🇨🇿
lp
2026-09-12 09:23:36
(13 hours ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 94.154.127.235
2026-09-12T11:03:55+02 ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 94.154.127.235
2026-09-12T11:03:55+02:00 vpn Access-Reject 'aahrens' station: 94.154.127.235 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
🇸🇪
OnTheEdge
2026-09-09 02:36:03
(3 days ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-11 08:47:37
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 94.154.127.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 94.154.127.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 04:47:29.376411 2026] [security2:error] [pid 1128485:tid 1128485] [client 94.154.127.235:62161] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rimbey.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rimbey.us"] [uri "/wp-json/wp/v2/users"] [unique_id "anrhoWzuKfYB67jEBAPfqQAAAA4"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-04 13:18:01
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 94.154.127.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 94.154.127.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 04 09:17:57.427704 2026] [security2:error] [pid 1275737:tid 1275737] [client 94.154.127.235:27741] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cottrillcyclodyne.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cottrillcyclodyne.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anHmhY4_rehmj6oDo13e3AAAABk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-03 22:51:04
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 94.154.127.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 94.154.127.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 18:51:00.384471 2026] [security2:error] [pid 742167:tid 742179] [client 94.154.127.235:21455] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||behaviorhealth.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "behaviorhealth.org"] [uri "/wp-json/wp/v2/users"] [unique_id "anEbVJTOT-AXfhwjPhoRYgAAAEo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-01 04:53:20
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 94.154.127.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 94.154.127.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 00:53:15.289599 2026] [security2:error] [pid 1430:tid 1430] [client 94.154.127.235:21789] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||hvacmechanalysis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "hvacmechanalysis.com"] [uri "/wp-json/wp/v2/users"] [unique_id "akSdO4hgwAWop7Ojizqi_AAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
oncord
2026-07-01 03:04:21
(2 months ago)
Form spam
Web Spam
🇨🇭
backslash
2026-06-03 14:27:00
(3 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
🇺🇸
TPI-Abuse
2026-05-14 09:23:15
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 94.154.127.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 94.154.127.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 05:23:10.291668 2026] [security2:error] [pid 929:tid 929] [client 94.154.127.235:27679] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sahinozalit.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sahinozalit.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agWUfgLDlwp5ZsNGFuAXWwAAAAo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-09-02 19:30:49
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-07-31 13:58:03
(1 year ago)
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.07.31 is noted in report tim ...
show more
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.07.31 is noted in report timestamp
show less
Hacking
Brute-Force
🇲🇽
licjperezl
2025-06-19 19:46:33
(1 year ago)
Ataque de diccionario o DDoS en nuestros servicios en linea
Brute-Force
🇨🇦
wil.com
2025-06-08 17:59:03
(1 year ago)
GlobalProtect login attempts with user bday.
VPN IP
Brute-Force
Anonymous
2025-02-23 07:52:17
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-02-16 18:26:42
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH