๐บ๐ธ
Ben Schoolland
2026-09-27 14:21:18
(1 day ago)
Requested known WordPress backdoor/scanner-only paths. No legitimate use.
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-27 04:28:43
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 13:35:45
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 157.22.18.70 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.18.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 09:35:38.362679 2026] [security2:error] [pid 22560:tid 22560] [client 157.22.18.70:38141] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gonzalez.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gonzalez.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amykquw5y5TDjPogIz5e2wAAABM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-07-16 20:21:00
(2 months ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot
๐บ๐ธ
jfz-abuse
2026-07-15 17:57:23
(2 months ago)
fail2ban: apache-php-recon
...
Web App Attack
๐ฌ๐ท
setupgr
2026-07-07 19:39:32
(2 months ago)
(XMLRPC) WP XMLRPC Attack 157.22.18.70 (FR/France/รยle-de-France/Paris/-/[AS213954 -Reserved AS-]): ...
show more
(XMLRPC) WP XMLRPC Attack 157.22.18.70 (FR/France/รยle-de-France/Paris/-/[AS213954 -Reserved AS-]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 157.22.18.70 - - [07/Jul/2026:22:39:18 +0300] "POST /xmlrpc.php HTTP/1.1" 503 7308 "-" "curl/8.6.0"
show less
Port Scan
๐ซ๐ท
Tilellit.PRO
2026-06-28 06:54:03
(3 months ago)
Fail2Ban banned 157.22.18.70 for security violations in jail wp-armour. Log: 2026/06/28 06:54:02 [er ...
show more
Fail2Ban banned 157.22.18.70 for security violations in jail wp-armour. Log: 2026/06/28 06:54:02 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 157.22.18.70 | Target: wplogin" , client: 157.22.18.70, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ฌ๐ง
consul.to
2026-06-26 20:22:24
(3 months ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
kjaerulff
2026-04-14 05:56:23
(5 months ago)
Failed Wordpress login using wp-login.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 22:46:50
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 157.22.18.70 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.18.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 18:46:45.450063 2026] [security2:error] [pid 1682143:tid 1682143] [client 157.22.18.70:26873] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jwphotodesign.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jwphotodesign.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adWJVTxdNkPGWbF2rXJYrAAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 10:21:07
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 157.22.18.70 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.18.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 06:21:00.665480 2026] [security2:error] [pid 23181:tid 23181] [client 157.22.18.70:22499] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||paladinmicro.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "paladinmicro.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abvODFrhbbYgla6GqLCCMAAAAAU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-10 09:38:24
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 157.22.18.70 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.18.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 10 05:38:18.549112 2026] [security2:error] [pid 30518:tid 30518] [client 157.22.18.70:60097] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fsmfl.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fsmfl.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aa_miuF1trG2YhHi-SI_MAAAAA4"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-22 11:01:15
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 157.22.18.70 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.18.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 06:01:09.998207 2026] [security2:error] [pid 25558:tid 25558] [client 157.22.18.70:33009] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||arellasoc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "arellasoc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aXIDdSVwYC6FLMZmtJQaNgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-01-21 12:19:40
(8 months ago)
wordpress-trap
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-01-21 09:06:11
(8 months ago)
Try to access /xmlrpc.php
Web App Attack