๐บ๐ธ
TPI-Abuse
2026-05-18 18:51:22
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 185.94.35.192 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 185.94.35.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 18 14:51:15.921319 2026] [security2:error] [pid 10087:tid 10155] [client 185.94.35.192:46053] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||artmarialeon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "artmarialeon.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agtfo7WEGL916V3VPBuXCAAAAYM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-10 21:58:55
(3 weeks ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 00-58.185.94.35.192.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 00-58.185.94.35.192.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
Anonymous
2026-05-08 07:10:56
(4 weeks ago)
Forum/form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2025-09-06 21:31:21
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 185.94.35.192 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 185.94.35.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 17:31:16.411637 2025] [security2:error] [pid 29116:tid 29116] [client 185.94.35.192:24871] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Barcalounger/Images/Lectern II/Brighton Chocolate/Thumbs.db"] [unique_id "aLyoJDZuVMSjSFeaaoRYPwAAAA4"], referer: https://vitalitywebb.com/backstore/Barcalounger/Images/Lectern%20II/Brighton%20Chocolate/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-21 01:26:10
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 185.94.35.192 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 185.94.35.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 20 21:26:04.914881 2025] [security2:error] [pid 3065994:tid 3065994] [client 185.94.35.192:18357] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Steelcase/pics/STLC-674791/Thumbs.db"] [unique_id "aFYKLJoDXtMzQDUZF94T6gAAAAI"], referer: https://vitalitywebb.com/backstore/Steelcase/pics/STLC-674791/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-06-13 04:05:01
(11 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐จ๐ฆ
wil.com
2025-06-08 04:53:59
(11 months ago)
GlobalProtect login attempts with user jwilliams.
VPN IP
Brute-Force
๐ฒ๐ฝ
licjperezl
2025-06-05 17:58:29
(1 year ago)
Ataque de diccionario o DDoS en nuestros servicios en linea
Brute-Force
๐จ๐ญ
backslash
2025-05-23 22:55:05
(1 year ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-03-05 09:09:36
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 185.94.35.192 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 185.94.35.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 05 04:09:32.796845 2025] [security2:error] [pid 4124685:tid 4124685] [client 185.94.35.192:29037] [client 185.94.35.192] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".jpg - shortcut.lnk"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Golden-Technologies/pics/Golden_Technologies_PR535_MaxiComfort_Lift_Chair_Recliner_Anchor_Front.jpg - Shortcut.lnk"] [unique_id "Z8gUzBEwL0xaCuWrUvUJUgAAAAQ"], referer: https://vitalitywebb.com/backstore/Golden-Technologies/pics/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-02-27 13:53:07
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-02-23 14:00:09
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-02-15 12:52:11
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-01-27 14:15:00
(1 year ago)
Used in a distributed login attack
Brute-Force
๐บ๐ธ
nationaleventpros.com
2024-10-16 21:32:30
(1 year ago)
WordPress login attempt
Brute-Force