Anonymous
2026-09-28 14:11:15
(51 minutes ago)
Multiple failed login attemps RDS-Web-Access-Server
Brute-Force
Web App Attack
πͺπΈ
librebit
2026-09-27 15:48:20
(23 hours ago)
Brute force
Brute-Force
πͺπΈ
librebit
2026-09-25 15:43:25
(2 days ago)
Brute force
Brute-Force
π¨πΏ
Countryman
2026-09-14 00:10:01
(2 weeks ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
π¨πΏ
lp
2026-09-12 06:21:47
(2 weeks ago)
Unauthorized VPN login attempts: 3 attempts were recorded from 178.20.215.253
2026-09-12T07:26:01+02 ...
show more
Unauthorized VPN login attempts: 3 attempts were recorded from 178.20.215.253
2026-09-12T07:26:01+02:00 vpn Access-Reject 'cecile.cahen' station: 178.20.215.253 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-12T07:27:21+02:00 vpn Access-Reject 'claire.lausecker' station: 178.20.215.253 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-12T07:28:41+02:00 vpn Access-Reject 'diane.duche' station: 178.20.215.253 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
π¨πΏ
lp
2026-09-11 04:50:38
(2 weeks ago)
Unauthorized VPN login attempts: 4 attempts were recorded from 178.20.215.253
2026-09-11T06:33:39+02 ...
show more
Unauthorized VPN login attempts: 4 attempts were recorded from 178.20.215.253
2026-09-11T06:33:39+02:00 vpn Access-Reject 'sonia.introini' station: 178.20.215.253 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-11T06:35:07+02:00 vpn Access-Reject 'carmen.pantiru' station: 178.20.215.253 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-11T06:36:33+02:00 vpn Access-Reject 'augusto.buccomino' station: 178.20.215.253 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-11T06:37:59+02:00 vpn Access-Reject 'laura.busatto' station: 178.20.215.253 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
π³π±
Savvii
2026-05-27 19:59:12
(4 months ago)
20 attempts against mh_ha-misbehave-ban on sonic
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
oncord
2026-05-05 23:33:12
(4 months ago)
Form spam
Web Spam
πΊπΈ
TPI-Abuse
2026-01-22 14:24:21
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 178.20.215.253 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 178.20.215.253 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 09:24:17.730631 2026] [security2:error] [pid 14719:tid 14719] [client 178.20.215.253:56371] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tell-me-first.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tell-me-first.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aXIzETUcO0RVzmD75GUhJgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-07 10:03:46
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 178.20.215.253 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 178.20.215.253 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 07 05:03:41.347243 2026] [security2:error] [pid 10189:tid 10189] [client 178.20.215.253:16485] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||phuket-boatcharter.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "phuket-boatcharter.com"] [uri "/wp-login.php"] [unique_id "aV4vfZKzvCoLO0FUcW2WZgAAACA"], referer: http://phuket-boatcharter.com/blog/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-21 00:12:08
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 178.20.215.253 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 178.20.215.253 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 20 20:12:03.633687 2025] [security2:error] [pid 13370:tid 13370] [client 178.20.215.253:46121] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||staben.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "staben.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aM9C02dC6r_aVfNUMJTBrwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π·πΊ
sms.ru
2024-09-27 07:05:04
(2 years ago)
SMS pumping attack from foreign country
DDoS Attack