-03-30 12:20:12
(1 year ago)
This IP was involved in an brute force and password spray attack on 2025/03/30 07:18:08
Port Scan
Brute-Force
Exploited Host
Web App Attack
Anonymous
2025-03-28 11:55:14
(1 year ago)
This IP was involved in an brute force and password spray attack on 2025/03/28 06:53:55
Port Scan
Brute-Force
Exploited Host
Web App Attack
๐จ๐ฆ
wil.com
2025-03-28 08:26:18
(1 year ago)
GlobalProtect login attempts with user prwilliams.
VPN IP
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-03-18 12:19:21
(1 year ago)
(mod_security) mod_security (id:211120) triggered by 45.140.206.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211120) triggered by 45.140.206.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 18 08:19:13.847739 2025] [security2:error] [pid 4323:tid 4323] [client 45.140.206.217:59343] [client 45.140.206.217] ModSecurity: Access denied with code 403 (phase 2). Match of "endsWith /modules/paypal/express_checkout/payment.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "29"] [id "211120"] [rev "12"] [msg "COMODO WAF: Remote File Inclusion Attack||arsndetx.com|F|2"] [data "Matched Data: http://adguard.digital/payload/index.php? found within REQUEST_FILENAME: /wp-content/plugins/wp-super-cache/js/cache-loader.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arsndetx.com"] [uri "/wp-content/plugins/wp-super-cache/js/cache-loader.php"] [unique_id "Z9lkwTKRiqqnvv9iAJ4J5wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-11 11:40:23
(1 year ago)
(mod_security) mod_security (id:211120) triggered by 45.140.206.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211120) triggered by 45.140.206.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 11 07:40:20.655953 2025] [security2:error] [pid 3977:tid 3977] [client 45.140.206.217:58713] [client 45.140.206.217] ModSecurity: Access denied with code 403 (phase 2). Match of "endsWith /modules/paypal/express_checkout/payment.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "29"] [id "211120"] [rev "12"] [msg "COMODO WAF: Remote File Inclusion Attack||aeongames.com|F|2"] [data "Matched Data: http://adguard.digital/payload/index.php? found within REQUEST_FILENAME: /wp-content/plugins/wp-super-cache/js/cache-loader.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aeongames.com"] [uri "/wp-content/plugins/wp-super-cache/js/cache-loader.php"] [unique_id "Z9AhJOovxAXCFagu_4_gGgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack