๐น๐ท
neron
2026-08-19 18:26:20
(5 days ago)
CrowdSec blocked: tcp:scan detected via OPNsense firewall
Hacking
Web App Attack
๐บ๐ธ
dealpickeal
2026-08-10 13:56:24
(2 weeks ago)
Unauthorized authentication attempt against our Microsoft Entra ID tenant.
Source IP: 91.217.249. ...
show more
Unauthorized authentication attempt against our Microsoft Entra ID tenant.
Source IP: 91.217.249.44
Application: Azure Active Directory PowerShell
Event time (UTC): 8/9/2026 1:18
Error code: 50053
Result: Sign-in was blocked because it came from an IP address with malicious activity
Destination service: login.microsoftonline.com
Destination port: TCP 443
Activity is consistent with automated password spraying, credential stuffing, or brute-force authentication attempts.
show less
Brute-Force
Hacking
๐น๐ท
neron
2026-07-26 19:50:51
(4 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 10:58:36
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 91.217.249.44 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 91.217.249.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 06:58:29.955532 2026] [security2:error] [pid 3536605:tid 3536605] [client 91.217.249.44:21375] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grmvrr.com"] [uri "/wp-includes/wp-config.php"] [unique_id "amXoVfM2fWq8tratxtTvqAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
neron
2026-07-25 08:27:07
(4 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐ซ๐ท
Octopuce
2026-07-25 06:27:13
(4 weeks ago)
Aggressive web search of vulnerable pages: /wp-admin/js/ /wp-content/themes/news-portal/sitebar.php ...
show more
Aggressive web search of vulnerable pages: /wp-admin/js/ /wp-content/themes/news-portal/sitebar.php /wp-content/admin.php /about.php /wp-conten ...
show less
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-15 01:38:19
(1 month ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ณ๐ฑ
Site.eu
2026-07-06 19:08:12
(1 month ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ซ๐ท
dynamix
2026-07-05 22:02:26
(1 month ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-05 16:04:15
(1 month ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ฎ๐ฉ
sockominfo
2026-06-29 21:00:52
(1 month ago)
Zimbra: Login failures from malicious IP: 91.217.249.44. Threat Score: 6.6/10 (HIGH). Confidence: 40 ...
show more
Zimbra: Login failures from malicious IP: 91.217.249.44. Threat Score: 6.6/10 (HIGH). Confidence: 40%. CVSS v3.1: 4.6/10 (Medium). CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L. Bayesian Probability: 87%. MITRE ATT&CK: T1083 (File and Directory Discovery). Tactic: TA0001. Freshness: Very Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฌ๐ท
setupgr
2026-06-24 12:29:24
(2 months ago)
(mod_security) mod_security (id:1000001) triggered by 91.217.249.44 (DE/Germany/Hesse/Frankfurt am M ...
show more
(mod_security) mod_security (id:1000001) triggered by 91.217.249.44 (DE/Germany/Hesse/Frankfurt am Main/-/[AS206092 SECFIREWALLAS]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jun 24 15:29:21.973541 2026] [security2:error] [pid 63968:tid 64002] [client 91.217.249.44:25957] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/1.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "93"] [id "1000001"] [msg "Bad file blocked: /1.php"] [severity "CRITICAL"] [tag "security"] [hostname "pankoskal.gr"] [uri "/1.php"] [unique_id "ajvNoT_tjI8vsxY4WxPlvgAAAIc"]
show less
Port Scan
Anonymous
2026-06-23 02:29:03
(2 months ago)
91.217.249.44 - - [23/Jun/2026:04:28:54 +0200] "GET /jazz/?utm_source=cvajazz.nl&utm_medium=referral ...
show more
91.217.249.44 - - [23/Jun/2026:04:28:54 +0200] "GET /jazz/?utm_source=cvajazz.nl&utm_medium=referral&utm_campaign=redirects HTTP/1.1" 200 19474 "https://cvajazz.nl/xmlrpc.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 OPR/114.0.0.0"
91.217.249.44 - - [23/Jun/2026:04:28:55 +0200] "GET /klassiek/?utm_source=cvaklassiek.nl&utm_medium=referral&utm_campaign=redirects HTTP/1.1" 200 12873 "https://cvaklassiek.nl/xmlrpc.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 OPR/114.0.0.0"
91.217.249.44 - - [23/Jun/2026:04:28:56 +0200] "GET /jazz/?utm_source=cvajazz.nl&utm_medium=referral&utm_campaign=redirects HTTP/1.1" 200 12399 "https://cvajazz.nl/xmlrpc.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
91.217.249.44 - - [23/Jun/2026:04:28:57 +0200] "GET /jjc/?utm_source=juniorjazzcollege.nl&utm_medium=referral&u
...
show less
Brute-Force
๐ซ๐ท
ELYAZ
2026-06-23 01:57:01
(2 months ago)
(wordpress) Failed wordpress login from 91.217.249.44 (DE/Germany/-): (CF_ENABLE)
Brute-Force
๐บ๐ฆ
URAN Publishing Service
2026-06-15 08:45:15
(2 months ago)
91.217.249.44 - - [15/Jun/2026:11:45:14 +0300] "GET /amax.php HTTP/1.1" 404 711 "-" "Mozilla/5.0 (Wi ...
show more
91.217.249.44 - - [15/Jun/2026:11:45:14 +0300] "GET /amax.php HTTP/1.1" 404 711 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0"
...
show less
Web App Attack