🇨🇿
lp
2026-09-14 09:21:31
(7 hours ago)
Unauthorized VPN login attempts: 2 attempts were recorded from 157.22.45.150
2026-09-14T10:42:23+02: ...
show more
Unauthorized VPN login attempts: 2 attempts were recorded from 157.22.45.150
2026-09-14T10:42:23+02:00 vpn Access-Reject 'nielsenog2' station: 157.22.45.150 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-14T10:43:42+02:00 vpn Access-Reject 'sougud.qc' station: 157.22.45.150 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
🇺🇸
agabeckov
2026-09-14 08:25:05
(8 hours ago)
Fail2Ban detected brute-force attempt on Cisco Anyconnect
VPN IP
Brute-Force
🇨🇿
lp
2026-09-13 00:21:40
(1 day ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 157.22.45.150
2026-09-13T01:09:05+02: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 157.22.45.150
2026-09-13T01:09:05+02:00 vpn Access-Reject 'ANGEL' station: 157.22.45.150 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
🇨🇿
Countryman
2026-09-13 00:10:01
(1 day ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
🇨🇿
Countryman
2026-09-12 00:10:01
(2 days ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
🇨🇿
Countryman
2026-09-10 00:10:01
(4 days ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
🇺🇸
TPI-Abuse
2026-06-11 01:29:50
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 157.22.45.150 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.45.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 21:29:44.035769 2026] [security2:error] [pid 13400:tid 13400] [client 157.22.45.150:17849] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cesmat.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cesmat.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aioPiN4tXmMNiylWBGevqgAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-06 02:37:47
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 157.22.45.150 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.45.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 22:37:42.780501 2026] [security2:error] [pid 14365:tid 14369] [client 157.22.45.150:12205] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jrc3.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jrc3.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiOH9rRUfpjp-aTMa99V5AAAAMI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇩
Burayot
2026-05-31 14:50:26
(3 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 157.22.45.150 (GB/United Kingdom/-) ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 157.22.45.150 (GB/United Kingdom/-): 1 in the last 3600 secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-05-26 12:21:21
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 157.22.45.150 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.45.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 08:21:16.364311 2026] [security2:error] [pid 26628:tid 26628] [client 157.22.45.150:45849] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||directcch.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "directcch.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahWQPAKqTMJ-lqU4x3G0owAAADw"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-24 12:19:04
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 157.22.45.150 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.45.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 24 08:18:59.902851 2026] [security2:error] [pid 19227:tid 19227] [client 157.22.45.150:25709] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||winterspring.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "winterspring.net"] [uri "/wp-json/wp/v2/users"] [unique_id "acKBM5Zf5xiEqS-rtFu7_wAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
kjaerulff
2026-03-23 20:39:47
(5 months ago)
Failed Wordpress login using wp-login.php
Web App Attack
🇺🇸
TPI-Abuse
2026-03-23 17:55:16
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 157.22.45.150 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.45.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 23 13:55:09.830126 2026] [security2:error] [pid 19201:tid 19201] [client 157.22.45.150:58035] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||michaels-house.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "michaels-house.net"] [uri "/wp-json/wp/v2/users"] [unique_id "acF-fQKhQ3sXSGdxETKwggAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-21 22:42:23
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 157.22.45.150 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.45.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 18:42:16.395452 2026] [security2:error] [pid 4495:tid 4577] [client 157.22.45.150:44377] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||leadingedgesupply.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "leadingedgesupply.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ab8eyETqmFpyctEsJH71OwAAAI8"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
nationaleventpros.com
2026-03-21 22:26:32
(5 months ago)
WordPress login attempt
Brute-Force