π©πͺ
SwinT
2026-07-28 11:00:08
(2 days ago)
SMTP brute-force detected by Fail2Ban in plesk-postfix jail
Email Spam
Brute-Force
π¬π§
consul.to
2026-07-04 05:32:18
(3 weeks ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-10 22:34:05
(1 month ago)
(mod_security) mod_security (id:210831) triggered by 151.240.58.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 151.240.58.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 18:33:59.054523 2026] [security2:error] [pid 2215:tid 2220] [client 151.240.58.97:59425] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.tiltedfish.net|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.tiltedfish.net"] [uri "/robots.txt"] [unique_id "ainmVzaU1bOg_ZcALXB-VgAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-10 20:03:03
(1 month ago)
(mod_security) mod_security (id:210831) triggered by 151.240.58.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 151.240.58.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 16:02:57.466490 2026] [security2:error] [pid 8997:tid 8997] [client 151.240.58.97:39745] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.websiterescuecontest.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.websiterescuecontest.com"] [uri "/robots.txt"] [unique_id "ainC8T1N3Ug8d8A9C539VAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-10 15:12:42
(1 month ago)
(mod_security) mod_security (id:210831) triggered by 151.240.58.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 151.240.58.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 11:12:36.312238 2026] [security2:error] [pid 3040:tid 3057] [client 151.240.58.97:36565] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.anglicancouncil.org|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.anglicancouncil.org"] [uri "/"] [unique_id "ail-5P_9_VddCuWMD-vFxgAAAYs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-10 10:36:38
(1 month ago)
(mod_security) mod_security (id:210831) triggered by 151.240.58.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 151.240.58.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 06:36:30.390622 2026] [security2:error] [pid 19246:tid 19304] [client 151.240.58.97:52221] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.lazyllamaranch.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.lazyllamaranch.com"] [uri "/"] [unique_id "aik-LnM4MRgkL2I4XTHgqQAAAYs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-10 00:08:00
(1 month ago)
(mod_security) mod_security (id:210831) triggered by 151.240.58.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 151.240.58.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 20:07:52.750440 2026] [security2:error] [pid 6875:tid 6875] [client 151.240.58.97:52783] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.computerdoc-rx.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.computerdoc-rx.com"] [uri "/"] [unique_id "aiiq2D6BPlLUHZohRKPLvgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-09 16:29:43
(1 month ago)
(mod_security) mod_security (id:210831) triggered by 151.240.58.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 151.240.58.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 12:29:34.767707 2026] [security2:error] [pid 8338:tid 8338] [client 151.240.58.97:65409] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.lovingangelicreiki.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.lovingangelicreiki.com"] [uri "/"] [unique_id "aig_buqlcl6OMioZTPFW0wAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
ger-stg-sifi1
2026-05-27 23:29:43
(2 months ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
π¬π§
consul.to
2026-05-26 18:20:41
(2 months ago)
Web attack/malicious scanning detected
Web App Attack
π§πͺ
cmbplf
2026-05-22 00:26:02
(2 months ago)
6.397 requests with url.path //xmlrpc.php
5.647 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
πΊπΈ
bitblockit
2026-05-21 12:15:27
(2 months ago)
Reconnaissance or port-scan activity observed on a honeypot sensor. Honeypot decoy type: Suricata. D ...
show more
Reconnaissance or port-scan activity observed on a honeypot sensor. Honeypot decoy type: Suricata. Decoy listen port: 22413/tcp. Observed event time: 2026-05-21 12:15:27 UTC. Report from passive honeypot only; no payload or credentials included.
show less
Port Scan
πΊπΈ
bitblockit
2026-05-21 12:14:57
(2 months ago)
Reconnaissance or port-scan activity observed on a honeypot sensor. Honeypot decoy type: Suricata. D ...
show more
Reconnaissance or port-scan activity observed on a honeypot sensor. Honeypot decoy type: Suricata. Decoy listen port: 22413/tcp. Observed event time: 2026-05-21 12:14:57 UTC. Report from passive honeypot only; no payload or credentials included.
show less
Port Scan
π¬π§
consul.to
2026-05-21 03:21:16
(2 months ago)
Web attack/malicious scanning detected
Web App Attack
π©πͺ
CELOS-SOC
2026-05-16 00:30:56
(2 months ago)
Multiple Unauthorized SSLVPN Login Attempts
Hacking
Brute-Force