๐จ๐ญ
backslash
2026-01-11 11:55:04
(5 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
kosada.com
2026-01-06 00:38:08
(5 months ago)
Web password guessing
Brute-Force
Anonymous
2026-01-05 20:08:06
(5 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2026.01.05 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2026.01.05 is noted in report timestamp
show less
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-11-24 09:37:51
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 154.213.166.211 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 154.213.166.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:37:42.376593 2025] [security2:error] [pid 20566:tid 20566] [client 154.213.166.211:52709] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blueweddingnapkins.com"] [uri "/.git/HEAD"] [unique_id "aSQnZtRfCO6HYcL--S6X0wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 08:39:40
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 154.213.166.211 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 154.213.166.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:39:36.714570 2025] [security2:error] [pid 10899:tid 10899] [client 154.213.166.211:25835] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.gdg1.com"] [uri "/.git/HEAD"] [unique_id "aSQZyPccjR1eEJgsju5GpwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 07:28:45
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 154.213.166.211 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 154.213.166.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:28:41.337756 2025] [security2:error] [pid 28822:tid 28822] [client 154.213.166.211:59719] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aspenbrookestudio.com"] [uri "/.git/HEAD"] [unique_id "aSQJKa22Sv6Cb0WPhl0jBgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 05:26:25
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 154.213.166.211 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 154.213.166.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:26:21.436740 2025] [security2:error] [pid 2072:tid 2072] [client 154.213.166.211:29587] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.microkerneltechnologies.com"] [uri "/.env"] [unique_id "aSPsfZ_Qh2YajZcpnSEZNAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 03:51:48
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 154.213.166.211 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 154.213.166.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 22:51:43.755386 2025] [security2:error] [pid 6655:tid 6655] [client 154.213.166.211:23319] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "leah.byles.net"] [uri "/.svn/wc.db"] [unique_id "aSPWT4T575sV0Sbcc7h-fgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-14 05:34:26
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 154.213.166.211 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 154.213.166.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 14 00:34:20.541639 2025] [security2:error] [pid 3351:tid 3351] [client 154.213.166.211:43045] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.pscc.com"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aRa_XBc5zNrtYeUiu-Pu1gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-02 17:51:54
(7 months ago)
This IP was involved in an brute force and password spray attack on 2025/11/02 06:50:08
Port Scan
Brute-Force
Exploited Host
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2025-10-29 17:16:58
(7 months ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ง๐ท
hostseries
2025-09-25 21:13:05
(8 months ago)
Trigger: LF_DISTATTACK
Brute-Force
Anonymous
2025-09-21 04:28:58
(8 months ago)
Attempted brute force login to web vpn 3 time(s); last attempt for 2025.09.21 is noted in report tim ...
show more
Attempted brute force login to web vpn 3 time(s); last attempt for 2025.09.21 is noted in report timestamp
show less
Hacking
Brute-Force
๐ซ๐ท
tecnicorioja
2025-09-21 02:00:25
(8 months ago)
Failed password for root Sep 21 00:02:32 port 60543
Brute-Force
SSH
๐บ๐ธ
hostseries
2025-09-20 15:33:46
(8 months ago)
Trigger: LF_DISTATTACK
Brute-Force