Anonymous
2026-09-26 05:50:44
(42 minutes ago)
45.67.96.71 - - [26/Sep/2026:07:49:13 +0200] "GET /bless.php HTTP/1.1" 404 495 "-" "Mozilla/5.0 (Win ...
show more
45.67.96.71 - - [26/Sep/2026:07:49:13 +0200] "GET /bless.php HTTP/1.1" 404 495 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36"
45.67.96.71 - - [26/Sep/2026:07:49:13 +0200] "GET /O-Simple.php HTTP/1.1" 404 495 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36"
45.67.96.71 - - [26/Sep/2026:07:49:14 +0200] "GET /lock360.php HTTP/1.1" 404 495 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0"
45.67.96.71 - - [26/Sep/2026:07:49:14 +0200] "GET /zwso.php HTTP/1.1" 404 495 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95"
45.67.96.71 - - [26/Sep/2026:07:49:15 +0200] "GET /chosen.php HTTP/1.1" 404 495 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0"
45.67.96.71 - - [26/Sep/2026:07:49:15 +0200] "GET /
...
show less
DDoS Attack
๐ซ๐ท
dynamix
2026-09-23 04:03:30
(3 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-22 16:08:29
(3 days ago)
[22/Sep/2026:19:08:28 +0300] -- 45.67.96.71 Ban reason: User-Agent Go-http-client
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:32:12
(3 days ago)
(mod_security) mod_security (id:240000) triggered by 45.67.96.71 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240000) triggered by 45.67.96.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:32:06.563780 2026] [security2:error] [pid 9483:tid 9483] [client 45.67.96.71:31203] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||airdriedrivingschool.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "airdriedrivingschool.com"] [uri "/images/stories/themes.php"] [unique_id "arKRZqcLT3VUkakgfkO1KAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:02:09
(3 days ago)
(mod_security) mod_security (id:240000) triggered by 45.67.96.71 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240000) triggered by 45.67.96.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:01:11.465498 2026] [security2:error] [pid 31210:tid 31210] [client 45.67.96.71:60771] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||www.bigkevsperformance.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "www.bigkevsperformance.com"] [uri "/images/stories/themes.php"] [unique_id "arKKJ82AMkO0Xnd3fdi98wAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-21 05:59:20
(5 days ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
IndigoRidge
2026-09-21 03:30:00
(5 days ago)
45.67.96.71 - - [20/Sep/2026:23:29:21 -0400] "GET /.wp/wso.php HTTP/1.1" 301 162 "-" "Mozilla/5.0 (W ...
show more
45.67.96.71 - - [20/Sep/2026:23:29:21 -0400] "GET /.wp/wso.php HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0"
45.67.96.71 - - [20/Sep/2026:23:29:36 -0400] "GET /tinyfilemanager.php HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36"
45.67.96.71 - - [20/Sep/2026:23:30:00 -0400] "GET /wp-includes/assets/info.php HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 02:05:25
(5 days ago)
(mod_security) mod_security (id:240000) triggered by 45.67.96.71 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240000) triggered by 45.67.96.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:05:17.807965 2026] [security2:error] [pid 30094:tid 30094] [client 45.67.96.71:38573] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||www.drgas.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "www.drgas.com"] [uri "/images/stories/themes.php"] [unique_id "arCQ3RuJn3y-akz6iW_NzgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:25:49
(5 days ago)
(mod_security) mod_security (id:240000) triggered by 45.67.96.71 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240000) triggered by 45.67.96.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:25:43.281531 2026] [security2:error] [pid 31258:tid 31258] [client 45.67.96.71:55671] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||www.falundafatr.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "www.falundafatr.org"] [uri "/images/stories/themes.php"] [unique_id "aq_e14HoePjVAHf-0q-ioQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-20 12:24:13
(5 days ago)
Multiple WAF Violations
Web App Attack
๐ฌ๐ท
setupgr
2026-09-20 08:53:46
(5 days ago)
(mod_security) mod_security (id:1000001) triggered by 45.67.96.71 (AU/Australia/New South Wales/Sydn ...
show more
(mod_security) mod_security (id:1000001) triggered by 45.67.96.71 (AU/Australia/New South Wales/Sydney/-/[AS206092 F.n.s. Holdings Limited]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:53:43.474698 2026] [security2:error] [pid 1025625:tid 1025760] [client 45.67.96.71:43083] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/db.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "103"] [id "1000001"] [msg "Bad file blocked: /wp-content/themes/pridmag/db.php"] [severity "CRITICAL"] [tag "security"] [hostname "asteriassantorini.com"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "aq-fF9OHfR6d3QshG8c6MAAAAVI"]
show less
Port Scan
๐ซ๐ท
dynamix
2026-09-11 15:52:17
(2 weeks ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 11:54:42
(2 weeks ago)
(mod_security) mod_security (id:240000) triggered by 45.67.96.71 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240000) triggered by 45.67.96.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 07:54:38.017432 2026] [security2:error] [pid 14247:tid 14247] [client 45.67.96.71:51015] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||www.scermak.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "www.scermak.com"] [uri "/images/stories/themes.php"] [unique_id "aqPr_n8NHKlLPllVhsQYlAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 08:01:29
(2 weeks ago)
IP matched detection query many 3xx errors.
Brute-Force
๐ณ๐ฑ
Site.eu
2026-09-10 10:43:16
(2 weeks ago)
Excessive 404/403 errors
Brute-Force