๐ณ๐ฑ
homeshowdomain.nl
2026-05-28 22:03:46
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-27.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-28 01:59:29
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 45.43.64.149 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.43.64.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 21:59:22.729469 2026] [security2:error] [pid 12740:tid 12740] [client 45.43.64.149:43741] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "poohippie.com"] [uri "/.env.vercel"] [unique_id "ahehenbdnYkuluHmrmumyAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-05-27 23:22:44
(1 week ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 45.43.64.149 (GB/United Kingdom/-): ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 45.43.64.149 (GB/United Kingdom/-): 1 in the last 3600 secs
show less
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-27 21:59:37
(1 week ago)
Auto-ban: >3000 req/min op 2026-05-27
Web App Attack
SSH
Hacking
๐บ๐ธ
OceanTreasure
2026-05-27 19:45:29
(1 week ago)
tcp/443; SQL backup file access attempt: "GET /backup.sql" @ 2026-05-27T19:37:13Z [proxy]
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-05-27 19:20:10
(1 week ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ksol-hostmaster
2026-05-27 19:13:28
(1 week ago)
2026/05/27 21:13:27 [error] 60639#101439: *978481 limiting requests, excess: 0.964 by zone "crawler" ...
show more
2026/05/27 21:13:27 [error] 60639#101439: *978481 limiting requests, excess: 0.964 by zone "crawler", client: 45.43.64.149, server: ksol.io, request: "GET /sitemap_index.xml HTTP/1.1", host: "ksol.io"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-27 18:43:44
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 45.43.64.149 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:949110) triggered by 45.43.64.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 14:43:19.537672 2026] [security2:error] [pid 6326:tid 6326] [client 45.43.64.149:43419] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.tsmdsc.cescfoundation.org"] [uri "/wp-config.php.swp"] [unique_id "ahc7R7qBWNWhrQfXgOetIwAAAAU"], referer: https://www.google.com/search?q=www.tsmdsc.cescfoundation.org
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-05-27 15:48:00
(1 week ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-27 12:18:51
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 45.43.64.149 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.43.64.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 08:18:45.835156 2026] [security2:error] [pid 20405:tid 20405] [client 45.43.64.149:55983] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.z-industrial.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.z-industrial.com"] [uri "/backup.sql"] [unique_id "ahbhJWv9-qlzxI7Fn0xL_QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-05-27 03:52:55
(1 week ago)
[WedMay2705:52:52.1737542026][security2:error][pid1082002:tid1082342][client45.43.64.149:0]ModSecuri ...
show more
[WedMay2705:52:52.1737542026][security2:error][pid1082002:tid1082342][client45.43.64.149:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\"wp-config\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"cpu-services.ch\"][uri\"/wp-config.php.swp\"][unique_id\"ahZqlHq1OLB-hb2AZuyCmgAAAQ8\"]
show less
Hacking
Web App Attack
Anonymous
2026-05-27 03:14:28
(1 week ago)
45.43.64.149 - - [27/May/2026:11:14:28 +0800] "HEAD /wp-config.php~ HTTP/1.1" 404 - "https://www.goo ...
show more
45.43.64.149 - - [27/May/2026:11:14:28 +0800] "HEAD /wp-config.php~ HTTP/1.1" 404 - "https://www.google.com/search?q=www.witgang.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 00:32:19
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 45.43.64.149 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.43.64.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 20:32:11.192972 2026] [security2:error] [pid 7453:tid 7453] [client 45.43.64.149:51591] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.macallanmitchell.macryder.com"] [uri "/wp-config.php~"] [unique_id "ahY7i1bTP-erPXzYHiszQQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Roderic
2026-01-25 02:57:59
(4 months ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
๐บ๐ธ
rsiddall
2024-02-14 14:48:48
(2 years ago)
45.43.64.149 - - [14/Feb/2024:09:47:57 -0500] "POST /xmlrpc.php HTTP/1.1" 403 1809 "https://blog.jan ...
show more
45.43.64.149 - - [14/Feb/2024:09:47:57 -0500] "POST /xmlrpc.php HTTP/1.1" 403 1809 "https://blog.janehaddam.com/" "PHP/5.3.51"
45.43.64.149 - - [14/Feb/2024:09:48:48 -0500] "POST /xmlrpc.php HTTP/1.1" 403 1809 "https://blog.janehaddam.com/" "PHP/5.2.73"
...
show less
Brute-Force