Anonymous
2026-05-01 06:15:02
(1 month ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-29 23:19:54
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 45.66.209.78 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.66.209.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 29 19:19:50.236442 2026] [security2:error] [pid 23315:tid 23443] [client 45.66.209.78:57943] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.bodytherapies.us|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.bodytherapies.us"] [uri "/s3cmd.ini"] [unique_id "afKSFocTjQ8oaDcZ1fmRlAAAAhM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-29 10:41:22
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 45.66.209.78 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.66.209.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 29 06:41:15.829453 2026] [security2:error] [pid 19783:tid 19783] [client 45.66.209.78:13463] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||solporpoise.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "solporpoise.com"] [uri "/s3cmd.ini"] [unique_id "afHgS5awZdPany0hvIz4jgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-26 03:32:45
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 45.66.209.78 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.66.209.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 25 23:32:40.751503 2026] [security2:error] [pid 17341:tid 17341] [client 45.66.209.78:56387] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||workzoap.com.worldchat.global|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "workzoap.com.worldchat.global"] [uri "/s3cmd.ini"] [unique_id "ae2HWO-k0yc_ZvTANrIXKwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-19 23:34:48
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 45.66.209.78 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 45.66.209.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 19 19:34:42.657860 2026] [security2:error] [pid 9093:tid 9093] [client 45.66.209.78:64939] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||whitenapkins.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "whitenapkins.com"] [uri "/"] [unique_id "aeVmkuKFzqES-OwMnq_TawAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
SSH-Admin
2026-02-07 17:12:28
(4 months ago)
Probing for Exploits
Exploited Host
Web App Attack
๐ฉ๐ช
stinpriza
2025-12-18 08:31:13
(5 months ago)
Web App Attack
Web App Attack
๐ณ๐ฑ
i-turnradio.nl
2025-12-17 22:12:02
(5 months ago)
2025-12-17 @ 23:12:02 (CET) ~ Blocked based on risk assessment and prior abuse reports
Web App Attack
๐ซ๐ท
solution.it
2025-12-17 12:59:31
(5 months ago)
[Wed Dec 17 13:59:30.480225 2025] [php7:error] [pid 790630:tid 790630] [client 45.66.209.78:30479] s ...
show more
[Wed Dec 17 13:59:30.480225 2025] [php7:error] [pid 790630:tid 790630] [client 45.66.209.78:30479] script '/var/www/html/wp-login.php' not found or unable to stat
show less
Web App Attack
Anonymous
2025-12-16 02:23:25
(5 months ago)
2025-12-16T04:23:24.817326+02:00 zanati wp(www.sahpa.co.za)[977434]: Blocked authentication attempt ...
show more
2025-12-16T04:23:24.817326+02:00 zanati wp(www.sahpa.co.za)[977434]: Blocked authentication attempt for admin from 45.66.209.78
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-06 05:06:08
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 45.66.209.78 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 45.66.209.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 06 00:06:00.870966 2025] [security2:error] [pid 23547:tid 23547] [client 45.66.209.78:10205] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||hippiehaven.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "hippiehaven.com"] [uri "/"] [unique_id "aTO5uBR7MY3fxxedDspdWgAAABc"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
SSH-Admin
2025-12-01 02:33:03
(6 months ago)
Probing for Exploits
Exploited Host
Web App Attack
Anonymous
2025-10-31 06:28:35
(7 months ago)
2025-10-31T08:28:35.021909+02:00 zanati wp(www.sahpa.co.za)[409161]: Blocked authentication attempt ...
show more
2025-10-31T08:28:35.021909+02:00 zanati wp(www.sahpa.co.za)[409161]: Blocked authentication attempt for admin from 45.66.209.78
...
show less
Web App Attack
Anonymous
2025-10-28 11:29:32
(7 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-10-08 05:50:26
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 45.66.209.78 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 45.66.209.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 08 01:50:19.127706 2025] [security2:error] [pid 5563:tid 5563] [client 45.66.209.78:48617] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||tipdavid.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "tipdavid.com"] [uri "/"] [unique_id "aOX7m1-1KIaaeXyQlIC1lwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack