๐บ๐ธ
TPI-Abuse
2026-05-22 11:20:20
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 185.94.32.196 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 185.94.32.196 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 07:20:14.933494 2026] [security2:error] [pid 23491:tid 23531] [client 185.94.32.196:47379] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.catislandrentals.com.nicholsinvest.com"] [uri "/wp-config.php~"] [unique_id "ahA77jKDm1bcZwC1kZ7mLwAAAMs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
tmiland
2026-05-21 01:26:59
(2 weeks ago)
(wordpress_404) WordPress Plugins Honeypot Trap 185.94.32.196 (RU/Russia/-): 2 in the last 3600 secs ...
show more
(wordpress_404) WordPress Plugins Honeypot Trap 185.94.32.196 (RU/Russia/-): 2 in the last 3600 secs; IP: 185.94.32.196; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 185.94.32.196 - - [21/May/2026:03:26:54 +0200] "HEAD /wp-content/plugins/brizy/readme.txt HTTP/1.1" 404 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.2 Safari/605.1.15" 185.94.32.196 - - [21/May/2026:03:26:54 +0200] "HEAD /wp-content/plugins/really-simple-ssl/readme.txt HTTP/1.1" 404 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.2 Safari/605.1.15"
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-20 21:29:11
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 185.94.32.196 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 185.94.32.196 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 17:29:05.414226 2026] [security2:error] [pid 11165:tid 11165] [client 185.94.32.196:9575] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "avalderlaw.com"] [uri "/.wp-config.php.swp"] [unique_id "ag4noTP_sxqTXREcp0K_AQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 12:57:31
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 185.94.32.196 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 185.94.32.196 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 08:57:23.571795 2026] [security2:error] [pid 7412:tid 7412] [client 185.94.32.196:41733] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.txt" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brianwhitty.com"] [uri "/wp-config.txt"] [unique_id "ag2vs4U-yOAhpM0pq69TkQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-17 11:00:02
(1 month ago)
| [Dangerous/Russia] Aggressive IP 185.94.32.196 (~30 hits). Type: DoS Defender- Web server 400 erro ...
show more
| [Dangerous/Russia] Aggressive IP 185.94.32.196 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
๐ซ๐ท
dynamix
2026-04-17 08:05:02
(1 month ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-04-15 21:17:00
(1 month ago)
Exceeded the maximum global requests per minute for crawlers or humans.
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
wil.com
2024-10-20 19:43:14
(1 year ago)
GlobalProtect login attempts with user hrfax.
VPN IP
Brute-Force
๐บ๐ธ
Matthew VanEpps
2024-03-14 09:15:33
(2 years ago)
GLOBALPROTECT gateway-auth login Source User: customerservice Authentication failed: Invalid usernam ...
show more
GLOBALPROTECT gateway-auth login Source User: customerservice Authentication failed: Invalid username or password
show less
Brute-Force
Exploited Host
๐บ๐ธ
Matthew VanEpps
2024-03-14 09:15:33
(2 years ago)
GLOBALPROTECT gateway-auth login Source User: customerservice Authentication failed: Invalid usernam ...
show more
GLOBALPROTECT gateway-auth login Source User: customerservice Authentication failed: Invalid username or password
show less
Brute-Force
Exploited Host