๐บ๐ธ
TPI-Abuse
2025-10-30 06:17:40
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 45.159.23.199 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.159.23.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 30 02:17:34.321072 2025] [security2:error] [pid 30900:tid 30900] [client 45.159.23.199:41347] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jolankagroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jolankagroup.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aQMC_upO8Wh3UTWv7MhDawAAABo"], referer: https://jolankagroup.com/wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-30 01:34:43
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 45.159.23.199 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.159.23.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 29 21:34:35.979958 2025] [security2:error] [pid 4623:tid 4623] [client 45.159.23.199:20737] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||maffiniandbearce.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "maffiniandbearce.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aQLAq3Upo05rSIk9tVk0rgAAAAo"], referer: https://maffiniandbearce.com/wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-06 20:37:11
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 45.159.23.199 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.159.23.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 16:37:04.698814 2025] [security2:error] [pid 28487:tid 28487] [client 45.159.23.199:48399] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Barcalounger/Images/Danbury II/Thumbs.db"] [unique_id "aLybcIJMWD_KCiTeqlPFAAAAABk"], referer: https://vitalitywebb.com/backstore/Barcalounger/Images/Danbury%20II/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2025-06-27 10:07:48
(11 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐จ๐ญ
backslash
2025-05-23 22:50:06
(1 year ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-05-23 17:35:09
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 45.159.23.199 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.159.23.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 23 13:35:00.355150 2025] [security2:error] [pid 365057:tid 365057] [client 45.159.23.199:57331] [client 45.159.23.199] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.backstore.com|F|2"] [data ".vitalityweb.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.backstore.com"] [uri "/visit our website at www.Vitalityweb.com"] [unique_id "aDCxxIRVmeMFudE05ySZ2AAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Roderic
2024-12-31 10:35:45
(1 year ago)
(apache-bow-document) Failed apache-bow-scanners trigger with match [redacted] from 45.159.23.199 (U ...
show more
(apache-bow-document) Failed apache-bow-scanners trigger with match [redacted] from 45.159.23.199 (US/United States/-)
show less
Hacking
Anonymous
2024-12-22 04:36:40
(1 year ago)
Attempted brute force login to web vpn 2 time(s); last attempt for 2024.12.22 is noted in report tim ...
show more
Attempted brute force login to web vpn 2 time(s); last attempt for 2024.12.22 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2024-12-19 06:17:54
(1 year ago)
Attempted brute force login to web vpn
Hacking
Brute-Force
Anonymous
2024-12-17 20:05:26
(1 year ago)
Attempted brute force login to web vpn
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-11-10 17:11:50
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 45.159.23.199 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.159.23.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 10 12:11:45.826483 2024] [security2:error] [pid 2355052:tid 2355052] [client 45.159.23.199:36907] [client 45.159.23.199] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Barcalounger/Images/Lectern II/Brighton Chocolate/originals/Thumbs.db"] [unique_id "ZzDpUZVjmriA6MVUydtjHQAAAAM"], referer: https://vitalitywebb.com/backstore/Barcalounger/Images/Lectern%20II/Brighton%20Chocolate/originals/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Admins@FBN
2024-10-30 17:07:43
(1 year ago)
VPN Logon Failed: AAA user authentication Rejected user = <zakupki>
Brute-Force
Exploited Host
๐จ๐ฆ
wil.com
2024-10-21 00:42:52
(1 year ago)
GlobalProtect login attempts with user quality.
VPN IP
Brute-Force
Anonymous
2024-09-09 16:55:18
(1 year ago)
VPN Authentication Brute Force biteme
Brute-Force
Anonymous
2024-05-30 01:02:37
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH