Anonymous
2026-04-12 05:41:06
(1 month ago)
Attempt to scan vulnerabilities
Hacking
๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(2 months ago)
"DDoS against public endpoint"
DDoS Attack
Anonymous
2025-12-27 13:08:34
(5 months ago)
2025-12-27T15:08:33.729111+02:00 zanati wp(www.sahpa.co.za)[193657]: Blocked authentication attempt ...
show more
2025-12-27T15:08:33.729111+02:00 zanati wp(www.sahpa.co.za)[193657]: Blocked authentication attempt for [email protected] from 45.3.34.158
...
show less
Web App Attack
๐ฎ๐น
VHosting
2025-12-23 10:47:51
(5 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
๐บ๐ธ
COMPLEX
2025-12-15 05:41:10
(5 months ago)
Triggered Cloudflare WAF (l7ddos) from US.
Action taken: BLOCK
ASN: 200373 (DREI-K-TECH-GMBH)
Protoc ...
show more
Triggered Cloudflare WAF (l7ddos) from US.
Action taken: BLOCK
ASN: 200373 (DREI-K-TECH-GMBH)
Protocol: HTTP/2 (GET method)
Endpoint: /
show less
DDoS Attack
Bad Web Bot
Anonymous
2025-12-10 15:37:02
(5 months ago)
botnet
DDoS Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:50:40
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.34.158 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.34.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:50:34.411865 2025] [security2:error] [pid 5910:tid 5910] [client 45.3.34.158:17061] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.mandel.vc"] [uri "/.git/HEAD"] [unique_id "aSU1mlWrVSmf43Eqsn9zOwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:08:48
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.34.158 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.34.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:08:28.759923 2025] [security2:error] [pid 620:tid 620] [client 45.3.34.158:23663] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.brennanarchitecture.com"] [uri "/.svn/wc.db"] [unique_id "aSUrvCWlrI1kODNND6p2vwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 03:04:57
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.34.158 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.34.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:04:40.956418 2025] [security2:error] [pid 703901:tid 703901] [client 45.3.34.158:29221] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "globalaccessau.com.salsberggroup.com"] [uri "/.svn/wc.db"] [unique_id "aSUcyLMXSC6WG9Gcdpho0QAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-16 03:12:13
(6 months ago)
botnet
DDoS Attack
Anonymous
2025-11-13 20:40:55
(6 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
Anonymous
2025-11-02 19:53:55
(7 months ago)
This IP was involved in an brute force and password spray attack on 2025/11/02 07:00:25
Port Scan
Brute-Force
Exploited Host
Web App Attack
๐จ๐ฆ
wil.com
2025-10-28 23:38:57
(7 months ago)
GlobalProtect login attempts with user kawasakik.
VPN IP
Brute-Force
๐ง๐ท
hostseries
2025-10-25 07:37:02
(7 months ago)
Trigger: LF_DISTATTACK
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-04-04 08:08:23
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.3.34.158 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 45.3.34.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 04 04:08:17.711277 2025] [security2:error] [pid 949441:tid 949441] [client 45.3.34.158:31453] [client 45.3.34.158] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gemexpressions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gemexpressions.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z--TcQkJCqNUtj07X9eeogAAAAE"], referer: https://gemexpressions.com
show less
Brute-Force
Bad Web Bot
Web App Attack