๐บ๐ธ
TPI-Abuse
2026-05-22 11:20:46
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 94.154.127.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 94.154.127.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 07:20:38.555019 2026] [security2:error] [pid 23491:tid 23541] [client 94.154.127.43:62503] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.tomrachman.com"] [uri "/wp-config.php.dist"] [unique_id "ahA8BjKDm1bcZwC1kZ7mQAAAANU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 03:11:10
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 94.154.127.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 94.154.127.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 19 23:11:05.107593 2026] [security2:error] [pid 1468:tid 1468] [client 94.154.127.43:49091] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "palumbodesigns.com"] [uri "/wp-config.php~"] [unique_id "ag0mSe9lbzI8C9HnWYm7IAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-04 08:24:36
(1 month ago)
94.154.127.43 - - [04/May/2026:16:24:35 +0800] "POST /xmlrpc.php HTTP/1.1" 200 4581 "-" "Mozilla/5.0 ...
show more
94.154.127.43 - - [04/May/2026:16:24:35 +0800] "POST /xmlrpc.php HTTP/1.1" 200 4581 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob.fr
2026-04-16 16:15:07
(2 months ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
๐บ๐ธ
nyt
2026-04-16 01:09:24
(2 months ago)
WP User Enumeration, WP Author Enumeration
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-28 00:58:53
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 94.154.127.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 94.154.127.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 27 19:58:48.744776 2026] [security2:error] [pid 28219:tid 28219] [client 94.154.127.43:9741] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||somehand.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "somehand.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aaI9yNoviXotTH9Lj-0GHQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-26 08:59:28
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 94.154.127.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 94.154.127.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 26 03:59:21.007250 2026] [security2:error] [pid 27716:tid 27716] [client 94.154.127.43:13811] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||boaredraven.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "boaredraven.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aaALaaaxowb9OyhC-JGvjQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-24 15:04:44
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 94.154.127.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 94.154.127.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 24 10:04:41.229054 2026] [security2:error] [pid 32300:tid 32343] [client 94.154.127.43:44199] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||41bravo.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "41bravo.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aZ2-CQ0uPzT7aJRjl4wwMAAAANE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-10 14:34:49
(6 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐จ๐ฟ
lp
2025-12-04 23:50:46
(6 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 94.154.127.43
2025-12-05T00:16:38+01: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 94.154.127.43
2025-12-05T00:16:38+01:00 vpn Access-Reject 'user' station: 94.154.127.43 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐จ๐ฟ
lp
2025-12-04 07:23:37
(6 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 94.154.127.43
2025-12-04T07:41:30+01: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 94.154.127.43
2025-12-04T07:41:30+01:00 vpn Access-Reject 'tracey5' station: 94.154.127.43 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
Anonymous
2025-12-02 15:52:44
(6 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.12.02 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.12.02 is noted in report timestamp
show less
Hacking
Brute-Force
๐จ๐ฟ
lp
2025-12-02 11:54:40
(6 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 94.154.127.43
2025-12-02T12:26:03+01: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 94.154.127.43
2025-12-02T12:26:03+01:00 vpn Access-Reject 'rsbot' station: 94.154.127.43 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐จ๐ฆ
wil.com
2024-10-20 10:14:58
(1 year ago)
GlobalProtect login attempts with user wonderware.
VPN IP
Brute-Force
Anonymous
2024-10-10 07:50:43
(1 year ago)
Automatic report - Vulnerability scan
/RDWeb/Pages/en-US/login.aspx
Web App Attack