๐ธ๐ช
OnTheEdge
2026-09-03 18:16:56
(2 weeks ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
๐ณ๐ฑ
Savvii
2026-08-31 04:12:09
(2 weeks ago)
20 attempts against mh_ha-misbehave-ban on yeti
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-30 08:11:03
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 127
Exploited Host
Web App Attack
๐ช๐ธ
librebit
2026-07-26 16:40:15
(1 month ago)
Brute force
Brute-Force
๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(5 months ago)
"DDoS against public endpoint"
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 02:32:40
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.48.174 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.48.174 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 17 21:32:33.920086 2026] [security2:error] [pid 25722:tid 25722] [client 45.3.48.174:15763] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rentalmgt.com"] [uri "/site/.git/config"] [unique_id "aZUkwYRQ5r2E_V-U2w-fiAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 00:50:27
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.48.174 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.48.174 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 17 19:50:17.330780 2026] [security2:error] [pid 13351:tid 13351] [client 45.3.48.174:17169] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "paulpasquali.com"] [uri "/backend/.env"] [unique_id "aZUMycCH6CX_kCGwICK7wAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-01 17:30:53
(7 months ago)
wordpress-trap
Web App Attack
๐บ๐ธ
mind5t0rm
2026-01-30 08:48:24
(7 months ago)
(XMLRPC,WPLOGIN) Login failure/trigger from 45.3.48.174 (US/United States/-): 3 in the last 3600 sec ...
show more
(XMLRPC,WPLOGIN) Login failure/trigger from 45.3.48.174 (US/United States/-): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: 45.3.48.174 - - [30/Jan/2026:15:47:57 +0700] "GET /wp-login.php HTTP/2.0" 200 2453 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Safari/605.1.15"
45.3.48.174 - - [30/Jan/2026:15:47:58 +0700] "POST /xmlrpc.php HTTP/2.0" 403 154 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:127.0) Gecko/20100101 Firefox/127.0"
45.3.48.174 - - [30/Jan/2026:15:48:21 +0700] "GET /wp-login.php HTTP/2.0" 200 2453 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.6367.207 Safari/537.36"
show less
Port Scan
Anonymous
2025-12-10 11:22:55
(9 months ago)
botnet
DDoS Attack
Anonymous
2025-11-28 07:08:10
(9 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.11.28 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.11.28 is noted in report timestamp
show less
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-11-25 05:07:38
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.48.174 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.48.174 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 00:07:34.573915 2025] [security2:error] [pid 13513:tid 13513] [client 45.3.48.174:31159] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.nwarchitect.com"] [uri "/.env"] [unique_id "aSU5lphhrpvl4EXTQfcX_gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 03:53:32
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.48.174 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.48.174 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:53:25.718565 2025] [security2:error] [pid 32735:tid 321] [client 45.3.48.174:33209] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.psychclinicforchange.com"] [uri "/.svn/wc.db"] [unique_id "aSUoNeyRrmvyed2G3rXJ7QAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 02:53:56
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.48.174 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.48.174 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:53:50.117256 2025] [security2:error] [pid 1647139:tid 1647168] [client 45.3.48.174:40065] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.penboy7.com"] [uri "/.svn/wc.db"] [unique_id "aSUaPp5eMzOQPKYL6rIEWwAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 02:01:34
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.48.174 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.48.174 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:01:29.913781 2025] [security2:error] [pid 19823:tid 19823] [client 45.3.48.174:19451] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.jbrodriguez.com"] [uri "/.git/HEAD"] [unique_id "aSUN-b-Le6eALvlPR0rHdAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack