(mod_security) mod_security (id:210492) triggered by 65.111.6.199 (-): 1 in the last 300 secs; Ports ...
show more(mod_security) mod_security (id:210492) triggered by 65.111.6.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 18 16:33:47.783076 2025] [security2:error] [pid 5569:tid 5569] [client 65.111.6.199:44119] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.chateau-saleza-bruges.com"] [uri "/.env"] [unique_id "aRzmO-OqbrS-C1pSeflN1wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
Anonymous
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.17 is noted in report tim ...
show moreAttempted brute force login to web vpn 1 time(s); last attempt for 2025.10.17 is noted in report timestamp
show less
GlobalProtect login attempts with user jvmonteiro.
VPN IP
Brute-Force
Anonymous
Dictionary attack on Palo Alto GlobalProtect VPN portal (port 443) detected via repeated login failu ...
show moreDictionary attack on Palo Alto GlobalProtect VPN portal (port 443) detected via repeated login failures with varying usernames.
show less