๐จ๐ญ
4server
2026-04-23 05:17:33
(1 month ago)
[ThuApr2307:17:26.1331262026][security2:error][pid2472241:tid2472286][client45.66.209.62:0]ModSecuri ...
show more
[ThuApr2307:17:26.1331262026][security2:error][pid2472241:tid2472286][client45.66.209.62:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"duoacaja.com\"][uri\"/\"][unique_id\"aemrZj6jyODYzTRss0gWcgAAAMY\"]\,referer:http://duoacaja.com/
show less
Hacking
Web App Attack
๐บ๐ธ
mnsf
2026-03-19 16:11:43
(2 months ago)
Scanning/Probing (14)
Brute-Force
Web App Attack
๐บ๐ธ
mind5t0rm
2026-02-07 12:20:01
(4 months ago)
(WPLOGIN) WP Login Attack 45.66.209.62 (RU/Russia/-): 3 in the last 3600 secs; Ports: *; Direction: ...
show more
(WPLOGIN) WP Login Attack 45.66.209.62 (RU/Russia/-): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: 45.66.209.62 - - [07/Feb/2026:19:19:51 +0700] "GET /wp-login.php?wp_lang=en_US HTTP/2.0" 200 2453 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.6367.207 Safari/537.36"
45.66.209.62 - - [07/Feb/2026:19:19:52 +0700] "POST /wp-login.php?wp_lang=en_US HTTP/2.0" 302 0 "https://zerowaterthailand.com/wp-login.php?wp_lang=en_US" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.6367.207 Safari/537.36"
45.66.209.62 - - [07/Feb/2026:19:20:00 +0700] "GET /wp-login.php?redirect_to=https%3A%2F%2Fwww.zerowaterthailand.com%2Fwp-admin%2Fplugins.php&reauth=1 HTTP/2.0" 200 2452 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.6367.207 Safari/537.36"
show less
Port Scan
๐จ๐ญ
backslash
2025-06-20 03:05:05
(11 months ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
๐ฆ๐บ
MAGIC
2025-06-19 10:07:27
(11 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2025-06-12 11:30:09
(11 months ago)
WAF: Old style account creation and modification in Joomla! 2- wsit
Email Spam
Brute-Force
๐บ๐ธ
webgobe
2025-06-11 09:15:15
(11 months ago)
jow-Joomla User : try to access forms...
Hacking
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2025-05-22 18:00:08
(1 year ago)
WAF: Block Joomla registration spam 2- wsit
Email Spam
Brute-Force
๐ช๐ธ
10dencehispahard SL
2025-05-14 05:24:28
(1 year ago)
WP probing for vulnerabilities
Hacking
Exploited Host
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2025-05-13 17:00:09
(1 year ago)
WAF: Block Joomla registration spam 2- wsit
Email Spam
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-11-10 17:10:34
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 45.66.209.62 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.66.209.62 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 10 12:10:29.147734 2024] [security2:error] [pid 2351663:tid 2351663] [client 45.66.209.62:40717] [client 45.66.209.62] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Golden-Technologies/pics/Golden Technologies 2009 Marketing CD/Lift Chairs/Comforter Series/Thumbs.db"] [unique_id "ZzDpBTq5C9RrGui1zRscXAAAAAA"], referer: https://vitalitywebb.com/backstore/Golden-Technologies/pics/Golden%20Technologies%202009%20Marketing%20CD/Lift%20Chairs/Comforter%20Series/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
sms.ru
2024-09-24 02:40:04
(1 year ago)
SMS pumping attack from foreign country
DDoS Attack
๐บ๐ธ
TPI-Abuse
2024-06-24 23:27:01
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.66.209.62 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 45.66.209.62 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 24 19:26:55.971964 2024] [security2:error] [pid 12499:tid 47603231241984] [client 45.66.209.62:28807] [client 45.66.209.62] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||draginich.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "draginich.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZnoAv6wEKcP7GMMK2oxAxAAAAIM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-05-29 23:31:00
(2 years ago)
"Scanning for multiple vulnerable file extensions and wp-login.php xmlrpc.php"
Web App Attack
๐จ๐ญ
backslash
2024-05-15 16:30:21
(2 years ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot