π©πͺ
maxpower
2026-10-03 19:07:14
(2 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 45.151.162.103 (DE/Germany/-): 1 in the ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 45.151.162.103 (DE/Germany/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 45.151.162.103 - - [03/Oct/2026:21:07:08 +0200] "GET /.ssh/id_rsa HTTP/1.1" 200 12107 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36" "-" host=keyprint.com.br
show less
Port Scan
π«π·
bigorre.org
2026-06-05 04:55:32
(3 months ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-04-08 21:33:59
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 45.151.162.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 45.151.162.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 17:33:49.641837 2026] [security2:error] [pid 177869:tid 177869] [client 45.151.162.103:43577] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.nbcnewsradio.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.nbcnewsradio.com"] [uri "/ssl/localhost.key"] [unique_id "adbJvSYwe6wZHp1cEqlHWwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-07 21:03:46
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 45.151.162.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.151.162.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 07 16:03:42.980403 2026] [security2:error] [pid 10747:tid 10747] [client 45.151.162.103:58807] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.nbcnewsradio.com"] [uri "/_.htaccess"] [unique_id "aYeormpTI16Q_OOFXv92PQAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-01 13:01:04
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 45.151.162.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.151.162.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 08:00:58.911637 2026] [security2:error] [pid 12299:tid 12333] [client 45.151.162.103:48191] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.kettlehill.com"] [uri "/api/.env"] [unique_id "aX9Ois_CAppeKcdveJ3o1wAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-03 02:34:33
(10 months ago)
(mod_security) mod_security (id:221260) triggered by 45.151.162.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:221260) triggered by 45.151.162.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 21:34:27.975001 2025] [security2:error] [pid 32263:tid 32263] [client 45.151.162.103:48117] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||autodiscover.farmers123.com:80|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.farmers123.com"] [uri "/cgi-bin/status/status.cgi"] [unique_id "aS-hs1pHY4RVJd7dBCs2PgAAABU"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-01 06:20:25
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 45.151.162.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.151.162.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 01:20:21.784120 2025] [security2:error] [pid 27471:tid 27499] [client 45.151.162.103:53583] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.kettlehill.com"] [uri "/.git/config"] [unique_id "aS0zpXLXOKC0tXS7y0kn3QAAAIs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-10-28 23:20:43
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 45.151.162.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 45.151.162.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 28 19:20:36.022148 2025] [security2:error] [pid 1062:tid 1062] [client 45.151.162.103:34733] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nbcnewsradio.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nbcnewsradio.com"] [uri "/admin/log/error.log"] [unique_id "aQFPxM-UwGJUMLacnnXcfwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-22 19:33:47
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 45.151.162.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.151.162.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 22 15:33:41.623097 2025] [security2:error] [pid 28838:tid 28838] [client 45.151.162.103:46505] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.deandobkin.com"] [uri "/.env"] [unique_id "aNGklfmg2idp-pwpNR4tbgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΏπ¦
slartybartfast69420blazit
2025-08-12 20:36:12
(1 year ago)
Fail2ban picked up 45.151.162.103 attacking nginx
Web App Attack
πΏπ¦
slartybartfast69420blazit
2025-08-11 20:32:23
(1 year ago)
Fail2ban picked up 45.151.162.103 attacking nginx
Web App Attack
πΏπ¦
slartybartfast69420blazit
2025-08-09 20:48:27
(1 year ago)
Fail2ban picked up 45.151.162.103 attacking nginx
Web App Attack
πΏπ¦
slartybartfast69420blazit
2025-08-08 20:45:31
(1 year ago)
Fail2ban picked up 45.151.162.103 attacking nginx
Web App Attack
πΏπ¦
slartybartfast69420blazit
2025-08-07 20:42:42
(1 year ago)
Fail2ban picked up 45.151.162.103 attacking nginx
Web App Attack
πΏπ¦
slartybartfast69420blazit
2025-08-06 20:39:53
(1 year ago)
Fail2ban picked up 45.151.162.103 attacking nginx
Web App Attack