🇨🇿
Countryman
2026-09-14 00:10:01
(15 hours ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
🇨🇿
lp
2026-09-11 06:22:36
(3 days ago)
Unauthorized VPN login attempts: 2 attempts were recorded from 216.40.75.104
2026-09-11T07:47:13+02: ...
show more
Unauthorized VPN login attempts: 2 attempts were recorded from 216.40.75.104
2026-09-11T07:47:13+02:00 vpn Access-Reject 'temporal' station: 216.40.75.104 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-11T07:48:43+02:00 vpn Access-Reject 'iztapalapa' station: 216.40.75.104 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
🇨🇿
lp
2026-09-09 03:22:15
(5 days ago)
Unauthorized VPN login attempts: 3 attempts were recorded from 216.40.75.104
2026-09-09T04:06:27+02: ...
show more
Unauthorized VPN login attempts: 3 attempts were recorded from 216.40.75.104
2026-09-09T04:06:27+02:00 vpn Access-Reject 'altus1' station: 216.40.75.104 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-09T04:07:49+02:00 vpn Access-Reject 'airboss' station: 216.40.75.104 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-09T04:09:12+02:00 vpn Access-Reject 'sbd' station: 216.40.75.104 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
🇸🇪
OnTheEdge
2026-09-08 13:06:00
(6 days ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
🇺🇸
www.winos.me
2026-09-06 18:02:56
(1 week ago)
Scanning for sensitive files/paths: /wp-login.php
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-05-22 11:47:06
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 216.40.75.104 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.40.75.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 07:47:03.533747 2026] [security2:error] [pid 11687:tid 11687] [client 216.40.75.104:62045] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.bak" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ohanameetup.party"] [uri "/wp-config.bak"] [unique_id "ahBCNxmOFJbv8eymQT4_GgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-22 11:05:49
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 216.40.75.104 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.40.75.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 07:05:44.195597 2026] [security2:error] [pid 3726:tid 3726] [client 216.40.75.104:44597] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dceabronwilliams.com"] [uri "/.wp-config.php.swp"] [unique_id "ahA4iHkPqgam5gj-lXZEPQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-21 22:26:25
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 216.40.75.104 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.40.75.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 18:26:20.514523 2026] [security2:error] [pid 31829:tid 31829] [client 216.40.75.104:46769] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drdot.xyz"] [uri "/wp-config.php~"] [unique_id "ag-GjMAHZwomeVjYt9Pr8AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-05-21 22:05:41
(3 months ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-05-20 18:00:56
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 216.40.75.104 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.40.75.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 14:00:50.887923 2026] [security2:error] [pid 7434:tid 7434] [client 216.40.75.104:63179] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cms2020.com"] [uri "/wp-config.php.bak"] [unique_id "ag320qwWMJmC5PtetDBlsQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-20 14:50:40
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 216.40.75.104 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.40.75.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 10:50:32.280543 2026] [security2:error] [pid 16055:tid 16055] [client 216.40.75.104:18999] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "coolcustomweddingproducts.com"] [uri "/.wp-config.php.swp"] [unique_id "ag3KOOfpMZrje-IK7_U1swAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
paissangroup
2026-05-17 21:47:24
(3 months ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-05-02 14:22:42
(4 months ago)
Aggressive web scan
Web App Attack
🇫🇮
stinpriza
2026-04-14 19:28:41
(4 months ago)
Web App Attack
Web App Attack
🇺🇸
TPI-Abuse
2026-02-25 07:01:24
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 216.40.75.104 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 216.40.75.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 25 02:01:19.444551 2026] [security2:error] [pid 30943:tid 30943] [client 216.40.75.104:42475] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gonzalez.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gonzalez.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aZ6eP92gQMNPAb2w7iTg6wAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack