🇺🇸
agabeckov
2026-09-14 01:47:52
(13 hours ago)
Fail2Ban detected brute-force attempt on Cisco Anyconnect
VPN IP
Brute-Force
🇨🇿
Countryman
2026-09-13 00:10:01
(1 day ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
🇨🇿
Countryman
2026-09-12 00:10:01
(2 days ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
🇩🇪
4server
2026-09-11 05:53:42
(3 days ago)
[FriSep1107:53:36.5927122026][security2:error][pid1367733:tid1367769][client185.201.137.103:0]ModSec ...
show more
[FriSep1107:53:36.5927122026][security2:error][pid1367733:tid1367769][client185.201.137.103:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"prstartup.ch\"][uri\"/xmlrpc.php\"][unique_id\"aqOXYAThQHpGkLyrELISXQAAABg\"]
show less
Port Scan
Brute-Force
Web App Attack
Anonymous
2026-08-22 18:47:36
(3 weeks ago)
Multiple failed login attemps RDS-Web-Access-Server
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-05-28 04:44:39
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 185.201.137.103 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.137.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 28 00:44:34.972000 2026] [security2:error] [pid 9655:tid 9723] [client 185.201.137.103:33907] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nationsrecovery.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nationsrecovery.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahfIMkRLDo_f_j-nR69P5wAAAU8"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-25 00:53:08
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 185.201.137.103 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.137.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 24 20:53:00.979163 2026] [security2:error] [pid 16996:tid 16996] [client 185.201.137.103:32065] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cucciniello.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cucciniello.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahOdbOh5qiMDOn37WztbDgAAAA4"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-22 00:06:39
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 185.201.137.103 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.137.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 20:06:31.293295 2026] [security2:error] [pid 4083:tid 4083] [client 185.201.137.103:26539] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wplusw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wplusw.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ag-eBz1c5zsbNipHjqrdowAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-21 18:50:58
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 185.201.137.103 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.137.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 14:50:50.938976 2026] [security2:error] [pid 7245:tid 7245] [client 185.201.137.103:41567] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||veenstras.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "veenstras.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ag9UCh6vXa6jONYW8hXl8QAAABo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-29 09:42:10
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 185.201.137.103 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 185.201.137.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 29 05:42:04.849007 2026] [security2:error] [pid 13881:tid 13881] [client 185.201.137.103:10559] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.gescosigns.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.gescosigns.com"] [uri "/s3cmd.ini"] [unique_id "afHSbBKnPYlm2i6yvVaiewAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-28 13:42:49
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 185.201.137.103 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 185.201.137.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 09:42:42.802234 2026] [security2:error] [pid 4698:tid 4698] [client 185.201.137.103:60275] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||teeandpanteeshop.srtmanagementservices.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "teeandpanteeshop.srtmanagementservices.com"] [uri "/s3cmd.ini"] [unique_id "afC5Ui_lYihiRUsizghr3wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-28 11:15:19
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 185.201.137.103 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 185.201.137.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 07:15:15.726282 2026] [security2:error] [pid 713:tid 713] [client 185.201.137.103:49727] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.buggyshop.org|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.buggyshop.org"] [uri "/s3cmd.ini"] [unique_id "afCWwwMz4zrVvVBlEyQB-wAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-26 04:03:32
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 185.201.137.103 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 185.201.137.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 00:03:29.274474 2026] [security2:error] [pid 3891:tid 3891] [client 185.201.137.103:63753] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ebookplanner.banis-associates.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ebookplanner.banis-associates.com"] [uri "/s3cmd.ini"] [unique_id "ae2OkWHzFR6u7EX8hqN_TQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack