๐ณ๐ฑ
EGP Abuse Dept
2026-04-01 00:34:39
(5 months ago)
Unauthorized connection to proxy port 8080
Port Scan
Hacking
๐จ๐ณ
ThreatBook.io
2025-12-27 23:13:32
(8 months ago)
ThreatBook Intelligence: Zombie,Spam more details on https://threatbook.io/ip/109.108.116.253
SSH
๐ช๐ธ
el-brujo
2025-12-27 12:06:52
(8 months ago)
12/27/2025-13:06:51.999366 109.108.116.253 Protocol: 6 ET SCAN Potential SSH Scan
Port Scan
๐ฎ๐น
VHosting
2025-12-03 16:48:36
(9 months ago)
Detected mail brute force attack from 4 different servers
Brute-Force
๐บ๐ธ
mind5t0rm
2025-08-30 08:12:23
(1 year ago)
(WPLOGIN) WP Login Attack 109.108.116.253 (CZ/Czechia/253.116.108.109.omegatech.cz): 3 in the last 3 ...
show more
(WPLOGIN) WP Login Attack 109.108.116.253 (CZ/Czechia/253.116.108.109.omegatech.cz): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: 109.108.116.253 - - [30/Aug/2025:15:12:06 +0700] "GET /wp-login.php HTTP/1.1" 200 2403 "https://convercon.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.198 Safari/537.36"
109.108.116.253 - - [30/Aug/2025:15:12:14 +0700] "POST /wp-login.php HTTP/1.1" 200 2545 "https://convercon.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.198 Safari/537.36"
109.108.116.253 - - [30/Aug/2025:15:12:20 +0700] "POST /wp-login.php HTTP/1.1" 200 2545 "https://convercon.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.198 Safari/537.36"
show less
Port Scan
๐ฒ๐พ
syokadmin
2025-08-30 05:41:09
(1 year ago)
109.108.116.253 (CZ/Czechia/253.116.108.109.omegatech.cz), 7 distributed SMTP Logins on account [hel ...
show more
109.108.116.253 (CZ/Czechia/253.116.108.109.omegatech.cz), 7 distributed SMTP Logins on account [[email protected] ] in the last 300 secs
show less
Brute-Force
๐ฒ๐พ
syokadmin
2025-08-29 22:09:31
(1 year ago)
109.108.116.253 (CZ/Czechia/253.116.108.109.omegatech.cz), 5 distributed SMTP Logins on account [hel ...
show more
109.108.116.253 (CZ/Czechia/253.116.108.109.omegatech.cz), 5 distributed SMTP Logins on account [[email protected] ] in the last 300 secs
show less
Brute-Force
๐ท๐บ
nyuuzyou
2025-08-17 16:05:43
(1 year ago)
{"action": "connection", "dest_ip": "0.0.0.0", "dest_port": "22", "server": "ssh_server", "src_ip": ...
show more
{"action": "connection", "dest_ip": "0.0.0.0", "dest_port": "22", "server": "ssh_server", "src_ip": "109.108.116.253", "src_port": "60244", "timestamp": "2025-08-17T16:04:42.562434"}
show less
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-07-08 13:06:14
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 109.108.116.253 (253.116.108.109.omegatech.cz): ...
show more
(mod_security) mod_security (id:225170) triggered by 109.108.116.253 (253.116.108.109.omegatech.cz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 08 09:06:09.455900 2025] [security2:error] [pid 32173:tid 32173] [client 109.108.116.253:49450] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||stationrestaurant.ca|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "stationrestaurant.ca"] [uri "/wp-json/wp/v2/users/"] [unique_id "aG0XwSisROPVSEbOr5d5OgAAAAo"], referer: https://stationrestaurant.ca/wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-26 12:16:20
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 109.108.116.253 (253.116.108.109.omegatech.cz): ...
show more
(mod_security) mod_security (id:225170) triggered by 109.108.116.253 (253.116.108.109.omegatech.cz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 26 08:16:14.284919 2025] [security2:error] [pid 1619459:tid 1619459] [client 109.108.116.253:55144] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||barigby.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "barigby.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aF06DlmERqL8jNoUOKBJaQAAAA4"], referer: https://barigby.com/wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Nicolmn
2025-06-24 17:01:12
(1 year ago)
Web form spam ( id hllhm.l )
Web Spam
Anonymous
2025-06-22 05:02:52
(1 year ago)
AGERADE WEBFORM SPAM 109.108.116.253 (253.116.108.109.omegatech.cz)
Web Spam
๐ช๐ธ
el-brujo
2025-06-11 07:29:17
(1 year ago)
06/11/2025-09:29:17.631379 109.108.116.253 Protocol: 6 GPL POLICY SOCKS Proxy attempt
Port Scan
๐ณ๐ฑ
hostmaster.stream
2025-05-30 05:36:36
(1 year ago)
Honeypot triggered on newsletter form. Web spam detected via newsletter signup form. Honeypot field ...
show more
Honeypot triggered on newsletter form. Web spam detected via newsletter signup form. Honeypot field was filled.
show less
Web Spam
๐ฉ๐ช
f2_IT
2025-05-23 14:51:26
(1 year ago)
SSLVPN Login attempt (blocked) from 109.108.116.253
Brute-Force