๐ฉ๐ช
Admins@FBN
2025-10-06 12:38:18
(8 months ago)
VPN Logon Failed: AAA user authentication Rejected user = <awa130563g>
Brute-Force
Exploited Host
Anonymous
2025-09-19 11:42:26
(8 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-09-13 01:25:14
(8 months ago)
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH
๐ง๐ท
hostseries
2025-09-11 08:50:15
(9 months ago)
Trigger: LF_DISTATTACK
Brute-Force
๐ง๐พ
stroytrest
2025-08-29 11:14:12
(9 months ago)
2025-08-29T14:14:11.355253+03:00 debian kernel: [469536.276470] nftables: SCAN-SSH IN=ens1 OUT= MAC= ...
show more
2025-08-29T14:14:11.355253+03:00 debian kernel: [469536.276470] nftables: SCAN-SSH IN=ens1 OUT= MAC= SRC=154.94.12.168 DST=xxx.xxx.xxx.xxx LEN=60 TOS=0x00 PREC=0x00 TTL=50 ID=11404 DF PROTO=TCP SPT=57695 DPT=22 WINDOW=64240 RES=0x00 SYN URGP=0
...
show less
Port Scan
๐ฉ๐ช
sato
2025-08-26 09:33:32
(9 months ago)
*Port Scan* detected from 154.94.12.168 (-).
Port Scan
Anonymous
2025-07-15 18:40:11
(10 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฌ๐ง
rakkor
2025-07-02 10:36:29
(11 months ago)
2025/07/02 11:36:28 [error] 15697#15697: *3226426 FastCGI sent in stderr: "Primary script unknown" w ...
show more
2025/07/02 11:36:28 [error] 15697#15697: *3226426 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 154.94.12.168, server: , request: "POST /xmlrpc.php HTTP/1.1", upstream: "fastcgi://unix:/run/php-fpm/php-925b669d-80ec-41dd-b8c8-bf5a26d831bf.sock:", host: "rakkor.co.uk"
...
show less
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-07-02 01:02:13
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 154.94.12.168 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 154.94.12.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 01 21:02:09.363115 2025] [security2:error] [pid 15835:tid 15835] [client 154.94.12.168:9805] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||eworld-media.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "eworld-media.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aGSFEb44xcqksWfc-c9D1wAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Netrix
2025-06-18 16:32:00
(11 months ago)
L7 Flood botnet hosted by 3xK Tech
DDoS Attack
Web Spam
SSH
๐บ๐ธ
TPI-Abuse
2025-04-11 01:16:41
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 154.94.12.168 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 154.94.12.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 10 21:16:32.901847 2025] [security2:error] [pid 21582:tid 21613] [client 154.94.12.168:35235] [client 154.94.12.168] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||andyboynton.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "andyboynton.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z_htcIZxhvbReO_x5_ZXqwAAABg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-09 07:46:22
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 154.94.12.168 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 154.94.12.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 09 03:46:18.051170 2025] [security2:error] [pid 3595:tid 3595] [client 154.94.12.168:45369] [client 154.94.12.168] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||g-h2o.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "g-h2o.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z_Ylys399amBk1X7VEPRlwAAABY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-09 06:51:27
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 154.94.12.168 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 154.94.12.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 09 02:51:19.840740 2025] [security2:error] [pid 23152:tid 23233] [client 154.94.12.168:16451] [client 154.94.12.168] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||keetons.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "keetons.net"] [uri "/wp-json/wp/v2/users"] [unique_id "Z_YY50QOYxfjNCNR6G87FAAAAFg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
oncord
2025-02-05 10:38:42
(1 year ago)
Form spam
Web Spam
๐บ๐ธ
oncord
2025-01-31 02:13:49
(1 year ago)
Form spam
Web Spam