Anonymous
2026-01-05 20:38:21
(5 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2026.01.05 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2026.01.05 is noted in report timestamp
show less
Hacking
Brute-Force
๐ฎ๐ฉ
Burayot
2026-01-02 16:35:38
(5 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 45.3.46.16 (CA/Canada/-): 1 in the ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 45.3.46.16 (CA/Canada/-): 1 in the last 3600 secs
show less
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-29 14:00:48
(5 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-11-26 11:29:55
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.46.16 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.46.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 06:29:48.191278 2025] [security2:error] [pid 30689:tid 30689] [client 45.3.46.16:29967] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.maunakeavista.com"] [uri "/.env"] [unique_id "aSbkrAFF5K_FHFbU4qYJ6AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 05:52:12
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.46.16 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.46.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 00:52:07.600175 2025] [security2:error] [pid 19425:tid 19425] [client 45.3.46.16:59159] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.infinite-e.com"] [uri "/.svn/wc.db"] [unique_id "aSaVh8lryc8UewFQYunR6QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 00:27:04
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.46.16 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.46.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 19:26:56.689346 2025] [security2:error] [pid 8440:tid 8440] [client 45.3.46.16:19545] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.mike-garner.com"] [uri "/.git/HEAD"] [unique_id "aSZJULHfLPkRms_EZV7f5gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MPL
2025-11-25 22:00:14
(6 months ago)
tcp/80 (27 or more attempts)
Port Scan
๐บ๐ธ
TPI-Abuse
2025-11-25 00:43:42
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.46.16 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.46.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 19:43:33.198796 2025] [security2:error] [pid 1647077:tid 1647110] [client 45.3.46.16:17949] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.wegelin.org"] [uri "/.git/HEAD"] [unique_id "aST7tdNHCagQpGvj6qO4TwAAAkM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-10 20:23:55
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.46.16 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.46.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 10 15:23:47.327539 2025] [security2:error] [pid 26625:tid 26625] [client 45.3.46.16:44295] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.campos.tv"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aRJJ00qkLHu7wcYRu0O3jgAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-02 21:56:19
(7 months ago)
This IP was involved in an brute force and password spray attack on 2025/11/02 07:15:25
Port Scan
Brute-Force
Exploited Host
Web App Attack
Anonymous
2025-10-30 14:56:49
(7 months ago)
WordPress Brute Force
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-10-10 21:04:03
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 45.3.46.16 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 45.3.46.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 10 17:03:56.602691 2025] [security2:error] [pid 3754:tid 3754] [client 45.3.46.16:9763] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dr-taylor.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dr-taylor.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aOl0vFvQ8yklsDzuGERWTQAAAA8"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ps-center
2025-02-10 19:47:10
(1 year ago)
C1: Web Attack POST /wp-login.php
Web Spam
Hacking
Bad Web Bot
Web App Attack
Anonymous
2024-12-29 13:52:06
(1 year ago)
wordpress-trap
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-12 19:04:23
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.3.46.16 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 45.3.46.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 12 14:04:17.362511 2024] [security2:error] [pid 7992:tid 7992] [client 45.3.46.16:52607] [client 45.3.46.16] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||stormwlf.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "stormwlf.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZzOmsfIPaoOAy1lplBGDnwAAABc"], referer: https://stormwlf.com
show less
Brute-Force
Bad Web Bot
Web App Attack