๐จ๐ญ
Origon
2026-09-16 19:39:25
(1 day ago)
http-bad-user-agent - IP: 170.168.173.52 - time="2026-09-16T21:39:25+02:00" level=info msg="(555f66 ...
show more
http-bad-user-agent - IP: 170.168.173.52 - time="2026-09-16T21:39:25+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-bad-user-agent by ip 170.168.173.52 (NL/59651) : 4h ban on Ip 170.168.173.52" module=db
show less
Bad Web Bot
๐ธ๐ช
OnTheEdge
2026-09-13 23:55:16
(4 days ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
๐จ๐ฟ
lp
2026-09-13 10:50:12
(5 days ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 170.168.173.52
2026-09-13T11:55:04+02 ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 170.168.173.52
2026-09-13T11:55:04+02:00 vpn Access-Reject 'canteen' station: 170.168.173.52 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐บ๐ธ
agabeckov
2026-09-09 23:27:24
(1 week ago)
Fail2Ban detected brute-force attempt on Cisco Anyconnect
VPN IP
Brute-Force
๐ธ๐ช
OnTheEdge
2026-09-08 16:22:36
(1 week ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
๐ช๐ธ
librebit
2026-07-08 19:34:02
(2 months ago)
Brute force
Brute-Force
๐ช๐ธ
librebit
2026-07-04 05:59:43
(2 months ago)
Brute force
Brute-Force
๐ช๐ธ
librebit
2026-06-29 04:02:05
(2 months ago)
Brute force
Brute-Force
๐ช๐ธ
librebit
2026-06-26 12:22:46
(2 months ago)
Brute force
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-22 13:03:51
(3 months ago)
(mod_security) mod_security (id:218580) triggered by 170.168.173.52 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:218580) triggered by 170.168.173.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 09:03:46.667371 2026] [security2:error] [pid 7217:tid 7217] [client 170.168.173.52:61359] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:\\\\/\\\\*[!+](?:[\\\\w\\\\s=_\\\\-()]+)?\\\\*\\\\/)" at ARGS:Sesion. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/22_SQL_SQLi.conf"] [line "76"] [id "218580"] [rev "1"] [msg "COMODO WAF: MySQL in-line comment detected.||www.teatrosohomadrid.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "SQLi"] [hostname "www.teatrosohomadrid.com"] [uri "/es/ficha-espectaculo.php"] [unique_id "ahBUMrr34xezf1dpNR3wXAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-22 01:05:00
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 170.168.173.52 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 170.168.173.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 21:04:54.665581 2026] [security2:error] [pid 12937:tid 12937] [client 170.168.173.52:19993] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.veneerdent.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.veneerdent.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ag-rtng-YLWxPaapseHdMQAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-21 04:25:01
(3 months ago)
(mod_security) mod_security (id:210350) triggered by 170.168.173.52 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 170.168.173.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 00:24:54.233859 2026] [security2:error] [pid 24818:tid 24818] [client 170.168.173.52:19545] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.nancyscafeandcatering.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.nancyscafeandcatering.com"] [uri "/wp-login.php"] [unique_id "ag6JFiyBUq0kSGSdpDpxwQAAAAs"], referer: http://www.nancyscafeandcatering.com/contact-us/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
securejdprop
2026-05-18 16:40:23
(3 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing. crowdsecurity/http-probing
Hacking
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-05-07 17:43:40
(4 months ago)
Fail2Ban banned 170.168.173.52 for security violations in jail wp-armour. Log: 2026/05/07 17:43:39 [ ...
show more
Fail2Ban banned 170.168.173.52 for security violations in jail wp-armour. Log: 2026/05/07 17:43:39 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 170.168.173.52 | Target: wplogin" , client: 170.168.173.52, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐บ๐ธ
TPI-Abuse
2026-05-05 07:15:33
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 170.168.173.52 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 170.168.173.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 05 03:15:29.610800 2026] [security2:error] [pid 18384:tid 18384] [client 170.168.173.52:14197] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||johnrobinsonconsulting.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "johnrobinsonconsulting.com"] [uri "/"] [unique_id "afmZEZjT_Zu73X4GfUykVwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack