๐ซ๐ท
dynamix
2026-08-11 13:04:00
(2 weeks ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 19:33:33
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 77.220.195.253 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 77.220.195.253 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 15:33:26.752004 2026] [security2:error] [pid 2959:tid 2959] [client 77.220.195.253:41597] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kingstoneproperties.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kingstoneproperties.com"] [uri "/[email protected] "] [unique_id "ajGlBm5-U7bu2eVqsk6C9gAAAAw"], referer: https://www.facebook.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
SSH-Admin
2026-02-07 17:12:28
(6 months ago)
Probing for Exploits
Exploited Host
Web App Attack
๐ซ๐ท
masterguru
2026-01-07 04:25:11
(7 months ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 77.220.195.253 (US/United States/-): 1 in the ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 77.220.195.253 (US/United States/-): 1 in the last 3600 secs (0-195)
show less
Hacking
๐จ๐ฆ
SSH-Admin
2025-12-27 13:45:08
(8 months ago)
Probing for Exploits
Exploited Host
Web App Attack
๐จ๐ฟ
lp
2025-08-28 19:52:10
(1 year ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 77.220.195.253
2025-08-28T21:11:30+02 ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 77.220.195.253
2025-08-28T21:11:30+02:00 vpn Access-Reject 'carlos' station: 77.220.195.253 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
Anonymous
2025-05-26 08:55:21
(1 year ago)
Failed Wordpress Logins
Web App Attack
Anonymous
2025-04-07 13:10:24
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-03-28 13:10:43
(1 year ago)
This IP was involved in an brute force and password spray attack on 2025/03/28 08:03:58
Port Scan
Brute-Force
Exploited Host
Web App Attack
๐จ๐ฆ
wil.com
2025-03-28 08:32:53
(1 year ago)
GlobalProtect login attempts with user TDALTON.
VPN IP
Brute-Force
๐จ๐ฟ
lp
2025-03-15 02:53:43
(1 year ago)
Unauthorized VPN login attempts: 2 attempts were recorded from 77.220.195.253
2025-03-15T02:34:27+01 ...
show more
Unauthorized VPN login attempts: 2 attempts were recorded from 77.220.195.253
2025-03-15T02:34:27+01:00 vpn Access-Reject 'sound' station: 77.220.195.253 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2025-03-15T02:36:29+01:00 vpn Access-Reject 'tinman' station: 77.220.195.253 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-09 23:58:39
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 77.220.195.253 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 77.220.195.253 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 09 19:58:33.387423 2025] [security2:error] [pid 2772146:tid 2772146] [client 77.220.195.253:18255] [client 77.220.195.253] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mobileonlinecasinos.co"] [uri "/.env"] [unique_id "Z84rKQav0hOBbpi3OOp8VgAAAA0"], referer: https://tasamm.com/about/mmm180.html
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-09 19:12:20
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 77.220.195.253 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 77.220.195.253 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 09 14:12:12.996168 2025] [security2:error] [pid 22845:tid 22845] [client 77.220.195.253:51831] [client 77.220.195.253] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alacabine.mediterraneepassion.com"] [uri "/.env"] [unique_id "Z6j-DCYLPrwSWsS3u2FSTAAAAA8"], referer: https://a00035.tiiny.site/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
sefinek.net
2024-08-31 00:32:50
(2 years ago)
IP 77.220.195.253 [RU] triggered Cloudflare WAF (firewallCustom).
Action taken: CHALLENGE
ASN: 26548 ...
show more
IP 77.220.195.253 [RU] triggered Cloudflare WAF (firewallCustom).
Action taken: CHALLENGE
ASN: 26548 (PUREVOLTAGE-INC)
Protocol: HTTP/2 (method GET)
Domain: sefinek.net
Endpoint: /favicon.ico
Timestamp: 2024-08-30T14:53:16Z
Ray ID: 8bb59bffdd02c383
Rule ID: cc5e7a6277d447eca9c1818934ba65c8
User agent: Mozilla/5.0 (Linux; Android 8.1; K1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.113 Mobile Safari/537.36
Report generated by Node-Cloudflare-WAF-AbuseIPDB (https://github.com/sefinek24/Node-Cloudflare-WAF-AbuseIPDB)
show less
Bad Web Bot
๐ฆ๐ท
Cerbero
2024-08-24 12:17:00
(2 years ago)
WordPress.REST.API.Username.Enumeration.Information.Disclosure - /wp-json/wp/v2/users
Port Scan
Brute-Force
Web App Attack