Anonymous
2026-01-12 03:34:51
(4 months ago)
wordpress-trap
Web App Attack
๐จ๐ญ
backslash
2025-12-29 17:40:04
(5 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐ฎ๐น
VHosting
2025-12-29 11:05:04
(5 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ฏ๐ต
ki3
2025-12-05 16:36:28
(6 months ago)
Fail2Ban: Web App Attacks and Forum Spam 154.213.164.28 1764952588.0(JST)
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-27 21:39:53
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 154.213.164.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 154.213.164.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 27 16:39:45.795808 2025] [security2:error] [pid 5218:tid 5218] [client 154.213.164.28:38691] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "floridafrontiersmen.org"] [uri "/.env"] [unique_id "aSjFIXlFGmKQjWhkcXgdIQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Thaliruth
2025-11-27 19:24:34
(6 months ago)
154.213.164.28 - - [27/Nov/2025:20:24:32 +0100] "GET /.aws/credentials HTTP/1.1" 404 257 "-" "Mozill ...
show more
154.213.164.28 - - [27/Nov/2025:20:24:32 +0100] "GET /.aws/credentials HTTP/1.1" 404 257 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36 Edg/119.0.0.0"
default:80 154.213.164.28 - - [27/Nov/2025:20:24:32 +0100] "GET /.aws/credentials HTTP/1.0" 404 421 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36 Edg/119.0.0.0"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 05:01:05
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 154.213.164.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 154.213.164.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 00:01:01.668058 2025] [security2:error] [pid 19223:tid 19223] [client 154.213.164.28:58605] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.nigunensemble.net"] [uri "/.git/HEAD"] [unique_id "aSU4DbBU5fl6AkpLZMVH-gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:30:47
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 154.213.164.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 154.213.164.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:30:40.323094 2025] [security2:error] [pid 8739:tid 8739] [client 154.213.164.28:9689] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.marine.curryfirm.com"] [uri "/.env"] [unique_id "aSUw8Bq4UXczJ5gcb1PngAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:14:18
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 154.213.164.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 154.213.164.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:14:14.475726 2025] [security2:error] [pid 12991:tid 12991] [client 154.213.164.28:24227] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.vonkugelgen.com"] [uri "/.svn/wc.db"] [unique_id "aSUtFv_Q6C9TUUGsa-pb9wAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 03:03:45
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 154.213.164.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 154.213.164.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:03:40.355499 2025] [security2:error] [pid 11191:tid 11191] [client 154.213.164.28:22085] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.lexvaz.com"] [uri "/.svn/wc.db"] [unique_id "aSUcjCQs7DAl34xMWoja6wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 02:28:27
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 154.213.164.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 154.213.164.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:28:21.503376 2025] [security2:error] [pid 27727:tid 27737] [client 154.213.164.28:28251] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.millicanjones.com"] [uri "/.git/HEAD"] [unique_id "aSUURfeXMnwYTnmV60PT5wAAAMg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 00:41:36
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 154.213.164.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 154.213.164.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 19:41:29.158859 2025] [security2:error] [pid 19299:tid 19299] [client 154.213.164.28:13959] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.tunabay.com"] [uri "/.svn/wc.db"] [unique_id "aST7Obx38N4DUUHitVz7bwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Ad Ministrator
2025-10-20 21:09:21
(7 months ago)
RdpGuard detected brute-force attempt on RD-WEB
Brute-Force
Anonymous
2025-09-25 19:35:30
(8 months ago)
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.09.25 is noted in report tim ...
show more
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.09.25 is noted in report timestamp
show less
Hacking
Brute-Force
๐ง๐ท
hostseries
2025-09-24 19:04:47
(8 months ago)
Distributed Brute-Force attack
Brute-Force