๐บ๐ธ
agabeckov
2026-09-14 18:27:53
(3 days ago)
Fail2Ban detected brute-force attempt on Cisco Anyconnect
VPN IP
Brute-Force
๐จ๐ฟ
lp
2026-09-14 15:21:09
(3 days ago)
Unauthorized VPN login attempts: 4 attempts were recorded from 122.8.92.27
2026-09-14T16:39:42+02:00 ...
show more
Unauthorized VPN login attempts: 4 attempts were recorded from 122.8.92.27
2026-09-14T16:39:42+02:00 vpn Access-Reject 'millena' station: 122.8.92.27 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-14T16:41:03+02:00 vpn Access-Reject 'lpizzi' station: 122.8.92.27 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-14T16:42:24+02:00 vpn Access-Reject 'dmelo' station: 122.8.92.27 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-14T16:43:42+02:00 vpn Access-Reject 'japarecida' station: 122.8.92.27 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐จ๐ฟ
lp
2026-09-13 03:20:59
(4 days ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 122.8.92.27
2026-09-13T03:52:29+02:00 ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 122.8.92.27
2026-09-13T03:52:29+02:00 vpn Access-Reject 'se03' station: 122.8.92.27 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐จ๐ฟ
Countryman
2026-09-12 00:10:01
(6 days ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
๐จ๐ฟ
lp
2026-09-11 09:21:15
(6 days ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 122.8.92.27
2026-09-11T10:04:47+02:00 ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 122.8.92.27
2026-09-11T10:04:47+02:00 vpn Access-Reject 'mgc2' station: 122.8.92.27 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐จ๐ฟ
lp
2026-09-09 19:49:46
(1 week ago)
Unauthorized VPN login attempts: 3 attempts were recorded from 122.8.92.27
2026-09-09T20:39:05+02:00 ...
show more
Unauthorized VPN login attempts: 3 attempts were recorded from 122.8.92.27
2026-09-09T20:39:05+02:00 vpn Access-Reject 'fares' station: 122.8.92.27 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-09T20:40:25+02:00 vpn Access-Reject 'fares' station: 122.8.92.27 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-09T20:41:44+02:00 vpn Access-Reject 'fariha' station: 122.8.92.27 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-15 12:47:10
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 122.8.92.27 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 122.8.92.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 15 08:47:05.426849 2026] [security2:error] [pid 813920:tid 813920] [client 122.8.92.27:45923] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thebumans.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thebumans.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ad-IyRiIvXkn-QSJziITygAAABQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-15 10:27:58
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 122.8.92.27 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 122.8.92.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 15 06:27:53.299962 2026] [security2:error] [pid 3623837:tid 3623837] [client 122.8.92.27:17335] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||advantage-plus.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "advantage-plus.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ad9oKUAqV9NUhytF5Tyk1gAAAAU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-29 14:02:18
(8 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam