๐ฉ๐ช
maxpower
2026-06-24 07:42:45
(1 month ago)
(backdoor_scan) REGOLA 7 - Backdoor Scan Attempt 45.77.178.246 (JP/Japan/45.77.178.246.vultrusercont ...
show more
(backdoor_scan) REGOLA 7 - Backdoor Scan Attempt 45.77.178.246 (JP/Japan/45.77.178.246.vultrusercontent.com): 2 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 45.77.178.246 - - [24/Jun/2026:09:42:24 +0200] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 301 309 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" "45.77.178.246" host=digiampaolosrl.it
45.77.178.246 - - [24/Jun/2026:09:42:38 +0200] "GET /wp-content/themes/seotheme/db.php?u HTTP/2.0" 500 711 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" "45.77.178.246" host=digiampaolosrl.it
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-24 07:40:42
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 45.77.178.246 (45.77.178.246.vultrusercontent.c ...
show more
(mod_security) mod_security (id:210350) triggered by 45.77.178.246 (45.77.178.246.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 03:40:36.355332 2026] [security2:error] [pid 15049:tid 15049] [client 45.77.178.246:57575] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.difusionens.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.difusionens.org"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ajuJ9C7yuANvCBPpRtTgjQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 07:07:30
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 45.77.178.246 (45.77.178.246.vultrusercontent.c ...
show more
(mod_security) mod_security (id:210350) triggered by 45.77.178.246 (45.77.178.246.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 03:07:23.928988 2026] [security2:error] [pid 5547:tid 5547] [client 45.77.178.246:57712] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.reyadecostarica.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.reyadecostarica.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ajuCK1Qn-E4S48afUvkWEQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 06:16:39
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 45.77.178.246 (45.77.178.246.vultrusercontent.c ...
show more
(mod_security) mod_security (id:210350) triggered by 45.77.178.246 (45.77.178.246.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 02:16:35.350795 2026] [security2:error] [pid 16618:tid 16618] [client 45.77.178.246:52314] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||lusineweb.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "lusineweb.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ajt2Qw1V0dW1XMKx88ylvAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-06-24 06:06:02
(1 month ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02,wa01]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-06-24 06:00:13
(1 month ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-24 05:20:38
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 45.77.178.246 (45.77.178.246.vultrusercontent.c ...
show more
(mod_security) mod_security (id:210350) triggered by 45.77.178.246 (45.77.178.246.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 01:20:31.923094 2026] [security2:error] [pid 1014:tid 1014] [client 45.77.178.246:63702] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.lspfest.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.lspfest.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ajtpH1rj4lKp8kJWslX5AgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-24 05:15:46
(1 month ago)
<jail> banned by fail2ban
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 04:51:29
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 45.77.178.246 (45.77.178.246.vultrusercontent.c ...
show more
(mod_security) mod_security (id:210350) triggered by 45.77.178.246 (45.77.178.246.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 00:51:22.639545 2026] [security2:error] [pid 24024:tid 24024] [client 45.77.178.246:63786] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||dennisangellismusic.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "dennisangellismusic.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ajtiSgSywn-o2FOVEdhvwwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
todix
2026-06-24 04:46:28
(1 month ago)
Web App Attack Exploid from 45.77.178.246
Web App Attack
๐ง๐ช
taivas.nl
2026-06-24 04:32:24
(1 month ago)
Many_bad_calls
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 04:28:32
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 45.77.178.246 (45.77.178.246.vultrusercontent.c ...
show more
(mod_security) mod_security (id:210350) triggered by 45.77.178.246 (45.77.178.246.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 00:28:24.946712 2026] [security2:error] [pid 32546:tid 32546] [client 45.77.178.246:51401] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.losbarbarosdelnorte.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.losbarbarosdelnorte.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ajtc6G9i_AP1uq7wez3asQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-06-24 04:18:02
(1 month ago)
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show more
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-24 04:07:34
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 45.77.178.246 (45.77.178.246.vultrusercontent.c ...
show more
(mod_security) mod_security (id:210350) triggered by 45.77.178.246 (45.77.178.246.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 00:07:27.866860 2026] [security2:error] [pid 15168:tid 15168] [client 45.77.178.246:49463] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.longmeadowcarcare.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.longmeadowcarcare.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ajtX_-Zoz23_M25APZGRnQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-06-24 04:07:01
(1 month ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack