๐จ๐ญ
filou812
2026-01-22 11:12:27
(5 months ago)
url tried is "/installer.php"
Web App Attack
๐ฆ๐บ
MAGIC
2025-12-28 03:04:03
(6 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2025-12-02 07:28:52
(6 months ago)
botnet
DDoS Attack
๐ง๐ช
madeit
2025-11-27 12:14:02
(7 months ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 09:51:16
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 154.213.164.101 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 154.213.164.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:51:12.797598 2025] [security2:error] [pid 18568:tid 18568] [client 154.213.164.101:31927] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.cofias.net"] [uri "/.git/HEAD"] [unique_id "aSQqkPnNdUTbhRXxX6dxQAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 06:45:49
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 154.213.164.101 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 154.213.164.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:45:44.435534 2025] [security2:error] [pid 7376:tid 7376] [client 154.213.164.101:13853] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "animatuevento.com.mx"] [uri "/.env"] [unique_id "aSP_GMH2v0rsm5Eon1_hEgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 05:45:21
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 154.213.164.101 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 154.213.164.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:45:04.686495 2025] [security2:error] [pid 16589:tid 16589] [client 154.213.164.101:34173] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.gracefaerie.com"] [uri "/.git/HEAD"] [unique_id "aSPw4Pg_xDJIxpPbwc4yFgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 04:23:55
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 154.213.164.101 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 154.213.164.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:23:50.378972 2025] [security2:error] [pid 12076:tid 12076] [client 154.213.164.101:14805] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.teleplussolutions.com"] [uri "/.env"] [unique_id "aSPd1r1VggWFv40wXiYgWwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-13 18:36:42
(7 months ago)
This IP was involved in an brute force and password spray attack on 2025/11/13 12:34:25
Port Scan
Brute-Force
Exploited Host
Web App Attack
๐ซ๐ฎ
JimArchon72
2025-10-27 04:44:49
(8 months ago)
2025-10-27 04:44:49 - Port Scan From IP: 154.213.164.101
Port Scan
SSH
๐ง๐ช
cmbplf
2025-10-05 21:30:46
(8 months ago)
3.971 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-10-05 00:56:00
(8 months ago)
(mod_security) mod_security (id:210831) triggered by 154.213.164.101 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 154.213.164.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 04 20:55:55.390927 2025] [security2:error] [pid 1402:tid 1402] [client 154.213.164.101:31597] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||maffiniandbearce.com|F|4"] [data "compatible ; MSIE"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "maffiniandbearce.com"] [uri "/xmlrpc.php"] [unique_id "aOHCGzQEYYCECAL3ucDiDgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nowyouknow
2025-09-30 15:05:00
(8 months ago)
(From [email protected] ) Hi cantalupochiropractic.net, hope youโre doing well, nowadays ...
show more
(From [email protected] ) Hi cantalupochiropractic.net, hope youโre doing well, nowadays businesses are seeing more profits by using AI agents instead of extra employees. Why pay employees for repetitive work when AI agents do it faster and at lower cost?
If youโd like, we can share our screen and explain everything in detail, showing exactly how this could work for your business.
got time for a quick talk this week?
Best,
Jay
Satori Online CEO
https://satori-online.com/satori-online
show less
Phishing
Web Spam
๐บ๐ธ
fbarela
2025-09-30 01:00:58
(8 months ago)
FortiGate SSL VPN login failures.
Hacking
Brute-Force
๐ฉ๐ช
neckaralb-admin.de
2025-09-27 10:02:49
(9 months ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack