๐บ๐ธ
TPI-Abuse
2026-06-20 15:49:46
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 194.104.8.106 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 194.104.8.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 11:49:39.105126 2026] [security2:error] [pid 12684:tid 12697] [client 194.104.8.106:55263] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||earthtravel.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "earthtravel.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aja2kwEHxKmjp4YEhBT52wAAAAs"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 17:47:23
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 194.104.8.106 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 194.104.8.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 13:47:18.953371 2026] [security2:error] [pid 30315:tid 30315] [client 194.104.8.106:60249] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sinsky.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sinsky.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ajWAplePnd2PJVrEdy6AgQAAAAo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
kjaerulff
2026-05-10 13:46:06
(1 month ago)
Failed Wordpress login using wp-login.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-02 20:47:32
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 194.104.8.106 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 194.104.8.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 16:47:27.573446 2026] [security2:error] [pid 25899:tid 25899] [client 194.104.8.106:47051] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gisur.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gisur.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ac7V31NEQX9RuC7vPZBlUwAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-26 09:22:17
(6 months ago)
wordpress-trap
Web App Attack
Anonymous
2025-10-05 10:05:46
(8 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฉ๐ช
Packets-Decreaser.NET
2025-09-24 11:16:39
(9 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐จ๐ฟ
lp
2025-08-28 19:52:03
(9 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 194.104.8.106
2025-08-28T21:12:01+02: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 194.104.8.106
2025-08-28T21:12:01+02:00 vpn Access-Reject 'bitches' station: 194.104.8.106 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐จ๐ฟ
lp
2025-08-13 19:51:15
(10 months ago)
Unauthorized VPN login attempts: 2 attempts were recorded from 194.104.8.106
2025-08-13T20:56:38+02: ...
show more
Unauthorized VPN login attempts: 2 attempts were recorded from 194.104.8.106
2025-08-13T20:56:38+02:00 vpn Access-Reject 'pnelson' station: 194.104.8.106 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2025-08-13T20:56:49+02:00 vpn Access-Reject 'cmoore' station: 194.104.8.106 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-09 23:35:53
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 194.104.8.106 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 194.104.8.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 09 19:35:49.193154 2025] [security2:error] [pid 19105:tid 19144] [client 194.104.8.106:41329] [client 194.104.8.106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mindgardens.com"] [uri "/.env"] [unique_id "Z84l1Uhesp8fxZ13glIJwQAAABc"], referer: https://tasamm.com/about/mmm172.html
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-02-17 04:15:03
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2024-10-16 02:45:28
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
ph
2024-06-02 19:20:03
(2 years ago)
Bad web bot attempting to run wp-login.php on non-WP site
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
SCHAPPY
2023-07-26 19:34:59
(2 years ago)
IP was involved in L7 DDoS attack.
DDoS Attack
๐บ๐ธ
WhiteFireOCN1
2023-05-07 20:41:53
(3 years ago)
Targeted credential stuffing attack, observed 2023-05-05T23:50:31. Part of an attack that included 2 ...
show more
Targeted credential stuffing attack, observed 2023-05-05T23:50:31. Part of an attack that included 204 logins from 194 IPs. Likely being used as a proxy/tor exit node.
show less
Hacking
Brute-Force
Exploited Host