๐ฉ๐ช
CELOS-SOC
2026-07-15 16:30:07
(2 weeks ago)
Multiple Unauthorized SSLVPN Login Attempts
Hacking
Brute-Force
๐จ๐ฟ
lp
2026-07-15 15:21:18
(2 weeks ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 151.240.109.187
2026-07-15T15:50:45+0 ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 151.240.109.187
2026-07-15T15:50:45+02:00 vpn Access-Reject 'ddavis' station: 151.240.109.187 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐จ๐ฟ
lp
2026-07-15 09:21:16
(2 weeks ago)
Unauthorized VPN login attempts: 7 attempts were recorded from 151.240.109.187
2026-07-15T10:14:02+0 ...
show more
Unauthorized VPN login attempts: 7 attempts were recorded from 151.240.109.187
2026-07-15T10:14:02+02:00 vpn Access-Reject 'swilson' station: 151.240.109.187 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-07-15T10:23:02+02:00 vpn Access-Reject 'sthomas' station: 151.240.109.187 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-07-15T10:32:21+02:00 vpn Access-Reject 'sthomas' station: 151.240.109.187 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-07-15T10:41:42+02:00 vpn Access-Reject 'dmiller' station: 151.240.109.187 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-07-15T10:50:34+02:00 vpn Access-Reject 'dmiller' station: 151.240.109.187 auth-type: - realm: vse.c
show less
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-07-04 07:57:17
(3 weeks ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 14:22:46
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 151.240.109.187 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 151.240.109.187 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 10:22:39.780497 2026] [security2:error] [pid 10171:tid 10171] [client 151.240.109.187:60589] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 151.240.109.187 (+1 hits since last alert)|arsenalfordemocracy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "arsenalfordemocracy.com"] [uri "/xmlrpc.php"] [unique_id "airEr7iXtq2Dw1WBFcImagAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-11 12:10:54
(1 month ago)
Attac
Brute-Force
๐ฌ๐ง
consul.to
2026-05-29 09:21:03
(2 months ago)
Web attack/malicious scanning detected
Web App Attack
๐ฎ๐ฑ
Dolphi
2026-05-29 06:20:03
(2 months ago)
POST //xmlrpc.php
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2026-05-27 20:33:20
(2 months ago)
1.761 requests with url.path //xmlrpc.php
Brute-Force
Bad Web Bot
๐ฌ๐ง
consul.to
2026-05-27 05:51:25
(2 months ago)
Web attack/malicious scanning detected
Web App Attack
๐ฌ๐ง
consul.to
2026-05-11 00:54:14
(2 months ago)
Web attack/malicious scanning detected
Web App Attack
๐ฌ๐ง
consul.to
2026-05-04 01:36:53
(2 months ago)
Web attack/malicious scanning detected
Web App Attack
๐ฌ๐ง
consul.to
2026-05-01 15:02:39
(2 months ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-28 13:46:51
(3 months ago)
(mod_security) mod_security (id:210831) triggered by 151.240.109.187 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 151.240.109.187 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 09:46:47.521514 2026] [security2:error] [pid 4086:tid 4086] [client 151.240.109.187:57945] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.friendlyfarm4fun.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.friendlyfarm4fun.com"] [uri "/"] [unique_id "afC6R_sLhaJnqMiFWpdkRwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-28 13:28:17
(3 months ago)
(mod_security) mod_security (id:210831) triggered by 151.240.109.187 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 151.240.109.187 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 09:28:13.393372 2026] [security2:error] [pid 15660:tid 15660] [client 151.240.109.187:33463] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||stbms.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "stbms.com"] [uri "/"] [unique_id "afC17Xu44lDeKn_8AFr8bwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack