Anonymous
2026-10-05 17:25:16
(2 days ago)
SSH tarpit (endlessh) connection from 155.212.37.160
Brute-Force
SSH
๐บ๐ธ
nationaleventpros.com
2026-09-15 15:56:46
(3 weeks ago)
WordPress login attempt
Brute-Force
๐ซ๐ท
dynamix
2026-09-15 06:10:35
(3 weeks ago)
Multiple WAF Violations
Web App Attack
๐จ๐ฆ
DRI
2026-09-14 22:43:21
(3 weeks ago)
Web attack/Malicious activity detected
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-27 22:27:45
(1 month ago)
[28/Aug/2026:01:27:44 +0300] -- 155.212.37.160 Ban reason: User-Agent curl/
Bad Web Bot
Web App Attack
๐ซ๐ท
claude CALVET
2026-08-26 13:11:19
(1 month ago)
gee-Joomla Admin : try to force the door...
Hacking
๐ซ๐ท
claude CALVET
2026-08-19 18:42:45
(1 month ago)
gee-Joomla Admin : try to force the door...
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-23 04:29:32
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 155.212.37.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 155.212.37.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 00:29:27.702512 2026] [security2:error] [pid 1750278:tid 1750278] [client 155.212.37.160:14337] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pghsea.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pghsea.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amGYp4CmRKsNuFDPeKFV7QAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-06-28 09:35:26
(3 months ago)
Fail2Ban banned 155.212.37.160 for security violations in jail wp-armour. Log: 2026/06/28 09:35:25 [ ...
show more
Fail2Ban banned 155.212.37.160 for security violations in jail wp-armour. Log: 2026/06/28 09:35:25 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 155.212.37.160 | Target: wplogin" , client: 155.212.37.160, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ซ๐ท
Tilellit.PRO
2026-06-25 18:05:36
(3 months ago)
Fail2Ban banned 155.212.37.160 for security violations in jail wp-armour. Log: 2026/06/25 18:05:35 [ ...
show more
Fail2Ban banned 155.212.37.160 for security violations in jail wp-armour. Log: 2026/06/25 18:05:35 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 155.212.37.160 | Target: wplogin" , client: 155.212.37.160, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ฉ๐ช
ghostwarriors
2026-06-20 10:20:14
(3 months ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 16:40:41
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 155.212.37.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 155.212.37.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 12:40:35.437906 2026] [security2:error] [pid 13571:tid 13571] [client 155.212.37.160:42813] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||geckoturner.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "geckoturner.com"] [uri "/wp-json/wp/v2/users"] [unique_id "af4SA7A0Ep8Np13PyS_tegAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-04-27 00:06:00
(5 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
kosada.com
2026-03-21 02:59:18
(6 months ago)
Web vulnerability probing: /xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-17 23:21:05
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 155.212.37.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 155.212.37.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 17 19:20:57.476845 2026] [security2:error] [pid 30974:tid 30974] [client 155.212.37.160:28493] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||manaplas.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "manaplas.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abnh2c7G9vWKZi7np6iuPQAAAAo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack