🇺🇸
TPI-Abuse
2026-08-26 01:25:46
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 21:25:18.613369 2026] [security2:error] [pid 24650:tid 24670] [client 45.132.227.181:39471] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.134"] [uri "/backend/.env"] [unique_id "ao5Afu2w6SfLT2RLwnmZYgAAAYc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-25 21:22:18
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 17:22:03.491019 2026] [security2:error] [pid 20540:tid 20540] [client 45.132.227.181:36597] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.244"] [uri "/base/.env"] [unique_id "ao4He7kfrzibYSw-5FSMNgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇳
Starburst SysOp Team
2026-08-24 06:59:06
(2 weeks ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-bom2-2)
Hacking
Bad Web Bot
🇫🇷
Teufel100
2026-08-16 20:37:11
(3 weeks ago)
ModSecurity rejected a query
Brute-Force
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-16 13:42:22
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 09:42:16.528778 2026] [security2:error] [pid 670865:tid 670865] [client 45.132.227.181:55969] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.183"] [uri "/.env"] [unique_id "aoG-OJq_mRgkRMD8DTlJAgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-16 11:34:40
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 07:34:07.770606 2026] [security2:error] [pid 4116:tid 4116] [client 45.132.227.181:35335] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.41"] [uri "/old/.env"] [unique_id "aoGgL0qZR-CQ4Ay8Lma2XAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-16 10:11:24
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 06:10:52.870439 2026] [security2:error] [pid 1122:tid 1122] [client 45.132.227.181:58241] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.31"] [uri "/vendor/laravel/.env"] [unique_id "aoGMrC3IpUx-L-fZSCna_gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-15 20:59:42
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 16:59:07.284706 2026] [security2:error] [pid 14390:tid 14390] [client 45.132.227.181:41757] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.46"] [uri "/cgi-bin/.env"] [unique_id "aoDTG9pOr0smtSVAwSX7pgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
filstal.org
2026-08-15 20:04:02
(3 weeks ago)
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels an ...
show more
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels and known vulnerability paths.
show less
Hacking
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-15 14:25:51
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 10:25:35.323700 2026] [security2:error] [pid 12001:tid 12001] [client 45.132.227.181:54907] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.10"] [uri "/database/.env"] [unique_id "aoB234lnojpKXQGN-IgTPAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-08-15 03:51:07
(3 weeks ago)
WordPress probing | req: /wp-login.php | UA: Mozilla/5.0 (Windows NT 10.0; Win64; rv:143.0) Gecko/20 ...
show more
WordPress probing | req: /wp-login.php | UA: Mozilla/5.0 (Windows NT 10.0; Win64; rv:143.0) Gecko/20100101 Firefox/143.0
show less
Brute-Force
Web App Attack
🇺🇸
WizardsToolkit
2026-08-05 11:45:45
(1 month ago)
attempted to access
Web App Attack
🇩🇪
neckaralb-admin.de
2026-08-05 09:47:56
(1 month ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇮🇹
CoreTech srl
2026-07-29 18:43:56
(1 month ago)
cloudlinux2 fail2ban: 2026-07-29 20:40:42,594 fail2ban.filter [1584]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-07-29 20:40:42,594 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 142.111.152.134 - 2026-07-29 20:40:42cloudlinux2 fail2ban: 2026-07-29 20:41:11,066 fail2ban.actions [1584]: NOTICE [plesk-modsecurity] Unban 45.243.42.102cloudlinux2 fail2ban: 2026-07-29 20:41:28,594 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 45.146.55.63 - 2026-07-29 20:41:28cloudlinux2 fail2ban: 2026-07-29 20:41:28,600 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 193.56.116.81 - 2026-07-29 20:41:28cloudlinux2 fail2ban: 2026-07-29 20:41:30,633 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 45.146.55.71 - 2026-07-29 20:41:30cloudlinux2 fail2ban: 2026-07-29 20:41:51,990 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 45.131.193.126 - 2026-07-29 20:41:51cloudlinux2 fail2ban: 2026-07-29 20:42:34,021 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 45.132.227.181 - 2026-07-29 20:42:31cloudlinux2 fail2ban: 2026-
show less
Web App Attack
🇦🇺
oncord
2026-07-28 00:59:52
(1 month ago)
Form spam
Web Spam