🇨🇿
Countryman
2026-09-12 00:10:01
(1 day ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
🇨🇿
lp
2026-09-11 09:23:11
(1 day ago)
Unauthorized VPN login attempts: 2 attempts were recorded from 62.204.49.237
2026-09-11T10:53:05+02: ...
show more
Unauthorized VPN login attempts: 2 attempts were recorded from 62.204.49.237
2026-09-11T10:53:05+02:00 vpn Access-Reject 'taisunwell' station: 62.204.49.237 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-11T10:54:34+02:00 vpn Access-Reject 'sbyd5c88' station: 62.204.49.237 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
🇨🇿
lp
2026-09-10 09:23:10
(2 days ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 62.204.49.237
2026-09-10T10:37:14+02: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 62.204.49.237
2026-09-10T10:37:14+02:00 vpn Access-Reject '63757' station: 62.204.49.237 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
🇨🇭
SOC [GOLINE SA]
2026-09-09 00:00:48
(4 days ago)
[RoutePulse | 2026-09-09T00:00:47Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 62.204.49.2 ...
show more
[RoutePulse | 2026-09-09T00:00:47Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 62.204.49.237
EVIDENCE: Shunned on the Cisco FTD VPN gateway — Cisco VPN RA Brute force on Cisco FTDv — distributed attack (4 attempts/15min) — shun on the VPN gateway
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇳🇿
Tripwire
2026-07-15 22:38:57
(1 month ago)
Wordpress login attempts
Brute-Force
Web App Attack
🇨🇿
ptlab
2026-05-28 04:45:31
(3 months ago)
Detected wp_admin attack from WP-host.
Hacking
Web App Attack
🇬🇧
Oakley
2026-05-26 09:20:10
(3 months ago)
(mod_security) mod_security (id:900178) triggered by 62.204.49.237 (US/United States/-): 5 in the la ...
show more
(mod_security) mod_security (id:900178) triggered by 62.204.49.237 (US/United States/-): 5 in the last 900 secs
show less
Web App Attack
Hacking
🇱🇻
garmtech.com
2026-05-23 22:34:29
(3 months ago)
IM360 WAF: Old style account creation and modification in Joomla! MV:registration
Web App Attack
🇺🇸
TPI-Abuse
2026-04-26 09:51:42
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 62.204.49.237 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 62.204.49.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 05:51:34.421426 2026] [security2:error] [pid 3373:tid 3489] [client 62.204.49.237:40877] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||paidsearchconsulting.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "paidsearchconsulting.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ae3gJs6ctN7o9b5Zfjc2UAAAABE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-25 19:55:16
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 62.204.49.237 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 62.204.49.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 25 15:55:11.496495 2026] [security2:error] [pid 4414:tid 4414] [client 62.204.49.237:62381] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||babylontravelone.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "babylontravelone.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ae0cH-IsrY-WDd0p_CDYdgAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
oralunal
2026-03-31 05:42:23
(5 months ago)
IP banned by Fail2Ban in jail ente-suss ente.com-ssl_log mvfnds
...
Bad Web Bot
Web App Attack
🇫🇷
mrcrassi
2026-02-05 22:39:40
(7 months ago)
Triggered Cloudflare WAF (firewallCustom) from FI.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST meth ...
show more
Triggered Cloudflare WAF (firewallCustom) from FI.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /wp-login.php
UA: curl/8.6.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇨🇦
polycoda
2026-01-10 13:27:49
(8 months ago)
📄 Probes for wp-login.php and other inexistent URLs
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-01-08 16:30:56
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 62.204.49.237 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 62.204.49.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 08 11:30:52.765962 2026] [security2:error] [pid 30989:tid 30989] [client 62.204.49.237:13041] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||admin.turedinmobiliaria.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "admin.turedinmobiliaria.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aV_bvDIXTog7AyM0NFhVdgAAAAU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-29 19:53:31
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 62.204.49.237 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 62.204.49.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 29 14:53:23.882014 2025] [security2:error] [pid 13289:tid 13289] [client 62.204.49.237:57087] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||danharrisphotoart.com|F|2"] [data ".dpreview.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "danharrisphotoart.com"] [uri "/www.dpreview.com"] [unique_id "aStPM-XTTuQ25We9USq_NgAAAA0"], referer: https://danharrisphotoart.com/checklist.html
show less
Brute-Force
Bad Web Bot
Web App Attack