๐บ๐ธ
ThreatsIntelz
2026-08-27 22:15:54
(3 weeks ago)
SSL-VPN brute-force / password-guessing attempts against FortiGate SSLVPN. Observed source subnet 19 ...
show more
SSL-VPN brute-force / password-guessing attempts against FortiGate SSLVPN. Observed source subnet 194.99.25.0/24 (owner: FINEGROUPSERVERS-LEASE); 2 attempts above threshold.
show less
Brute-Force
SSH
๐บ๐ธ
mawan
2026-08-24 11:41:04
(4 weeks ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 13:42:26
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 194.99.25.158 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 194.99.25.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 09:42:19.188535 2026] [security2:error] [pid 705550:tid 705550] [client 194.99.25.158:55649] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.caferutadelaseda.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.caferutadelaseda.com"] [uri "/mail:[email protected] "] [unique_id "anXgu_CK2F8Q30itz4aYiAAAAA4"], referer: https://www.caferutadelaseda.com/contacto.php
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-01-05 02:56:16
(8 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐จ๐ฟ
lp
2025-12-03 16:22:00
(9 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 194.99.25.158
2025-12-03T17:03:04+01: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 194.99.25.158
2025-12-03T17:03:04+01:00 vpn Access-Reject 'test1' station: 194.99.25.158 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐จ๐ฟ
lp
2025-12-01 22:25:08
(9 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 194.99.25.158
2025-12-01T22:22:23+01: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 194.99.25.158
2025-12-01T22:22:23+01:00 vpn Access-Reject 'pc' station: 194.99.25.158 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-14 04:42:12
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 194.99.25.158 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.25.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 14 00:42:04.623443 2025] [security2:error] [pid 792290:tid 800833] [client 194.99.25.158:50227] [client 194.99.25.158] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rockabyecotons.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rockabyecotons.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aCQfHCv6HAyjItfaw4depQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-12 19:22:25
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 194.99.25.158 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.25.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 12 15:22:18.564308 2025] [security2:error] [pid 861986:tid 861986] [client 194.99.25.158:35961] [client 194.99.25.158] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ismaelcavazos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ismaelcavazos.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aCJKarI6PbQmfpDifpU2ugAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Anonymous
2025-02-28 16:00:00
(1 year ago)
Brute force attack detected from 194.99.25.158
DDoS Attack
Brute-Force
Web App Attack
Anonymous
2024-12-20 02:48:02
(1 year ago)
Attempted brute force login to web vpn
Hacking
Brute-Force
Anonymous
2024-11-14 12:59:02
(1 year ago)
Brute force attempt to access portal using various usernames
Brute-Force
๐ฉ๐ช
css672
2024-10-17 09:19:35
(1 year ago)
Credential brute-force attacks on webpage logins [18,21].
remote_addr: 194.99.25.158, error_code: 76 ...
show more
Credential brute-force attacks on webpage logins [18,21].
remote_addr: 194.99.25.158, error_code: 76
username: annashevchuk12ukr-net
password: [censored]
fruad_score: 0, abuseConfidenceScore: 0
css672: V.4.10.16.1436
show less
Brute-Force
Web App Attack
Anonymous
2024-10-10 07:45:46
(1 year ago)
Automatic report - Vulnerability scan
/RDWeb/Pages/en-US/login.aspx
Web App Attack
๐จ๐ฆ
wil.com
2024-09-23 12:41:28
(2 years ago)
GlobalProtect login attempts with user ubaxter.
VPN IP
Brute-Force
Anonymous
2024-09-10 07:33:31
(2 years ago)
VPN Authentication Brute Force
Brute-Force