๐บ๐ธ
agabeckov
2026-09-15 03:56:43
(3 days ago)
Fail2Ban detected brute-force attempt on Cisco Anyconnect
VPN IP
Brute-Force
๐จ๐ฟ
Countryman
2026-09-12 00:10:01
(6 days ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-04-08 23:20:55
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 157.22.16.220 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.16.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 19:20:49.000572 2026] [security2:error] [pid 2913620:tid 2913620] [client 157.22.16.220:38533] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||delstarr.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "delstarr.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adbi0Byys85i9UwCN-eu1QAAAAM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-02 17:12:54
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 157.22.16.220 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.16.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 13:12:50.713262 2026] [security2:error] [pid 15242:tid 15268] [client 157.22.16.220:17025] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||newports.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "newports.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ac6jkrS2W8u8px5gFv5t8QAAAIc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-03-29 07:57:00
(5 months ago)
GET /wp-login.php HTTP/1.1
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-28 21:37:04
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 157.22.16.220 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.16.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 28 17:36:55.733513 2026] [security2:error] [pid 18789:tid 18789] [client 157.22.16.220:17401] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||poltorak.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "poltorak.net"] [uri "/wp-json/wp/v2/users"] [unique_id "achJ9_Ba8T41uqPsc5094gAAABE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
INTEQ
2026-03-27 06:04:10
(5 months ago)
Web attack from 157.22.16.220
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-25 18:02:56
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 157.22.16.220 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.16.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 25 14:02:51.694009 2026] [security2:error] [pid 964:tid 964] [client 157.22.16.220:25967] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rendermatrix.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rendermatrix.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acQjS_KTwa6N8XhXOAYC5AAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
JimArchon72
2026-02-27 12:55:01
(6 months ago)
2026/02/27 12:54:56 "POST /wp-login.php HTTP/1.1"
Web App Attack