๐บ๐ธ
TPI-Abuse
2026-08-15 08:12:40
(1 week ago)
(mod_security) mod_security (id:240000) triggered by 45.133.5.195 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240000) triggered by 45.133.5.195 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 04:12:36.485627 2026] [security2:error] [pid 1917141:tid 1917175] [client 45.133.5.195:49445] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||attorneylouisiana.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "attorneylouisiana.com"] [uri "/images/stories/themes.php"] [unique_id "aoAfdBclW3J2iBtbqC5QYQAAAZc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-08-14 22:40:08
(1 week ago)
Aggressive web search of vulnerable pages: /themes/zMousse/otuz1.php /wp-content/edit-wolf.php /wp-c ...
show more
Aggressive web search of vulnerable pages: /themes/zMousse/otuz1.php /wp-content/edit-wolf.php /wp-content/plugins/ubh/up.php /wp-admin/images/ ...
show less
Web App Attack
๐ซ๐ท
masterguru
2026-08-14 20:43:56
(1 week ago)
Too much 404 requests in 1 minute. Operator GE matched 10 at IP:block_script. (46020-195)
Hacking
๐ฉ๐ช
scolastico
2026-07-22 23:32:48
(4 weeks ago)
[automated] IP failed to authenticate or send unauthenticated INVITE requests
Brute-Force
Fraud VoIP
๐ฉ๐ช
scolastico
2026-07-21 22:13:25
(1 month ago)
[automated] IP failed to authenticate or send unauthenticated INVITE requests
Brute-Force
Fraud VoIP
๐ซ๐ท
dynamix
2026-07-18 07:28:27
(1 month ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
Rayulcifer
2026-06-11 11:30:15
(2 months ago)
[Mon Jun 08 03:00:31.644344 2026] [access_compat:error] [pid 920126:tid 132702896363200] [client 45. ...
show more
[Mon Jun 08 03:00:31.644344 2026] [access_compat:error] [pid 920126:tid 132702896363200] [client 45.133.5.195:56085] AH01797: client denied by server configuration: proxy:http://localhost:4000/
[Mon Jun 08 03:56:36.002050 2026] [access_compat:error] [pid 1068087:tid 132706015426240] [client 45.133.5.195:56169] AH01797: client denied by server configuration: proxy:http://localhost:4000/
[Mon Jun 08 04:04:41.626571 2026] [access_compat:error] [pid 1101970:tid 132701336106688] [client 45.133.5.195:26843] AH01797: client denied by server configuration: proxy:http://localhost:4000/
[Mon Jun 08 04:07:05.635678 2026] [access_compat:error] [pid 1103579:tid 132705614288576] [client 45.133.5.195:46625] AH01797: client denied by server configuration: proxy:http://localhost:4000/
[Mon Jun 08 04:14:43.557598 2026] [access_compat:error] [pid 1109083:tid 132703483590336] [client 45.133.5.195:23983] AH01797: client denied by server configuration: proxy:http://localhost:4000/
...
show less
Brute-Force
SSH
๐ง๐ท
ICS Labs
2026-06-08 13:25:38
(2 months ago)
ICS Labs identified 45.133.5.195 as a malicious indicator from threat intelligence.
DDoS Attack
Hacking
Brute-Force
Exploited Host
๐บ๐ธ
Rayulcifer
2026-06-08 09:14:43
(2 months ago)
[Mon Jun 08 03:00:31.644344 2026] [access_compat:error] [pid 920126:tid 132702896363200] [client 45. ...
show more
[Mon Jun 08 03:00:31.644344 2026] [access_compat:error] [pid 920126:tid 132702896363200] [client 45.133.5.195:56085] AH01797: client denied by server configuration: proxy:http://localhost:4000/
[Mon Jun 08 03:56:36.002050 2026] [access_compat:error] [pid 1068087:tid 132706015426240] [client 45.133.5.195:56169] AH01797: client denied by server configuration: proxy:http://localhost:4000/
[Mon Jun 08 04:04:41.626571 2026] [access_compat:error] [pid 1101970:tid 132701336106688] [client 45.133.5.195:26843] AH01797: client denied by server configuration: proxy:http://localhost:4000/
[Mon Jun 08 04:07:05.635678 2026] [access_compat:error] [pid 1103579:tid 132705614288576] [client 45.133.5.195:46625] AH01797: client denied by server configuration: proxy:http://localhost:4000/
[Mon Jun 08 04:14:43.557598 2026] [access_compat:error] [pid 1109083:tid 132703483590336] [client 45.133.5.195:23983] AH01797: client denied by server configuration: proxy:http://localhost:4000/
...
show less
Brute-Force
SSH
๐ฉ๐ช
4server
2026-05-24 18:53:22
(2 months ago)
[SunMay2420:53:15.2906142026][security2:error][pid2928478:tid2928589][client45.133.5.195:0]ModSecuri ...
show more
[SunMay2420:53:15.2906142026][security2:error][pid2928478:tid2928589][client45.133.5.195:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.agilityrossoblu.ch\"][uri\"/wp-login.php\"][unique_id\"ahNJG9zd6Dw2BloYiYIQcgAAANI\"]\,referer:https://www.agilityrossoblu.ch/wp-admin/
show less
Port Scan
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-05-11 22:55:11
(3 months ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
nyt
2026-05-11 22:45:08
(3 months ago)
404 flood (16/60s), 404 flood (17/60s)
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-05-11 19:15:08
(3 months ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
Anonymous
2026-05-10 23:25:08
(3 months ago)
host-ipset-guard auto-report; server=server.osotir.org; rule=httpd-suspicious-path; count=6/6; durat ...
show more
host-ipset-guard auto-report; server=server.osotir.org; rule=httpd-suspicious-path; count=6/6; duration=168h; scope=server.osotir.org; country=AU; sites=megasvasilios.gr; samples=/wp-content/uploads/cartflows-logs/system_core.php | /wp-content/uploads/edd/system_core.php | /wp-content/plugins/advanced-custom-fields-pro/includes/Updater/about.php
show less
Hacking
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-05-09 19:50:27
(3 months ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack