๐ณ๐ฟ
Antinson
2025-12-16 08:01:07
(8 months ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
๐บ๐ฆ
URAN Publishing Service
2025-12-16 04:58:38
(8 months ago)
45.67.99.34 - - [16/Dec/2025:06:58:36 +0200] "GET //wp-content/uploads/wpr-addons/forms/b1ack.php HT ...
show more
45.67.99.34 - - [16/Dec/2025:06:58:36 +0200] "GET //wp-content/uploads/wpr-addons/forms/b1ack.php HTTP/1.1" 404 277 "-" "Go-http-client/1.1"
45.67.99.34 - - [16/Dec/2025:06:58:38 +0200] "GET //wp-content/plugins/linkpreview/index.php HTTP/1.1" 404 277 "-" "Go-http-client/1.1"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-16 04:37:49
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 45.67.99.34 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 45.67.99.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 15 23:37:42.612470 2025] [security2:error] [pid 10054:tid 10054] [client 45.67.99.34:33379] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mpaexchangeinc.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mpaexchangeinc.com"] [uri "/old/dump.sql"] [unique_id "aUDiFjcvcMmJ-WD7tN4pEwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-16 02:41:14
(8 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐จ๐ญ
backslash
2025-12-16 01:05:07
(8 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
kosada.com
2025-12-16 00:30:43
(8 months ago)
Web vulnerability probing: //.well-known/acme-challenge/index.php
Web App Attack
๐ฎ๐ฉ
Burayot
2025-12-15 23:32:14
(8 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 45.67.99.34 (-): 2 in the last 3600 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 45.67.99.34 (-): 2 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
[email protected]
2025-12-12 02:02:01
(8 months ago)
Fail2Ban jail apache-json-scanners detected activity on 2025-12-12T02:02:01Z
Brute-Force
๐บ๐ธ
[email protected]
2025-12-12 01:02:32
(8 months ago)
Fail2Ban jail apache-json-scanners detected activity on 2025-12-12T01:02:32Z
Brute-Force
๐บ๐ธ
[email protected]
2025-12-12 00:03:13
(8 months ago)
Fail2Ban jail apache-json-scanners detected activity on 2025-12-12T00:03:12Z
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-12-11 23:50:32
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 45.67.99.34 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.67.99.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 11 18:50:24.969247 2025] [security2:error] [pid 20522:tid 20522] [client 45.67.99.34:58969] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gcigmbh.com"] [uri "/back/sftp-config.json"] [unique_id "aTtYwCNCNveGdwSaEmGRBQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Penny Packer
2025-12-11 23:27:57
(8 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-09 05:09:31
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 45.67.99.34 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 45.67.99.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 09 00:09:26.519000 2025] [security2:error] [pid 27587:tid 27587] [client 45.67.99.34:38255] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||matteozacchino.dev|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "matteozacchino.dev"] [uri "/bak/sql.sql"] [unique_id "aTevBmP5o70bzZEV9OqfiQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-03 20:16:57
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 45.67.99.34 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 45.67.99.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 03 15:16:50.998757 2025] [security2:error] [pid 29415:tid 29415] [client 45.67.99.34:27039] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||loriatrading.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "loriatrading.com"] [uri "/backup/sql.sql"] [unique_id "aTCaslF8xVUNoK0wkNtFBgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2025-11-25 05:05:16
(9 months ago)
Too many Status 40X (11)
Brute-Force
Web App Attack