Anonymous
2026-06-13 11:39:00
(1 week ago)
[osotir.org] httpd-login-spray-site: sites=agonistes.gr; logs=/var/log/httpd/domains/agonistes.gr.lo ...
show more
[osotir.org] httpd-login-spray-site: sites=agonistes.gr; logs=/var/log/httpd/domains/agonistes.gr.log; samples=site_wide=true | distinct_ips=57 | /wp-login.php?wp_lang=en_US
show less
Hacking
Web App Attack
๐ซ๐ฎ
inlink.ltd
2026-05-28 00:13:36
(3 weeks ago)
Known malicious PHP file or CMS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-30 10:17:21
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 77.220.194.254 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 77.220.194.254 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 06:17:16.704020 2026] [security2:error] [pid 12874:tid 12874] [client 77.220.194.254:37965] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sbodyworkbychris.com"] [uri "/.env"] [unique_id "afMsLIqmRRZXr1lEdBwiVQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-28 03:11:39
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 77.220.194.254 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 77.220.194.254 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 27 23:11:35.428228 2026] [security2:error] [pid 5806:tid 5806] [client 77.220.194.254:38517] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tecnologiadelagua.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tecnologiadelagua.com"] [uri "/s3cmd.ini"] [unique_id "afAlZ0HdR3ynWCrXOO0m5AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-27 11:04:52
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 77.220.194.254 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 77.220.194.254 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 27 07:04:48.369392 2026] [security2:error] [pid 31689:tid 31695] [client 77.220.194.254:19005] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.htpsocal.com.ceol.us|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.htpsocal.com.ceol.us"] [uri "/s3cmd.ini"] [unique_id "ae9C0K88ut9lQ7UFnF-GkgAAAMQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-26 13:13:35
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 77.220.194.254 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 77.220.194.254 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 09:13:32.692743 2026] [security2:error] [pid 8039:tid 8039] [client 77.220.194.254:32229] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.dcsteven.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.dcsteven.com"] [uri "/s3cmd.ini"] [unique_id "ae4PfMm82K5moTEv485dkQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-26 12:12:17
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 77.220.194.254 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 77.220.194.254 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 08:12:10.406905 2026] [security2:error] [pid 21418:tid 21418] [client 77.220.194.254:30669] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.anbrusgoldens.anbruskitchens.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.anbrusgoldens.anbruskitchens.com"] [uri "/s3cmd.ini"] [unique_id "ae4BGtKlpRTEJkYEmZy2iAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
GreekCity
2026-04-05 10:58:34
(2 months ago)
bad-bot hacking for vulnerable links.
Hacking
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-03-30 15:43:53
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 77.220.194.254 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 77.220.194.254 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 11:43:47.419593 2026] [security2:error] [pid 13992:tid 13992] [client 77.220.194.254:41583] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||digifonics.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "digifonics.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acqaM8XSSpavIRUT3e4DywAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-29 17:23:17
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 77.220.194.254 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 77.220.194.254 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 29 13:23:13.515057 2026] [security2:error] [pid 2555:tid 2555] [client 77.220.194.254:50623] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||srossi.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "srossi.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aclgAXymh05K_Pik0NuymAAAAAM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-28 06:23:33
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 77.220.194.254 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 77.220.194.254 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 28 02:23:29.205520 2026] [security2:error] [pid 23003:tid 23003] [client 77.220.194.254:36725] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||silsby.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "silsby.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acdz4ep8QmurHqJN_xERaQAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
Cognisant-Security
2026-03-16 12:12:00
(3 months ago)
Attempts to login WordPress using invalid User Credentials
Web App Attack
Hacking
๐บ๐ธ
octageeks.com
2026-03-15 04:08:51
(3 months ago)
Wordpress malicious attack:[octawpauthor]
Web App Attack
๐จ๐ฟ
lp
2025-07-02 13:52:38
(11 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 77.220.194.254
2025-07-02T15:06:48+02 ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 77.220.194.254
2025-07-02T15:06:48+02:00 vpn Access-Reject 'r.wright' station: 77.220.194.254 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐จ๐ฟ
lp
2025-07-02 00:24:50
(11 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 77.220.194.254
2025-07-02T01:43:49+02 ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 77.220.194.254
2025-07-02T01:43:49+02:00 vpn Access-Reject 'd.smith' station: 77.220.194.254 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack