π©πͺ
Packets-Decreaser.NET
2025-12-10 14:34:41
(5 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
π¨πΏ
lp
2025-11-14 17:50:51
(6 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 45.66.209.161
2025-11-14T18:31:01+01: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 45.66.209.161
2025-11-14T18:31:01+01:00 vpn Access-Reject 'Liam.Wilson' station: 45.66.209.161 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
π¨πΏ
lp
2025-11-13 08:52:31
(6 months ago)
Unauthorized VPN login attempts: 3 attempts were recorded from 45.66.209.161
2025-11-13T09:29:24+01: ...
show more
Unauthorized VPN login attempts: 3 attempts were recorded from 45.66.209.161
2025-11-13T09:29:24+01:00 vpn Access-Reject 'matthew.ward' station: 45.66.209.161 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2025-11-13T09:30:33+01:00 vpn Access-Reject 'wyatt.gomez' station: 45.66.209.161 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2025-11-13T09:40:19+01:00 vpn Access-Reject 'miles.cooper' station: 45.66.209.161 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
π¨πΏ
lp
2025-11-12 19:22:17
(6 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 45.66.209.161
2025-11-12T18:52:59+01: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 45.66.209.161
2025-11-12T18:52:59+01:00 vpn Access-Reject 'Owen.Jackson' station: 45.66.209.161 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
π¨πΏ
lp
2025-11-11 14:50:53
(6 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 45.66.209.161
2025-11-11T15:35:24+01: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 45.66.209.161
2025-11-11T15:35:24+01:00 vpn Access-Reject 'deputy' station: 45.66.209.161 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-06 17:59:08
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 45.66.209.161 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.66.209.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 13:59:01.652571 2025] [security2:error] [pid 1375:tid 1375] [client 45.66.209.161:60961] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Cozzia/pics/Thumbs.db"] [unique_id "aLx2ZchyJywWRF7K9vA7pQAAABE"], referer: https://vitalitywebb.com/backstore/Cozzia/pics/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-05-12 23:25:18
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.66.209.161 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.66.209.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 12 19:25:13.714179 2025] [security2:error] [pid 3009962:tid 3009965] [client 45.66.209.161:24583] [client 45.66.209.161] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||woofnrose.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "woofnrose.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aCKDWefiDADWS_yMsFmUhwAAAQA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
MAGIC
2025-05-10 22:10:21
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
πΊπΈ
TPI-Abuse
2025-05-06 20:46:42
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 45.66.209.161 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.66.209.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 06 16:46:34.071121 2025] [security2:error] [pid 1488846:tid 1488846] [client 45.66.209.161:15245] [client 45.66.209.161] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.backstore.com|F|2"] [data ".losangelesseating.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.backstore.com"] [uri "/www.losangelesseating.com"] [unique_id "aBp1Kr8QHSqPZbGoBUO34gAAABU"], referer: http://www.backstore.com/Web-Sites.htm
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
F242
2025-05-06 06:31:35
(1 year ago)
Wordpress Login or XMLRPC abuse
Web App Attack
Anonymous
2025-03-30 06:50:03
(1 year ago)
IP banned by Fail2Ban in jail wordpress
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-03-05 10:05:52
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 45.66.209.161 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.66.209.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 05 05:05:48.419041 2025] [security2:error] [pid 44212:tid 44212] [client 45.66.209.161:54575] [client 45.66.209.161] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Steelcase/pics/Cobi/Thumbs.db"] [unique_id "Z8gh_EXN4DhCdjLH86yg8AAAAAY"], referer: https://vitalitywebb.com/backstore/Steelcase/pics/Cobi/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-01-27 13:40:10
(1 year ago)
Automatic report - Vulnerability scan
/RDWeb/Pages/en-US/login.aspx
Web App Attack
Anonymous
2025-01-26 01:55:08
(1 year ago)
Automatic report - Vulnerability scan
/RDWeb/Pages/en-US/login.aspx
Web App Attack
Anonymous
2025-01-24 23:25:16
(1 year ago)
Automatic report - Vulnerability scan
/RDWeb/Pages/en-US/login.aspx
Web App Attack