Anonymous
2026-08-20 19:37:47
(6 days ago)
VPN portal credential brute-force / password spray against a SAML-only GlobalProtect portal (2 attem ...
show more
VPN portal credential brute-force / password spray against a SAML-only GlobalProtect portal (2 attempt(s) observed, 2 username(s) tried). Source blocked on our perimeter.
show less
Brute-Force
๐ฆ๐บ
cybertechsec
2026-08-08 14:05:00
(2 weeks ago)
Googlebot Fraud - Fake Googlebot user agent - The user agent claims to be a Google crawler, but th ...
show more
Googlebot Fraud - Fake Googlebot user agent - The user agent claims to be a Google crawler, but the IP is not verified by official ranges or confirmed DNS.
show less
Bad Web Bot
๐ฆ๐บ
oncord
2026-08-05 08:19:31
(3 weeks ago)
Form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2026-07-23 00:19:47
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 45.80.107.134 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.80.107.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 20:19:42.637171 2026] [security2:error] [pid 1828278:tid 1828278] [client 45.80.107.134:26317] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Barcalounger/Images/Cinna 8028/Thumbs.db"] [unique_id "amFeHi56T8oLBwr63ihaJQAAABQ"], referer: https://vitalitywebb.com/backstore/Barcalounger/Images/Cinna%208028/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Tripwire
2026-06-04 00:26:41
(2 months ago)
Probing for Wordpress - /wp-login.php
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 07:37:04
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 45.80.107.134 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.80.107.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 03:36:56.374236 2026] [security2:error] [pid 21626:tid 21626] [client 45.80.107.134:25545] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Steelcase/pics/Amia/Thumbs.db"] [unique_id "ah_ZmKiTtXvB1_RzTPyi9wAAAAQ"], referer: https://vitalitywebb.com/backstore/Steelcase/pics/Amia/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-06-01 14:45:54
(2 months ago)
Fail2Ban banned 45.80.107.134 for security violations in jail wp-armour. Log: 2026/06/01 14:45:53 [e ...
show more
Fail2Ban banned 45.80.107.134 for security violations in jail wp-armour. Log: 2026/06/01 14:45:53 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 45.80.107.134 | Target: wpregistration" , client: 45.80.107.134, server: [REDACTED], request: "POST /wp-login.php?action=register HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://espsformacion.com/wp-login.php?action=register"
...
show less
Web Spam
๐ฌ๐ง
Oakley
2026-05-11 09:53:58
(3 months ago)
(mod_security) mod_security (id:900209) triggered by 45.80.107.134 (IL/Israel/-): 5 in the last 900 ...
show more
(mod_security) mod_security (id:900209) triggered by 45.80.107.134 (IL/Israel/-): 5 in the last 900 secs
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-16 20:31:49
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 45.80.107.134 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.80.107.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 16 16:31:43.744740 2026] [security2:error] [pid 2190782:tid 2190782] [client 45.80.107.134:54235] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gamepart.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gamepart.com"] [uri "/home/tancedi1/gamepart.com"] [unique_id "aeFHLze0046C6BrLUihuTQAAACM"], referer: http://answers.google.com/answers/threadview/id/552967.html
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2025-12-30 14:10:45
(7 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 45.80.107.134 (IL/Israel/-): 1 in t ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 45.80.107.134 (IL/Israel/-): 1 in the last 3600 secs
show less
Web App Attack
Anonymous
2025-10-15 20:04:43
(10 months ago)
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-09-07 05:04:43
(11 months ago)
(mod_security) mod_security (id:210350) triggered by 45.80.107.134 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 45.80.107.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 07 01:04:37.859265 2025] [security2:error] [pid 19548:tid 19548] [client 45.80.107.134:25999] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||surrenderhouse.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "surrenderhouse.com"] [uri "/contact.html"] [unique_id "aL0SZSyf3QO3merF17TLkgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-06 20:18:45
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 45.80.107.134 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.80.107.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 16:18:41.936360 2025] [security2:error] [pid 8475:tid 8475] [client 45.80.107.134:13655] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Barcalounger/Images/Berkeley 4059/Thumbs.db"] [unique_id "aLyXIQLCgUVsMVKXzV7CBwAAABA"], referer: https://vitalitywebb.com/backstore/Barcalounger/Images/Berkeley%204059/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2025-05-10 04:58:27
(1 year ago)
Bad Web Bot
Anonymous
2025-01-22 04:47:55
(1 year ago)
wordpress-trap
Web App Attack