๐บ๐ธ
agabeckov
2026-09-15 02:38:37
(3 days ago)
Fail2Ban detected brute-force attempt on Cisco Anyconnect
VPN IP
Brute-Force
๐จ๐ฟ
Countryman
2026-09-14 00:10:01
(4 days ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
๐ฎ๐น
mgarofano80
2026-08-26 03:39:27
(3 weeks ago)
Brute-Force
Web App Attack
๐ฉ๐ช
4server
2026-08-11 00:10:10
(1 month ago)
[TueAug1102:10:06.7359842026][security2:error][pid917098:tid917146][client185.201.138.99:0]ModSecuri ...
show more
[TueAug1102:10:06.7359842026][security2:error][pid917098:tid917146][client185.201.138.99:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"alessandrolucchini.ch\"][uri\"/xmlrpc.php\"][unique_id\"anpoXn0GIymEgvDy0lPNBAAAAAo\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ช๐ธ
librebit
2026-06-21 21:25:31
(2 months ago)
Brute force
Brute-Force
๐ช๐ธ
librebit
2026-06-20 07:11:35
(2 months ago)
Brute force
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-03 00:20:23
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 185.201.138.99 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.138.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 02 20:20:16.726638 2026] [security2:error] [pid 6928:tid 6928] [client 185.201.138.99:15381] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||floridausa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "floridausa.com"] [uri "/wp-json/wp/v2/users"] [unique_id "afaUwHh45SeqOAaQUzOCzwAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-27 13:38:50
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 185.201.138.99 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.138.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 27 09:38:45.558522 2026] [security2:error] [pid 9162:tid 9162] [client 185.201.138.99:61811] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nekstlevel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nekstlevel.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ae9m5Y8CXiCdRxfMSX7OCgAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-26 01:15:23
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 185.201.138.99 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.138.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 25 21:15:18.272317 2026] [security2:error] [pid 20506:tid 20506] [client 185.201.138.99:31875] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||vonkugelgen.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "vonkugelgen.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ae1nJjaQkUJqJ0F81GQFwAAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-15 01:39:09
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 185.201.138.99 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.138.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 14 21:39:03.067001 2026] [security2:error] [pid 2404091:tid 2404091] [client 185.201.138.99:53565] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rogerg.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rogerg.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ad7sN0WwMosvdLWd8d9aWgAAAAs"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
kjaerulff
2026-04-12 19:16:37
(5 months ago)
Failed Wordpress login using wp-login.php
Web App Attack
๐บ๐ธ
masterguru
2026-03-16 00:24:26
(6 months ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-169)
Hacking