๐บ๐ธ
ThreatsIntelz
2026-08-20 21:36:55
(3 days ago)
SSL-VPN brute force / password guessing authentication attempts observed against FortiGate SSLVPN se ...
show more
SSL-VPN brute force / password guessing authentication attempts observed against FortiGate SSLVPN services. Source within 95.164.207.0/24.
show less
Brute-Force
SSH
Anonymous
2026-08-18 22:01:38
(5 days ago)
Network service scanning detected by FortiGate; source quarantined.
Port Scan
๐บ๐ธ
TPI-Abuse
2025-10-01 22:44:48
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 95.164.207.243 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 95.164.207.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 18:42:06.901916 2025] [security2:error] [pid 21060:tid 21060] [client 95.164.207.243:13279] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thomasanthonyquinn.com"] [uri "/backup/.env"] [unique_id "aN2uPpPe_jJz0C2Ar9_GyQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2025-10-01 22:42:52
(10 months ago)
(mod_security-custom) mod_security (id:210492) triggered by 95.164.207.243 (US/United States/New Jer ...
show more
(mod_security-custom) mod_security (id:210492) triggered by 95.164.207.243 (US/United States/New Jersey/Hackensack/-/[AS394814 ISP4LIFE]): 1 in the last 3600 secs (0-srv1)
show less
Hacking
๐บ๐ธ
Penny Packer
2025-10-01 17:17:56
(10 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-01 10:40:49
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 95.164.207.243 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 95.164.207.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 06:40:44.186104 2025] [security2:error] [pid 11588:tid 11588] [client 95.164.207.243:9063] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alsdepot.com"] [uri "/wp-config.php.save"] [unique_id "aN0FLPYLC03NxDtuCUTTKgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-15 05:25:41
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 95.164.207.243 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 95.164.207.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 15 01:25:33.395555 2025] [security2:error] [pid 24285:tid 24285] [client 95.164.207.243:15041] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||texasfurnitureinc.com|F|2"] [data ".com.sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "texasfurnitureinc.com"] [uri "/wp-content/texasfurnitureinc.com.sql"] [unique_id "aMejTfRXpaILVqdbLuRuggAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-15 00:41:00
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 95.164.207.243 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 95.164.207.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 14 20:40:57.320014 2025] [security2:error] [pid 11767:tid 11767] [client 95.164.207.243:11937] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kemela.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kemela.com"] [uri "/webcode.sql"] [unique_id "aMdgmf3_BX2gedqnTxqeVQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-14 21:52:38
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 95.164.207.243 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 95.164.207.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 14 17:52:31.879173 2025] [security2:error] [pid 29182:tid 29182] [client 95.164.207.243:32899] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||voodooshop.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "voodooshop.com"] [uri "/2024.sql"] [unique_id "aMc5H5XfY0sOOKLTX0vjWgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-11 22:21:06
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 95.164.207.243 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 95.164.207.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 11 18:21:00.806257 2025] [security2:error] [pid 21033:tid 21033] [client 95.164.207.243:27853] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||allautousa.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "allautousa.com"] [uri "/exports/pma.sql"] [unique_id "aMNLTNL2eZ33H4YEY6rt3gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-07-29 07:35:49
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ซ๐ฎ
JimArchon72
2024-07-25 11:10:01
(2 years ago)
2024/07/25 11:07:20 "GET /wp-login.php?action=register HTTP/1.1"
Web App Attack
๐ณ๐ฟ
Tripwire
2024-06-30 00:09:22
(2 years ago)
Wordpress login scanning
Brute-Force
Web App Attack
Anonymous
2024-06-27 23:29:46
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2024-06-27 23:13:33
(2 years ago)
Bot / scanning and/or hacking attempts: GET /wp-login.php HTTP/1.1
Hacking
Web App Attack