๐ณ๐ฑ
Savvii
2026-04-02 22:37:40
(2 months ago)
20 attempts against mh_ha-misbehave-ban on ethyl
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
Peter-Johann Sarbach
2026-01-17 06:41:36
(4 months ago)
Hacking website
Hacking
๐ณ๐ฑ
jjnxpct
2026-01-17 04:48:00
(4 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /s3cmd.ini (Rule ID: 920440) - URL file extension is restricted by policy
show less
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-16 17:51:29
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.46.87 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.46.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 12:51:24.843278 2026] [security2:error] [pid 31285:tid 31337] [client 45.3.46.87:52013] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.crowns.org"] [uri "/.env"] [unique_id "aWp6nI7pfUZH-1riQvgQHAAAAMA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Steve
2025-12-24 01:35:43
(5 months ago)
Repeated attempts against wordpress site
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2025-12-24 00:25:07
(5 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 06:24:35
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.46.87 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.46.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 01:24:28.693557 2025] [security2:error] [pid 9736:tid 9736] [client 45.3.46.87:44235] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.1educare.gemexpressions.com"] [uri "/.env"] [unique_id "aSVLnDvFnyIeqrrmq-ry4gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-25 04:05:02
(6 months ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 03:50:32
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.46.87 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.46.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:50:04.131066 2025] [security2:error] [pid 4235:tid 4235] [client 45.3.46.87:24221] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "digitalonlinesuperstore.com"] [uri "/.git/HEAD"] [unique_id "aSUnbOJPnn4rYEsRPoMusAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2025-11-25 02:48:44
(6 months ago)
Attempted access to sensitive endpoint (/.svn/wc.db) detected. Automated scan or unauthorized probin ...
show more
Attempted access to sensitive endpoint (/.svn/wc.db) detected. Automated scan or unauthorized probing.
show less
Web App Attack
Anonymous
2025-11-13 18:55:46
(6 months ago)
This IP was involved in an brute force and password spray attack on 2025/11/13 12:52:45
Port Scan
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-02 17:16:07
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.3.46.87 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 45.3.46.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 02 12:16:01.785986 2025] [security2:error] [pid 2805:tid 2805] [client 45.3.46.87:26341] [client 45.3.46.87] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||chameleonpcs.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "chameleonpcs.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z5-oUcdGVF_dD-M2pmGqeAAAAAE"], referer: https://chameleonpcs.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-30 15:39:07
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.3.46.87 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 45.3.46.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 30 10:39:01.106811 2025] [security2:error] [pid 18309:tid 18309] [client 45.3.46.87:12661] [client 45.3.46.87] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||portraitsinblues.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "portraitsinblues.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z5udFU5bznb-KM1Owdez8QAAABc"], referer: https://portraitsinblues.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2024-12-24 07:35:04
(1 year ago)
block ruleset Badbot using very old user-agents 5CF3CDB778C7D82564405B86B9242E612F378C68
Bad Web Bot
๐ฉ๐ช
XICTRON
2024-12-12 11:30:24
(1 year ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host