Anonymous
2026-08-21 15:24:34
(2 days ago)
Multiple failed login attemps RDS-Web-Access-Server
Brute-Force
Web App Attack
๐บ๐ธ
kosada.com
2026-08-19 14:27:51
(4 days ago)
Web vulnerability probing: /wp-json/wp/v2/users
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 18:28:47
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 157.22.16.190 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.16.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 14:28:37.976123 2026] [security2:error] [pid 3040714:tid 3040714] [client 157.22.16.190:47475] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mdsshop.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mdsshop.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anYj1cPGqwQgtFD2LhhbVQAAADI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 07:19:00
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 157.22.16.190 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.16.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 03:18:54.548073 2026] [security2:error] [pid 25046:tid 25046] [client 157.22.16.190:46855] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jolankagroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jolankagroup.com"] [uri "/wp-json/wp/v2/users"] [unique_id "al8dXlKIwkGNchSZEq1Q1QAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
librebit
2026-07-15 14:39:36
(1 month ago)
Brute force
Brute-Force
๐ซ๐ท
Tilellit.PRO
2026-06-29 10:32:41
(1 month ago)
Fail2Ban banned 157.22.16.190 for security violations in jail wp-armour. Log: 2026/06/29 10:32:40 [e ...
show more
Fail2Ban banned 157.22.16.190 for security violations in jail wp-armour. Log: 2026/06/29 10:32:40 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 157.22.16.190 | Target: wplogin" , client: 157.22.16.190, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ซ๐ท
Tilellit.PRO
2026-06-28 08:59:50
(1 month ago)
Fail2Ban banned 157.22.16.190 for security violations in jail wp-armour. Log: 2026/06/28 08:59:50 [e ...
show more
Fail2Ban banned 157.22.16.190 for security violations in jail wp-armour. Log: 2026/06/28 08:59:50 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 157.22.16.190 | Target: wplogin" , client: 157.22.16.190, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐บ๐ธ
TPI-Abuse
2026-06-27 20:49:04
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 157.22.16.190 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.16.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 16:49:00.590762 2026] [security2:error] [pid 10965:tid 10965] [client 157.22.16.190:63587] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||szeliga.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "szeliga.com"] [uri "/wp-json/wp/v2/users"] [unique_id "akA3PN-bKOmX93nwiqSbwAAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 00:19:11
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 157.22.16.190 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.16.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 20:19:07.486635 2026] [security2:error] [pid 15889:tid 15966] [client 157.22.16.190:23885] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rcorbet.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rcorbet.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ajXcey9D62sLQBBnBVzMYgAAAEo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 00:03:00
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 157.22.16.190 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.16.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 20:02:55.153179 2026] [security2:error] [pid 1121:tid 1121] [client 157.22.16.190:32457] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||agrisea.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "agrisea.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ajXYr3L0R7NjYKpO6BmscQAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
kjaerulff
2026-03-11 14:23:15
(5 months ago)
Failed Wordpress login using wp-login.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-06 17:13:35
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 157.22.16.190 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.16.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 06 12:13:30.829688 2026] [security2:error] [pid 15212:tid 15231] [client 157.22.16.190:65313] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||paidsearchconsulting.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "paidsearchconsulting.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aasLOqQnUz3_YHbkr1gJCQAAABE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack