Anonymous
2026-01-03 13:35:20
(5 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2026.01.03 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2026.01.03 is noted in report timestamp
show less
Hacking
Brute-Force
๐ฉ๐ช
bescared
2026-01-02 18:38:59
(5 months ago)
F2B - Malicious activity detected. URL Probing.
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 05:37:20
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.46.1 (-): 1 in the last 300 secs; Ports: * ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.46.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 00:37:17.323360 2025] [security2:error] [pid 9474:tid 9474] [client 45.3.46.1:39531] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vampireproductions.com"] [uri "/.svn/wc.db"] [unique_id "aVITjaQC5T6w9E1NNaC1BAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 05:16:45
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.46.1 (-): 1 in the last 300 secs; Ports: * ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.46.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 00:16:39.364490 2025] [security2:error] [pid 26201:tid 26201] [client 45.3.46.1:27843] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "z-mgmt.com"] [uri "/.git/HEAD"] [unique_id "aVIOtyDMwE8dZs-QZBPfQAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 03:57:49
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.46.1 (-): 1 in the last 300 secs; Ports: * ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.46.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 22:57:46.167396 2025] [security2:error] [pid 9320:tid 9320] [client 45.3.46.1:55859] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "coffeewitheinstein.com"] [uri "/.svn/wc.db"] [unique_id "aVH8OnICHBHN8_xpIO2GwgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 05:13:11
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.46.1 (-): 1 in the last 300 secs; Ports: * ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.46.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 00:13:04.688543 2025] [security2:error] [pid 23373:tid 23373] [client 45.3.46.1:49339] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.recollected.net"] [uri "/.env"] [unique_id "aSaMYBqRdy05UG1uEm4iXwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 06:17:03
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.46.1 (-): 1 in the last 300 secs; Ports: * ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.46.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 01:16:54.546902 2025] [security2:error] [pid 8969:tid 8969] [client 45.3.46.1:41031] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.gavinnine.com"] [uri "/.git/HEAD"] [unique_id "aSVJ1gx0oAI9xZ0mgWDPIAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 05:10:29
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.46.1 (-): 1 in the last 300 secs; Ports: * ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.46.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 00:10:25.390769 2025] [security2:error] [pid 21001:tid 21001] [client 45.3.46.1:58245] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.marisetravel.com"] [uri "/.env"] [unique_id "aSU6QdoaFiwMIt5VK2pNNwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:11:24
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.46.1 (-): 1 in the last 300 secs; Ports: * ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.46.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:11:11.621417 2025] [security2:error] [pid 5491:tid 5491] [client 45.3.46.1:54847] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.mvseasea.com"] [uri "/.git/HEAD"] [unique_id "aSUsX83-F4UzDMF3_19uowAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 02:35:30
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.46.1 (-): 1 in the last 300 secs; Ports: * ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.46.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:35:22.747903 2025] [security2:error] [pid 26891:tid 26891] [client 45.3.46.1:18275] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.sitexpress.es"] [uri "/.git/HEAD"] [unique_id "aSUV6uAERWLyKBUg-ioe6wAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 00:04:37
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.46.1 (-): 1 in the last 300 secs; Ports: * ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.46.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 19:04:23.082236 2025] [security2:error] [pid 1590769:tid 1590782] [client 45.3.46.1:56689] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ioqm.com"] [uri "/.git/HEAD"] [unique_id "aSTyh2GwGZE4_DDLbJbKzAAAAIs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 08:10:27
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.46.1 (-): 1 in the last 300 secs; Ports: * ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.46.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:10:13.778504 2025] [security2:error] [pid 2628:tid 2628] [client 45.3.46.1:11807] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.barristershall.com"] [uri "/.env"] [unique_id "aSQS5Z4I6X2iV9ON6V4fvwAAADs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-21 18:27:50
(6 months ago)
This IP was involved in an brute force and password spray attack on 2025/11/21 12:25:01
Port Scan
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-23 20:49:35
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.3.46.1 (-): 1 in the last 300 secs; Ports: * ...
show more
(mod_security) mod_security (id:225170) triggered by 45.3.46.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 23 16:49:31.510808 2025] [security2:error] [pid 57166:tid 57166] [client 45.3.46.1:52621] [client 45.3.46.1] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||salsberggroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "salsberggroup.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z-Bz2wbH_Z5CEL-E40iLcgAAABs"], referer: https://salsberggroup.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-21 06:40:04
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.3.46.1 (-): 1 in the last 300 secs; Ports: * ...
show more
(mod_security) mod_security (id:225170) triggered by 45.3.46.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 21 01:39:58.876416 2025] [security2:error] [pid 20995:tid 20995] [client 45.3.46.1:21085] [client 45.3.46.1] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||enfiestate.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "enfiestate.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z7gfvmS0XLsMtGrkoe0LFgAAABM"], referer: https://enfiestate.com
show less
Brute-Force
Bad Web Bot
Web App Attack