๐น๐ท
neron
2026-07-24 13:30:32
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐ง๐ท
ICS Labs
2026-07-16 01:35:16
(1 month ago)
ICS Labs identified 45.80.158.249 as a malicious indicator from threat intelligence.
Hacking
Anonymous
2026-06-29 13:46:21
(1 month ago)
Failed Wordpress Logins
Web App Attack
๐ซ๐ฎ
nNordic
2026-06-09 09:12:18
(2 months ago)
Connection attempt blocked by IDS/IPS from 45.80.158.249/32
Hacking
๐ฎ๐ณ
evicky2002
2026-05-28 07:33:20
(2 months ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฆ๐บ
oncord
2026-05-28 06:31:49
(2 months ago)
Form spam
Web Spam
๐ซ๐ท
EDSL
2026-05-28 06:25:31
(2 months ago)
[SRV-VPN1] Blocked by SysWarden Firewall (Web Attack)
Port Scan
Hacking
Web App Attack
๐ฉ๐ช
LRob
2026-05-27 10:45:12
(2 months ago)
Plesk panel login attempt with forbidden username (root/admin), blocked by Fail2Ban in custom-plesk- ...
show more
Plesk panel login attempt with forbidden username (root/admin), blocked by Fail2Ban in custom-plesk-login jail
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 06:09:48
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 45.80.158.249 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.80.158.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 02:09:32.226139 2026] [security2:error] [pid 15434:tid 15434] [client 45.80.158.249:39226] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fresh-cut.us|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fresh-cut.us"] [uri "/dump.sql"] [unique_id "ahaKnHN2diMkYWHFh3ZOrwAAAAI"], referer: fresh-cut.us/dump.sql
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-27 05:00:49
(2 months ago)
2026-05-26 21:00:44,297 fail2ban.actions [3625835]: NOTICE [tor] Ban 45.80.158.249
2026-05-2 ...
show more
2026-05-26 21:00:44,297 fail2ban.actions [3625835]: NOTICE [tor] Ban 45.80.158.249
2026-05-27 00:00:34,252 fail2ban.actions [3625835]: NOTICE [tor] Ban 45.80.158.249
2026-05-27 03:00:21,157 fail2ban.actions [3625835]: NOTICE [tor] Ban 45.80.158.249
2026-05-27 05:01:29,433 fail2ban.actions [3625835]: NOTICE [tor] Ban 45.80.158.249
2026-05-27 08:00:48,882 fail2ban.actions [3625835]: NOTICE [tor] Ban 45.80.158.249
show less
Brute-Force
๐ฉ๐ช
ger-stg-sifi1
2026-05-27 03:17:58
(2 months ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 23:36:56
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 45.80.158.249 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.80.158.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 19:36:39.069929 2026] [security2:error] [pid 23750:tid 23750] [client 45.80.158.249:51740] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||maycockfamily.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "maycockfamily.com"] [uri "/dump.sql"] [unique_id "ahYuh1z7gUVBjePT6vg_8QAAAAU"], referer: maycockfamily.com/dump.sql
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 21:45:26
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 45.80.158.249 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.80.158.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 17:45:10.502460 2026] [security2:error] [pid 22458:tid 22458] [client 45.80.158.249:18296] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||budfromstlouis.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "budfromstlouis.com"] [uri "/dump.sql"] [unique_id "ahYUZlL4wYG3qICv84zE7AAAAEo"], referer: budfromstlouis.com/dump.sql
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 21:22:14
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 45.80.158.249 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.80.158.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 17:21:58.238905 2026] [security2:error] [pid 25969:tid 25969] [client 45.80.158.249:28496] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||andamiospime.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "andamiospime.com"] [uri "/dump.sql"] [unique_id "ahYO9oT6k8SnLUJzl1Y3kQAAAA8"], referer: andamiospime.com/dump.sql
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 20:37:10
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 45.80.158.249 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.80.158.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 16:36:54.820400 2026] [security2:error] [pid 20601:tid 20601] [client 45.80.158.249:54122] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||odessatexas.us|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "odessatexas.us"] [uri "/dump.sql"] [unique_id "ahYEZr3XynF0Y2tgGGALzgAAAAU"], referer: odessatexas.us/dump.sql
show less
Brute-Force
Bad Web Bot
Web App Attack