πΊπΈ
TPI-Abuse
2025-11-24 09:01:43
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.50.103 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.50.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:01:36.394777 2025] [security2:error] [pid 3396:tid 3396] [client 45.3.50.103:24527] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.californiastarsfarm.com"] [uri "/.git/HEAD"] [unique_id "aSQe8JD_V4nQz7HZDPXclgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 08:39:31
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.50.103 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.50.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:39:10.068004 2025] [security2:error] [pid 13940:tid 13959] [client 45.3.50.103:56937] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.aapmapac.com"] [uri "/.env"] [unique_id "aSQZrlcEhUGiZJQ6jyrAegAAAMg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 07:52:43
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.50.103 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.50.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:52:38.772765 2025] [security2:error] [pid 30667:tid 30667] [client 45.3.50.103:49359] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.waynemather.com"] [uri "/.git/HEAD"] [unique_id "aSQOxgqW4s75aCmSwlEegwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 07:35:45
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.50.103 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.50.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:35:39.193138 2025] [security2:error] [pid 10128:tid 10128] [client 45.3.50.103:37161] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.kirt.us"] [uri "/.svn/wc.db"] [unique_id "aSQKy0PpLeLpcH_TIBsTQwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 06:18:57
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.50.103 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.50.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:18:53.514580 2025] [security2:error] [pid 16498:tid 16498] [client 45.3.50.103:54857] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.rendermatrix.com"] [uri "/.svn/wc.db"] [unique_id "aSP4zSj3B9Kzu8HyeynV6wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-13 21:11:19
(6 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
Anonymous
2025-10-06 04:04:01
(8 months ago)
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.10.06 is noted in report tim ...
show more
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.10.06 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-09-28 14:55:45
(8 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.09.28 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.09.28 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-09-27 01:02:44
(8 months ago)
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.09.27 is noted in report tim ...
show more
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.09.27 is noted in report timestamp
show less
Hacking
Brute-Force
π©πͺ
Hazzard
2025-03-12 08:02:42
(1 year ago)
(plesk-panel) Failed plesk-panel login with username [redacted])
Brute-Force
πΊπΈ
TPI-Abuse
2024-12-22 03:35:03
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.3.50.103 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 45.3.50.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 21 22:34:58.398781 2024] [security2:error] [pid 2974438:tid 2974438] [client 45.3.50.103:59695] [client 45.3.50.103] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tradenaples.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tradenaples.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z2eI4oTg9C_093D8DFqsuAAAAAQ"], referer: https://tradenaples.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-11-17 05:56:08
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.3.50.103 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 45.3.50.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 17 00:56:01.136861 2024] [security2:error] [pid 2018:tid 2018] [client 45.3.50.103:42723] [client 45.3.50.103] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||egret.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "egret.us"] [uri "/wp-json/wp/v2/users"] [unique_id "ZzmFcV5SwY-MbctFR8afjgAAAAY"], referer: https://egret.us
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
hostseries
2024-10-29 14:50:16
(1 year ago)
Trigger: LF_DISTATTACK
Brute-Force
πΊπΈ
TPI-Abuse
2024-10-18 18:14:16
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.3.50.103 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 45.3.50.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 18 14:14:13.672281 2024] [security2:error] [pid 29489:tid 29489] [client 45.3.50.103:14369] [client 45.3.50.103] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||firstamericanind.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "firstamericanind.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZxKldVF6rqjW4NWKCEKsXAAAAAo"], referer: https://firstamericanind.com
show less
Brute-Force
Bad Web Bot
Web App Attack