๐ซ๐ท
masterguru
2026-03-26 15:29:03
(3 months ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 45.3.49.184 (US/United States/-): 1 in the las ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 45.3.49.184 (US/United States/-): 1 in the last 3600 secs (0-193)
show less
Hacking
๐ช๐ธ
10dencehispahard SL
2026-01-26 11:35:59
(5 months ago)
Wordpress probing for vulnerabilities
Hacking
Exploited Host
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-29 14:01:11
(6 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-12-29 05:29:55
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.49.184 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.49.184 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 00:29:48.945281 2025] [security2:error] [pid 4514:tid 4514] [client 45.3.49.184:37377] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cbsproductionsinc.com"] [uri "/.env"] [unique_id "aVIRzJeJnvm_0njzTkShagAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 04:45:39
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.49.184 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.49.184 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 23:45:30.835653 2025] [security2:error] [pid 24604:tid 24604] [client 45.3.49.184:13541] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "omnitractors.com"] [uri "/.svn/wc.db"] [unique_id "aVIHale9a3mIeirOUtjvMgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2025-12-24 07:50:09
(6 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
Anonymous
2025-12-11 22:53:53
(6 months ago)
botnet
DDoS Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 06:36:33
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.49.184 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.49.184 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 01:36:26.659811 2025] [security2:error] [pid 13041:tid 13041] [client 45.3.49.184:60521] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.title16.com"] [uri "/.env"] [unique_id "aSaf6taV2GmsX1brByE_eAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 05:34:26
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.49.184 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.49.184 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 00:34:21.565877 2025] [security2:error] [pid 2556:tid 2556] [client 45.3.49.184:33259] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.blockdredge.com"] [uri "/.git/HEAD"] [unique_id "aSaRXRu2UGA3wbqCh4aYZQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 01:44:18
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.49.184 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.49.184 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 20:44:09.842058 2025] [security2:error] [pid 30540:tid 30540] [client 45.3.49.184:43943] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.brunswickcemeteries.org"] [uri "/.env"] [unique_id "aSZbaSk4HeukMrSJVHE9SAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 00:43:23
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.49.184 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.49.184 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 19:43:18.000626 2025] [security2:error] [pid 25379:tid 25379] [client 45.3.49.184:42035] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.a2thdoc.com"] [uri "/.svn/wc.db"] [unique_id "aSZNJcDLLtd_Z7aWlmzCfgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 09:33:34
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.49.184 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.49.184 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:33:10.669267 2025] [security2:error] [pid 1306:tid 1306] [client 45.3.49.184:19775] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.northmyrtlebeachcondos.com"] [uri "/.svn/wc.db"] [unique_id "aSQmVvxfLLdPC9S-w5qenwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 09:17:02
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.49.184 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.49.184 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:16:53.703839 2025] [security2:error] [pid 11311:tid 11311] [client 45.3.49.184:55049] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.lindafoley.com"] [uri "/.env"] [unique_id "aSQihbsSVctxDD09wqiu7gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-23 17:53:52
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.49.184 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.49.184 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 12:53:45.198130 2025] [security2:error] [pid 21334:tid 21334] [client 45.3.49.184:23971] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.discountbirthannouncements.com"] [uri "/.git/config"] [unique_id "aSNKKXB4ZGNsK-FBnAtYPAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-14 07:39:02
(7 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack