๐จ๐ฟ
Countryman
2026-09-13 00:10:01
(2 weeks ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
๐จ๐ฟ
Countryman
2026-09-12 00:10:01
(2 weeks ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
๐จ๐ญ
SOC [GOLINE SA]
2026-09-10 22:54:36
(2 weeks ago)
[RoutePulse | 2026-09-10T22:54:36Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 77.220.194. ...
show more
[RoutePulse | 2026-09-10T22:54:36Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 77.220.194.191
EVIDENCE: Shunned on the Cisco FTD VPN gateway โ Cisco VPN RA Brute force on Cisco FTDv โ shunned by the FTD's own threat detection (adopted by RoutePulse: TTL, strike, diary)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
๐ฉ๐ช
webanyone
2026-08-11 19:16:46
(1 month ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-25 15:12:31
(5 months ago)
(mod_security) mod_security (id:210350) triggered by 77.220.194.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 77.220.194.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 25 11:12:23.895560 2026] [security2:error] [pid 26210:tid 26210] [client 77.220.194.191:13467] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||bordalo-es.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "bordalo-es.com"] [uri "/"] [unique_id "aezZ19_LdWgcKA_Dwj6_KQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
gurnip
2026-03-05 11:21:36
(6 months ago)
Vulnerability probe of page /wp-login.php, not found on server.
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-02-22 10:55:02
(7 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-24 09:52:47
(1 year ago)
(mod_security) mod_security (id:211120) triggered by 77.220.194.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211120) triggered by 77.220.194.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 24 05:52:41.040129 2025] [security2:error] [pid 3617834:tid 3617834] [client 77.220.194.191:13187] [client 77.220.194.191] ModSecurity: Access denied with code 403 (phase 2). Match of "endsWith /modules/paypal/express_checkout/payment.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "29"] [id "211120"] [rev "12"] [msg "COMODO WAF: Remote File Inclusion Attack||beirutbazar.com|F|2"] [data "Matched Data: http://adguard.digital/payload/index.php? found within REQUEST_FILENAME: /wp-content/plugins/wp-super-cache/js/cache-loader.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "beirutbazar.com"] [uri "/wp-content/plugins/wp-super-cache/js/cache-loader.php"] [unique_id "Z-EraX0-mlvCsDdOKD4yDwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-19 06:35:06
(1 year ago)
(mod_security) mod_security (id:211120) triggered by 77.220.194.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211120) triggered by 77.220.194.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 19 02:34:56.145659 2025] [security2:error] [pid 15466:tid 15466] [client 77.220.194.191:60693] [client 77.220.194.191] ModSecurity: Access denied with code 403 (phase 2). Match of "endsWith /modules/paypal/express_checkout/payment.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "29"] [id "211120"] [rev "12"] [msg "COMODO WAF: Remote File Inclusion Attack||ashleycroft.com|F|2"] [data "Matched Data: http://adguard.digital/payload/index.php? found within REQUEST_FILENAME: /wp-content/plugins/w3-total-cache/lib/w3/pager.class.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ashleycroft.com"] [uri "/wp-content/plugins/w3-total-cache/lib/W3/Pager.class.php"] [unique_id "Z9plkOyL_ahiz8fPsRogWQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-12 06:37:27
(1 year ago)
(mod_security) mod_security (id:211120) triggered by 77.220.194.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211120) triggered by 77.220.194.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 12 02:37:22.676185 2025] [security2:error] [pid 450046:tid 450046] [client 77.220.194.191:28003] [client 77.220.194.191] ModSecurity: Access denied with code 403 (phase 2). Match of "endsWith /modules/paypal/express_checkout/payment.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "29"] [id "211120"] [rev "12"] [msg "COMODO WAF: Remote File Inclusion Attack||aguirremoreno.com|F|2"] [data "Matched Data: http://adguard.digital/payload/index.php? found within REQUEST_FILENAME: /wp-content/plugins/all-in-one-seo-pack/classes/aiosp.class.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aguirremoreno.com"] [uri "/wp-content/plugins/all-in-one-seo-pack/classes/aiosp.class.php"] [unique_id "Z9Erot6kGz0yAm6jDOHs2wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-10 14:40:31
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 77.220.194.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 77.220.194.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 10 10:40:19.527169 2025] [security2:error] [pid 2472309:tid 2472309] [client 77.220.194.191:38101] [client 77.220.194.191] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "needtoorderprinting.com"] [uri "/.env"] [unique_id "Z87507xdyDkWXCFDLY06SQAAAA0"], referer: https://tasamm.com/about/mmm230.html
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-08 20:00:09
(1 year ago)
(mod_security) mod_security (id:211120) triggered by 77.220.194.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211120) triggered by 77.220.194.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 08 15:00:05.680235 2025] [security2:error] [pid 27176:tid 27176] [client 77.220.194.191:29547] [client 77.220.194.191] ModSecurity: Access denied with code 403 (phase 2). Match of "endsWith /modules/paypal/express_checkout/payment.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "29"] [id "211120"] [rev "12"] [msg "COMODO WAF: Remote File Inclusion Attack||495metro.com|F|2"] [data "Matched Data: http://adguard.digital/payload/index.php? found within REQUEST_FILENAME: /wp-content/plugins/w3-total-cache/lib/w3/pager.class.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "495metro.com"] [uri "/wp-content/plugins/w3-total-cache/lib/W3/Pager.class.php"] [unique_id "Z8yhxWpTB_OZOvjLX04MigAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-02-26 19:17:39
(1 year ago)
wordpress-trap
Web App Attack
๐บ๐ธ
Yawning Angel
2024-08-27 21:23:22
(2 years ago)
logdesc=SSL VPN login fail user=brod remip=77.220.194.191 reason=sslvpn_login_permission_denied
Hacking
Brute-Force
๐บ๐ธ
Yawning Angel
2024-08-07 10:07:33
(2 years ago)
msg=SSL user failed to logged in logdesc=SSL VPN login fail user=nlee remip=77.220.194.191 group=N/A ...
show more
msg=SSL user failed to logged in logdesc=SSL VPN login fail user=nlee remip=77.220.194.191 group=N/A tunnelid=0 tunneltype=ssl-web dst_host=N/A reason=sslvpn_login_permission_denied
show less
Hacking
Brute-Force