๐บ๐ธ
ThreatsIntelz
2026-08-20 21:36:55
(1 day ago)
SSL-VPN brute force / password guessing authentication attempts observed against FortiGate SSLVPN se ...
show more
SSL-VPN brute force / password guessing authentication attempts observed against FortiGate SSLVPN services. Source within 95.164.207.0/24.
show less
Brute-Force
SSH
๐บ๐ธ
EchoGuard
2026-02-25 16:50:47
(5 months ago)
FortiGate SSL VPN login failures
Brute-Force
VPN IP
๐ช๐ธ
Mugen
2026-02-24 02:43:10
(5 months ago)
Unauthorized VPN login attempts
Brute-Force
๐บ๐ธ
Cyber Crusader
2026-02-23 20:06:29
(5 months ago)
Hundreds of Attempts (at least) to Connect to and Access Firewall Ports
Port Scan
Hacking
Brute-Force
๐บ๐ธ
EchoGuard
2026-02-19 17:35:19
(6 months ago)
FortiGate SSL VPN login failures
VPN IP
Brute-Force
๐บ๐ธ
fbarela
2026-02-19 12:00:02
(6 months ago)
FortiGate SSL VPN login failures.
Brute-Force
Hacking
Anonymous
2025-10-28 10:35:02
(9 months ago)
wordpress-trap
Web App Attack
๐ฎ๐ฉ
Burayot
2025-10-27 18:01:32
(9 months ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 95.164.207.252 (US/United States/-): ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 95.164.207.252 (US/United States/-): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-16 23:44:11
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 95.164.207.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 95.164.207.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 16 19:44:06.017949 2025] [security2:error] [pid 27126:tid 27126] [client 95.164.207.252:19875] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cruisedawgs.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cruisedawgs.com"] [uri "/site.sql"] [unique_id "aPGDRhQ2PzHGYqAdfoCmSQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-13 22:37:04
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 95.164.207.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 95.164.207.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 13 18:36:58.303585 2025] [security2:error] [pid 9247:tid 9247] [client 95.164.207.252:22907] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||havelocktruckandauto.ca|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "havelocktruckandauto.ca"] [uri "/localhost.sql"] [unique_id "aO1_Cr97NK_7iPC4HqjZTgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-12 11:46:56
(10 months ago)
95.164.207.252 - - [12/Oct/2025:11:46:55 +0000] "GET /backup/localhost.sql HTTP/1.1" 404 46966 "-" " ...
show more
95.164.207.252 - - [12/Oct/2025:11:46:55 +0000] "GET /backup/localhost.sql HTTP/1.1" 404 46966 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36 Edg/116.0.0.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-09 22:44:51
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 95.164.207.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 95.164.207.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 09 18:44:45.081020 2025] [security2:error] [pid 31917:tid 31920] [client 95.164.207.252:24731] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kylight.com"] [uri "/wp-content/backup/wp-config.php.bak"] [unique_id "aOg63Qubz1STfpCB6o2v7gAAAME"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-09 19:31:44
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 95.164.207.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 95.164.207.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 09 15:31:40.308013 2025] [security2:error] [pid 1016:tid 1016] [client 95.164.207.252:13979] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "veneerdent.com"] [uri "/wp-content/uploads/wp-config.php.old"] [unique_id "aOgNnPe-6_qKEySFlKVlwgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-09 18:59:18
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 95.164.207.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 95.164.207.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 09 14:59:13.272459 2025] [security2:error] [pid 30129:tid 30129] [client 95.164.207.252:9963] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gonzalez.com"] [uri "/wp-content/uploads/wp-config.php.old"] [unique_id "aOgGAbgmF8vRgUjDq9bf0wAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-09 18:21:43
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 95.164.207.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 95.164.207.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 09 14:21:35.522087 2025] [security2:error] [pid 6623:tid 6623] [client 95.164.207.252:28353] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mcarrollcommunications.com"] [uri "/wp-content/uploads/wp-config.php.old"] [unique_id "aOf9LxNM1GvUO2e0YzieZQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack