๐บ๐ธ
ctrlpew
2026-05-19 01:01:04
(3 weeks ago)
WordPress login brute-force botnet targeting ctrlpew.com. Distributed IPs cycling every 3 seconds wi ...
show more
WordPress login brute-force botnet targeting ctrlpew.com. Distributed IPs cycling every 3 seconds with UA rotation. All attempts against non-existent usernames. 2026-05-18.
show less
Brute-Force
Web App Attack
๐บ๐ธ
oncord
2026-03-30 23:21:42
(2 months ago)
Form spam
Web Spam
๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(2 months ago)
"DDoS against public endpoint"
DDoS Attack
Anonymous
2026-02-24 05:50:49
(3 months ago)
Probing to gain illegal access
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-23 22:57:35
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.33.178 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.33.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 17:57:30.988345 2026] [security2:error] [pid 10981:tid 10981] [client 45.3.33.178:38917] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "draintheswamp.banis-associates.com"] [uri "/.git/config"] [unique_id "aZzbWizmZLGz-vC7wAvMvwAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Lino Project
2026-01-09 00:55:55
(5 months ago)
45.3.33.178 - - [09/Jan/2026:01:55:54 +0100] "POST /xmlrpc.php HTTP/1.1" 403 3945 "-" "Wget/1.21.4"
...
show more
45.3.33.178 - - [09/Jan/2026:01:55:54 +0100] "POST /xmlrpc.php HTTP/1.1" 403 3945 "-" "Wget/1.21.4"
45.3.33.178 - - [09/Jan/2026:01:55:54 +0100] "POST /xmlrpc.php HTTP/1.1" 403 3945 "-" "curl/7.88.1"
45.3.33.178 - - [09/Jan/2026:01:55:55 +0100] "POST /xmlrpc.php HTTP/1.1" 403 3945 "-" "curl/7.88.1"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-11-30 13:09:55
(6 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-11-25 05:29:12
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.33.178 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.33.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 00:28:57.146326 2025] [security2:error] [pid 11448:tid 11448] [client 45.3.33.178:40349] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.economy-cleaners.walkerweb.com"] [uri "/.svn/wc.db"] [unique_id "aSU-mdqNcLqoQabH6dURqQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:26:45
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.33.178 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.33.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:26:39.963906 2025] [security2:error] [pid 5129:tid 5129] [client 45.3.33.178:58311] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.veneye.com"] [uri "/.svn/wc.db"] [unique_id "aSUv_8PVsETjMCkPllL81AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 03:38:51
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.33.178 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.33.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:38:48.382579 2025] [security2:error] [pid 7916:tid 7916] [client 45.3.33.178:56693] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.demircan.org"] [uri "/.git/HEAD"] [unique_id "aSUkyA0WQdcdjDsnvo7ohAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 02:26:07
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.33.178 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.33.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:25:49.905888 2025] [security2:error] [pid 27768:tid 27768] [client 45.3.33.178:19407] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.joyfulservice.com"] [uri "/.env"] [unique_id "aSUTrY4uvbJ7iSKl3acp8AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 02:08:22
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.33.178 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.33.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:08:12.630871 2025] [security2:error] [pid 29767:tid 29767] [client 45.3.33.178:23263] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gnquivers.com"] [uri "/.svn/wc.db"] [unique_id "aSUPjFKS3oLCXMnGbiuBjQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Carsten
2025-11-24 10:14:46
(6 months ago)
GET [.aws/credentials]
Port Scan
๐บ๐ธ
TPI-Abuse
2025-11-24 09:40:49
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.33.178 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.33.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:40:40.852680 2025] [security2:error] [pid 9710:tid 9710] [client 45.3.33.178:21683] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.awcadvocate.com"] [uri "/.git/HEAD"] [unique_id "aSQoGBt3gLnAS1eSOmn82gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 06:42:28
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.33.178 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.33.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:42:18.626543 2025] [security2:error] [pid 13940:tid 13955] [client 45.3.33.178:32451] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.uoexpanse.com"] [uri "/.git/HEAD"] [unique_id "aSP-SlcEhUGiZJQ6jyqV8AAAAMQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack