🇭🇺
bcsaba
2026-09-14 14:22:54
(1 day ago)
Going for WP CVE-2026-63030
45.5.56.185 - - [14/Sep/2026:16:22:53 +0200] "POST /?rest_route=/batch/v ...
show more
Going for WP CVE-2026-63030
45.5.56.185 - - [14/Sep/2026:16:22:53 +0200] "POST /?rest_route=/batch/v1 HTTP/1.1" 403 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
show less
Web App Attack
🇬🇧
Apache
2026-09-14 14:21:03
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 45.5.56.185 (PE/Peru/-): 5 in the last 300 secs ...
show more
(mod_security) mod_security (id:210492) triggered by 45.5.56.185 (PE/Peru/-): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
Anonymous
2026-09-14 10:23:46
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-14 09:22:08
(1 day ago)
[ns3.backorder.gr] httpd-config-scan: sites=www.justcare.gr; logs=/var/log/httpd/domains/justcare.gr ...
show more
[ns3.backorder.gr] httpd-config-scan: sites=www.justcare.gr; logs=/var/log/httpd/domains/justcare.gr.log; samples=/wp-config.php.save
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 07:38:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 45.5.56.185 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.5.56.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 03:37:59.548071 2026] [security2:error] [pid 21316:tid 21316] [client 45.5.56.185:44682] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.hg/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.casadelsolmexico.net"] [uri "/.hg/store/00manifest.i"] [unique_id "aqekV0hpC7R3Az-ROnNzyQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 22:50:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 45.5.56.185 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.5.56.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 18:49:52.061090 2026] [security2:error] [pid 25370:tid 25370] [client 45.5.56.185:55316] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "magacine.tv"] [uri "/.env.bak"] [unique_id "aqcokFzQNR5HTUyDDniP0gAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 21:01:14
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 45.5.56.185 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:949110) triggered by 45.5.56.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 17:01:09.871777 2026] [security2:error] [pid 22366:tid 22366] [client 45.5.56.185:59262] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "delcano.org"] [uri "/wp-config.php.bak"] [unique_id "aqcPFUesNaIOCy76eZmBRAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-13 19:40:01
(1 day ago)
crowdsecurity/http-cve-probing
Brute-Force
Web App Attack
🇺🇸
mnsf
2026-09-13 19:05:35
(1 day ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
Anonymous
2026-09-13 15:26:13
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-13 15:01:46
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 12:09:40
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 45.5.56.185 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.5.56.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 08:09:33.195540 2026] [security2:error] [pid 2856:tid 2856] [client 45.5.56.185:42432] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/composer.lock" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "versallis.com"] [uri "/composer.lock"] [unique_id "aqaSfbuFrPxBObWQoloAXQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 09:42:19
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 45.5.56.185 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.5.56.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 05:42:10.958907 2026] [security2:error] [pid 12454:tid 12454] [client 45.5.56.185:37232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "desdier.com"] [uri "/.env.save"] [unique_id "aqZv8oLWw5LIY32X24vsZAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 08:55:07
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 45.5.56.185 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.5.56.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 04:54:58.961588 2026] [security2:error] [pid 860882:tid 860882] [client 45.5.56.185:32940] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "joeordie.com"] [uri "/.env.txt"] [unique_id "aqZk4vHgGadJw9OXYPmwVgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 03:50:40
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 45.5.56.185 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.5.56.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 23:50:34.523855 2026] [security2:error] [pid 27461:tid 27461] [client 45.5.56.185:41850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tcit.org"] [uri "/.env.old"] [unique_id "aqYdigZvitNpj_20jkrRvwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack