🇫🇷
SpaceHost-Server
2026-09-10 22:22:45
(1 day ago)
Brute-Force
Web App Attack
🇫🇷
SpaceHost-Server
2026-09-09 22:20:27
(2 days ago)
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-09 10:52:34
(3 days ago)
45.132.227.55 - - [09/Sep/2026:08:34:33 +0200] "POST /wp-login.php HTTP/1.1" 200 23954 "-" "Mozilla/ ...
show more
45.132.227.55 - - [09/Sep/2026:08:34:33 +0200] "POST /wp-login.php HTTP/1.1" 200 23954 "-" "Mozilla/5.0"
45.132.227.55 - - [09/Sep/2026:09:46:44 +0200] "POST /wp-login.php HTTP/1.1" 200 23952 "-" "Mozilla/5.0"
45.132.227.55 - - [09/Sep/2026:12:52:31 +0200] "POST /wp-login.php HTTP/1.1" 200 23952 "-" "Mozilla/5.0"
45.132.227.55 - - [09/Sep/2026:08:44:52 +0200] "POST /wp-login.php HTTP/1.1" 200 20628 "-" "Mozilla/5.0"
45.132.227.55 - - [09/Sep/2026:11:20:52 +0200] "POST /wp-login.php HTTP/1.1" 200 20629 "-" "Mozilla/5.0"
45.132.227.55 - - [09/Sep/2026:05:42:32 +0200] "GET /wp-login.php HTTP/1.1" 301 575 "-" "Mozilla/5.0"
45.132.227.55 - - [09/Sep/2026:05:42:33 +0200] "GET /wp-login.php HTTP/1.1" 404 4490 "-" "Mozilla/5.0"
45.132.227.55 - - [09/Sep/2026:05:42:32 +0200] "GET /wp-login.php HTTP/1.1" 301 575 "-" "Mozilla/5.0"
45.132.227.55 - - [09/Sep/2026:05:42:32 +0200] "GET /wp-login.php HTTP/1.1" 301 593 "-" "Mozilla/5.0"
45.132.227.55 - - [09/Sep/2026:05:42:33 +0200] "GET /wp-login.php
show less
Web App Attack
Brute-Force
🇩🇪
FeG Deutschland
2026-08-25 06:10:56
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇺🇸
Starburst SysOp Team
2026-08-24 10:14:20
(2 weeks ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-stl2-14)
Hacking
Bad Web Bot
🇺🇸
TPI-Abuse
2026-08-23 20:27:47
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.55 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 16:27:41.021467 2026] [security2:error] [pid 31252:tid 31252] [client 45.132.227.55:43813] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.234"] [uri "/.env"] [unique_id "aotXvV9YI5epLm5dEq9E9wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-23 18:47:51
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.55 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 14:47:34.202854 2026] [security2:error] [pid 1177:tid 1177] [client 45.132.227.55:50689] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.92"] [uri "/base/.env"] [unique_id "aotARgCldwQOurSC0JxotQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-23 06:42:47
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.55 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 02:42:40.506496 2026] [security2:error] [pid 9217:tid 9217] [client 45.132.227.55:48397] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.18"] [uri "/.env"] [unique_id "aoqWYGipEUcQ29IXPn9oHQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇸
Smel
2026-08-23 04:37:29
(2 weeks ago)
HTTP/80/443/8080 Unauthorized Probe, Hack -
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-21 12:23:10
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.55 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 08:23:02.843355 2026] [security2:error] [pid 26983:tid 27000] [client 45.132.227.55:28997] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.125"] [uri "/new/.env"] [unique_id "aohDJljekeGnOCJ9ZrMjKAAAAI4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-21 10:46:03
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.55 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 06:45:51.502788 2026] [security2:error] [pid 2957:tid 2957] [client 45.132.227.55:52143] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.186"] [uri "/backend/.env"] [unique_id "aogsXxWsztGP_wg0rvDoagAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-21 09:17:24
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.55 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 05:17:08.521261 2026] [security2:error] [pid 20793:tid 20793] [client 45.132.227.55:47895] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.166"] [uri "/www/.env"] [unique_id "aogXlDR-MJmhMP5rWC5Z8AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-21 08:54:03
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.55 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 04:53:36.840192 2026] [security2:error] [pid 20618:tid 20618] [client 45.132.227.55:35995] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.87"] [uri "/app/.env"] [unique_id "aogSEOp7cpXrmHasj4c7FgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-21 03:59:15
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.55 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 23:58:53.445682 2026] [security2:error] [pid 19574:tid 19574] [client 45.132.227.55:63879] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.144"] [uri "/new/.env"] [unique_id "aofM_SEFjd5Y7-z1aVyefgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-08-21 01:37:53
(3 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: astropot.online | URI: /wp-login.php | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/129.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack