๐บ๐ธ
TPI-Abuse
2026-09-21 10:24:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 45.71.17.27 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.71.17.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 06:24:27.687475 2026] [security2:error] [pid 3157:tid 3157] [client 45.71.17.27:62611] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "christeningnapkins.com"] [uri "/.git/HEAD"] [unique_id "arEF21QXd6Q9cZI9Egr2QgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 10:46:53
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 45.71.17.27 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.71.17.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 06:46:45.618590 2026] [security2:error] [pid 2154:tid 2154] [client 45.71.17.27:35163] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "beckersystems.com"] [uri "/.git/HEAD"] [unique_id "aqpzlWPW1tn-EFNOw0TiBgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
JimArchon72
2026-09-14 01:30:52
(1 week ago)
2026/09/14 01:29:25 "GET /phpMyAdmin/ HTTP/1.1"
Web App Attack
๐ฉ๐ช
LRob
2026-09-13 00:21:17
(1 week ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: /ile-de-france | 2026-09-13 00:21 UTC
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-02 12:57:44
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 45.71.17.27 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 45.71.17.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 08:57:35.319425 2026] [security2:error] [pid 29777:tid 29777] [client 45.71.17.27:58323] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||capitalswisscorp.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "apgdP3mu9VKKQkYveRjJuQAAAB8"], referer: http://CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 01:08:19
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 45.71.17.27 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 45.71.17.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 21:08:11.447321 2026] [security2:error] [pid 21985:tid 21985] [client 45.71.17.27:37369] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||holgerfeld.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "ao-N-w3e4O3O32WNQRNuiwAAAAM"], referer: http://holgerfeld.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-04 09:42:25
(1 month ago)
FortiWeb WAF: 28 attacks detected. Threat Score: 11375405. Types: Client Management(14), Signature D ...
show more
FortiWeb WAF: 28 attacks detected. Threat Score: 11375405. Types: Client Management(14), Signature Detection(14). Origin: United States.
show less
Web App Attack
Anonymous
2026-07-24 13:19:14
(1 month ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
Anonymous
2026-07-22 05:33:13
(2 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐ฎ๐น
alessio loto
2026-05-12 00:47:00
(4 months ago)
WAF Detection: URI_Injection_Detected (Abusive IP). AI Confirmed Attack Payload.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-07 04:02:44
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 45.71.17.27 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 45.71.17.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 00:02:38.901456 2026] [security2:error] [pid 5579:tid 5579] [client 45.71.17.27:61197] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||americanexportimport.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "americanexportimport.com"] [uri "/mailto:[email protected] "] [unique_id "afwO3hlfQOMxoe3z9g8CyAAAAAk"], referer: http://americanexportimport.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-03-24 01:50:13
(5 months ago)
Fail2Ban banned 45.71.17.27 for security violations in jail nginx-aggressive. Log: 2026/03/24 01:50: ...
show more
Fail2Ban banned 45.71.17.27 for security violations in jail nginx-aggressive. Log: 2026/03/24 01:50:11 [crit] SSL_read() failed (SSL: error:0A00010B:SSL routines::wrong version number error:0A000139:SSL routines::record layer failure) while keepalive, client: 45.71.17.27, server: [REDACTED]
2026/03/24 01:50:13 [crit] SSL_read() failed (SSL: error:0A00010B:SSL routines::wrong version number error:0A000139:SSL routines::record layer failure) while keepalive, client: 45.71.17.27, server: [REDACTED]
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-23 01:18:40
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 45.71.17.27 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 45.71.17.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 22 21:18:33.015740 2026] [security2:error] [pid 26004:tid 26004] [client 45.71.17.27:27427] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||CapitalSwissCorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "acCU6TduuFgG7i164X4IYQAAAAc"], referer: http://CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack