Anonymous
2026-02-23 03:03:21
(3 months ago)
DirectAdmin Auto Report (error_log)
Brute-Force
SSH
π«π·
dynamix
2026-02-23 01:35:37
(3 months ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-02-23 01:14:37
(3 months ago)
[redacted] 45.154.138.90 - - [23/Feb/2026:02:14:29 +0100] "GET /wp-content/plugins/pwnd-1/admin.php ...
show more
[redacted] 45.154.138.90 - - [23/Feb/2026:02:14:29 +0100] "GET /wp-content/plugins/pwnd-1/admin.php HTTP/1.1" 404 196 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0"
[redacted] 45.154.138.90 - - [23/Feb/2026:02:14:30 +0100] "GET /wp-admin/shell20211028.php HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36"
[redacted] 45.154.138.90 - - [23/Feb/2026:02:14:31 +0100] "GET /wp-admin/images/admin.php HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0"
[redacted] 45.154.138.90 - - [23/Feb/2026:02:14:33 +0100] "GET /wp-admin/chosen.php HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95"
[redacted] 45.154.138.90 - - [23/Feb/2026:02:14:34
...
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-23 00:00:29
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.154.138.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.154.138.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 22 19:00:25.095739 2026] [security2:error] [pid 15417:tid 15417] [client 45.154.138.90:20591] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jrbentley.modelengines.info"] [uri "/.git/HEAD"] [unique_id "aZuYmUI2JbhI_IWxuIy1_gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-02-22 22:59:40
(3 months ago)
Auto-ban: >3000 req/min op 2026-02-22
Web App Attack
SSH
Hacking
Anonymous
2026-02-22 21:32:41
(3 months ago)
Probing to gain illegal access
Web App Attack
π¨π
backslash
2026-02-22 21:27:03
(3 months ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
Anonymous
2026-02-22 20:52:17
(3 months ago)
[redacted] 45.154.138.90 - - [22/Feb/2026:21:52:09 +0100] "GET /wp-admin/css/colors/blue/rk2.php HTT ...
show more
[redacted] 45.154.138.90 - - [22/Feb/2026:21:52:09 +0100] "GET /wp-admin/css/colors/blue/rk2.php HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0"
[redacted] 45.154.138.90 - - [22/Feb/2026:21:52:10 +0100] "GET /wp-admin/css/colors/light/profile.php HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3"
[redacted] 45.154.138.90 - - [22/Feb/2026:21:52:12 +0100] "GET /wp-admin/user/wp-login.php HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95"
[redacted] 45.154.138.90 - - [22/Feb/2026:21:52:13 +0100] "GET /wp-content/uploads/admin.php HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
[redacted] 45.154.138.90 - - [22/Feb/2026:21
...
show less
Hacking
Web App Attack
π¬π§
consul.to
2026-02-22 17:37:12
(3 months ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-22 15:34:56
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.154.138.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.154.138.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 22 10:34:53.034698 2026] [security2:error] [pid 28012:tid 28012] [client 45.154.138.90:30859] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.avvmarchetticollini.it"] [uri "/.git/HEAD"] [unique_id "aZsiHR_ocUvUqrWNrH8h2wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-19 23:59:34
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.154.138.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.154.138.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 19 18:58:57.305921 2026] [security2:error] [pid 17429:tid 17429] [client 45.154.138.90:26953] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "historiapatria.aguasolar.com"] [uri "/.git/HEAD"] [unique_id "aZejwYnxj4d6d_Y5UXj-bQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-19 22:49:33
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.154.138.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.154.138.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 19 17:49:30.035013 2026] [security2:error] [pid 8238:tid 8247] [client 45.154.138.90:52417] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sonatro.io"] [uri "/.git/HEAD"] [unique_id "aZeTegB0Hcadh0aX_AS9ZwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-19 22:14:58
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.154.138.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.154.138.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 19 17:14:53.277949 2026] [security2:error] [pid 4425:tid 4425] [client 45.154.138.90:65259] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.connectigramme.com.linguistes.com"] [uri "/.git/HEAD"] [unique_id "aZeLXeYYWuAi8uNi353r5wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-19 17:14:50
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.154.138.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.154.138.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 19 12:14:41.193776 2026] [security2:error] [pid 14984:tid 14984] [client 45.154.138.90:55275] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.santasfavorites.com.piratecostumesonline.com"] [uri "/.git/HEAD"] [unique_id "aZdFARFYH_T1ax-H6-LArQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
conseilgouz
2026-02-19 12:24:07
(3 months ago)
hae-7 : Trying access unauthorized files/dir=>/wp-includes/widgets/wp-login.php
Hacking