๐ฉ๐ช
HERA - Operations
2026-02-11 21:58:48
(4 months ago)
argeforum - searching for vulnerable scripts: config 2026/02/11 22:58:48
Web App Attack
๐ฎ๐น
VHosting
2025-12-23 11:31:18
(5 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
๐ช๐ธ
10dencehispahard SL
2025-12-03 07:45:16
(6 months ago)
Wordpress probing for vulnerabilities
Hacking
Exploited Host
๐ซ๐ฎ
Shaik Sai Meera
2025-11-25 19:10:12
(6 months ago)
IM360 WAF: Hidden file access
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-11-25 02:57:15
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 154.213.161.211 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 154.213.161.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:57:02.543999 2025] [security2:error] [pid 25037:tid 25037] [client 154.213.161.211:18797] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.miszewski.com"] [uri "/.env"] [unique_id "aSUa_udTvEE5rcofUm8yQQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 01:26:38
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 154.213.161.211 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 154.213.161.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 20:26:30.837048 2025] [security2:error] [pid 1211:tid 1211] [client 154.213.161.211:23327] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.londongroup.info"] [uri "/.env"] [unique_id "aSUFxiXn966Fv8EtFkjSXQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 00:55:21
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 154.213.161.211 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 154.213.161.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 19:52:53.616484 2025] [security2:error] [pid 10859:tid 10859] [client 154.213.161.211:14223] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.steam.steambalancing.com"] [uri "/.svn/wc.db"] [unique_id "aST95RHdB-sLnKPLHaG5dwAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-11 22:14:27
(7 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-10-04 09:50:49
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 154.213.161.211 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 154.213.161.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 04 05:50:41.879152 2025] [security2:error] [pid 23610:tid 23610] [client 154.213.161.211:45389] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.yuichiro.us:80|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.yuichiro.us"] [uri "/wp-json/wp/v2/users/"] [unique_id "aODt8TeiaUDGktHk58sOTgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
fbarela
2025-09-25 05:02:35
(8 months ago)
FortiGate SSL VPN login failures.
Hacking
Brute-Force
Anonymous
2025-09-22 21:50:13
(8 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.09.22 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.09.22 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-09-21 16:10:27
(8 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
Anonymous
2025-09-20 21:34:21
(8 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.09.20 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.09.20 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-09-13 01:56:04
(8 months ago)
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.09.13 is noted in report tim ...
show more
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.09.13 is noted in report timestamp
show less
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-09-11 22:34:00
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 154.213.161.211 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 154.213.161.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 11 18:33:56.136014 2025] [security2:error] [pid 25604:tid 25616] [client 154.213.161.211:33517] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gffm.aafm.us"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aMNOVJdnSZI7D2iYVPW_9AAAAEg"]
show less
Brute-Force
Bad Web Bot
Web App Attack