๐ซ๐ท
masterguru
2026-05-01 05:21:11
(1 month ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 45.66.208.32 (US/United States/-): 2 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 45.66.208.32 (US/United States/-): 2 in the last 3600 secs (0-196)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-30 05:50:40
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 45.66.208.32 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.66.208.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 01:50:36.550300 2026] [security2:error] [pid 29219:tid 29219] [client 45.66.208.32:21291] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sandpointidaho.com.kh6jim.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sandpointidaho.com.kh6jim.com"] [uri "/s3cmd.ini"] [unique_id "afLtrF07vl7Y5TWC09GawgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-04-28 11:47:08
(1 month ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 45.66.208.32 (US/United States/-): 1 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 45.66.208.32 (US/United States/-): 1 in the last 3600 secs (0-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-28 00:12:04
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 45.66.208.32 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.66.208.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 27 20:11:58.225342 2026] [security2:error] [pid 25724:tid 25724] [client 45.66.208.32:59613] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||servicioslama.com.matronasoy.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "servicioslama.com.matronasoy.com"] [uri "/s3cmd.ini"] [unique_id "ae_7TphBaYKplmmLMWegDAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-26 10:25:01
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 45.66.208.32 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.66.208.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 06:24:53.348206 2026] [security2:error] [pid 2191:tid 2191] [client 45.66.208.32:65089] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.exit10band.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.exit10band.com"] [uri "/s3cmd.ini"] [unique_id "ae3n9Y7Hzr87sX0OoKO6ZQAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-25 11:43:31
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 45.66.208.32 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 45.66.208.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 25 07:43:24.853041 2026] [security2:error] [pid 12851:tid 12851] [client 45.66.208.32:22777] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||intercite.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "intercite.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acPKXBzaZIq34xFMBDl8TgAAABY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-03-03 20:52:01
(3 months ago)
45.66.208.32 - - [03/Mar/2026:13:52:00 -0700] "POST /wp-login.php HTTP/1.1" 200 2354 "https://dooce. ...
show more
45.66.208.32 - - [03/Mar/2026:13:52:00 -0700] "POST /wp-login.php HTTP/1.1" 200 2354 "https://dooce.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-01-23 00:25:00
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 45.66.208.32 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 45.66.208.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 19:24:56.202876 2026] [security2:error] [pid 8787:tid 8787] [client 45.66.208.32:45901] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||natickvillagerentals.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "natickvillagerentals.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aXK_2Av_K0twHiu7FbsVoAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
ketovoila.pl
2026-01-22 15:03:44
(4 months ago)
ketovoila.pl HONEYPOT traffic: count=1, paths=1; sample_path=ketovoila.pl/; UA=Mozilla/5.0 (X11; Lin ...
show more
ketovoila.pl HONEYPOT traffic: count=1, paths=1; sample_path=ketovoila.pl/; UA=Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36; window=2026-01-22T14:59:27Z..2026-01-22T14:59:27Z
show less
Port Scan
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-01-03 16:59:07
(5 months ago)
(mod_security) mod_security (id:210350) triggered by 45.66.208.32 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 45.66.208.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 03 11:59:00.873357 2026] [security2:error] [pid 18150:tid 18150] [client 45.66.208.32:20427] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||rockymtnfire.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "rockymtnfire.com"] [uri "/"] [unique_id "aVlK1BjEP0rzUl2jcDzHxQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-10 06:12:44
(6 months ago)
Aggressive web scan
Web App Attack
๐ฉ๐ช
london2038.com
2025-09-25 06:47:52
(8 months ago)
Detected by WP fail2ban
2025-09-25T08:47:51.594253+02:00 wordpress: Authentication attempt from 45.6 ...
show more
Detected by WP fail2ban
2025-09-25T08:47:51.594253+02:00 wordpress: Authentication attempt from 45.66.208.32
show less
Brute-Force
Web App Attack
Anonymous
2024-08-05 12:10:30
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TTWebhosting
2022-08-12 02:11:15
(3 years ago)
(mod_security) mod_security (id:225170) triggered by 45.66.208.32 (RU/Russia/-/-/-): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 45.66.208.32 (RU/Russia/-/-/-): 1 in the last 3600 secs
show less
Port Scan
Hacking
Brute-Force
๐ฌ๐ง
headwall
2021-07-27 10:56:33
(4 years ago)
Attempted WordPress user enumeration by client 45.66.208.32
Web App Attack