๐บ๐ธ
agabeckov
2026-09-14 17:39:54
(2 days ago)
Fail2Ban detected brute-force attempt on Cisco Anyconnect
VPN IP
Brute-Force
๐จ๐ฟ
lp
2026-09-13 12:21:51
(4 days ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 170.168.99.19
2026-09-13T13:22:42+02: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 170.168.99.19
2026-09-13T13:22:42+02:00 vpn Access-Reject 'cynthia.vpn' station: 170.168.99.19 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐จ๐ฟ
Countryman
2026-09-13 00:10:01
(4 days ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
๐จ๐ฟ
Countryman
2026-09-12 00:10:01
(5 days ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
๐ช๐ธ
librebit
2026-07-12 03:57:48
(2 months ago)
Brute force
Brute-Force
๐ช๐ธ
librebit
2026-07-04 05:53:48
(2 months ago)
Brute force
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-03-31 11:05:37
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 170.168.99.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 170.168.99.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 07:05:29.117844 2026] [security2:error] [pid 5550:tid 5583] [client 170.168.99.19:41767] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rodela.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rodela.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acuqeVMuzCUw8jiRJBBWOAAAANE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-30 17:47:57
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 170.168.99.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 170.168.99.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 13:47:51.118678 2026] [security2:error] [pid 13584:tid 13584] [client 170.168.99.19:47569] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jiggaboojones.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jiggaboojones.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acq3Ry3H_i2y-qg0WW7MmAAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-03-25 03:53:54
(5 months ago)
Wordpress hacking attempt
Web App Attack
๐ง๐ช
voormedia
2026-03-17 05:38:47
(6 months ago)
Accessed trap at '/xmlrpc.php'
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-06 19:02:19
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 170.168.99.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 170.168.99.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 06 14:02:11.511184 2026] [security2:error] [pid 10508:tid 10508] [client 170.168.99.19:58791] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rockymtnfire.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rockymtnfire.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aasks_iHLdEhCRak5RH6VgAAAAg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-17 18:21:45
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 170.168.99.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 170.168.99.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 17 13:21:39.407907 2025] [security2:error] [pid 23257:tid 23285] [client 170.168.99.19:56497] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||mjkotob.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "mjkotob.com"] [uri "/"] [unique_id "aUL0s7h8LHuaNRHgJjE1JwAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack