🇺🇸
nationaleventpros.com
2026-09-05 05:06:05
(1 day ago)
WordPress login attempt
Brute-Force
🇺🇸
TPI-Abuse
2026-09-04 16:22:50
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 157.22.72.134 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.72.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 12:22:46.608432 2026] [security2:error] [pid 11765:tid 11765] [client 157.22.72.134:52007] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sjtent.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sjtent.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aprwVhsxvJhsriQIbodzFQAAABM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
nationaleventpros.com
2026-09-03 03:30:20
(3 days ago)
WordPress login attempt
Brute-Force
🇺🇸
kosada.com
2026-09-01 00:27:49
(5 days ago)
Web password guessing
Brute-Force
🇺🇸
TPI-Abuse
2026-08-31 22:14:46
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 157.22.72.134 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.72.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 18:14:41.438826 2026] [security2:error] [pid 3288:tid 3288] [client 157.22.72.134:15791] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mosherpit.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mosherpit.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apX80Y1gI6l1hyCjA3riGQAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-06 16:59:33
(4 weeks ago)
(caddyscan) Scanner path probe from 157.22.72.134 (GB/United Kingdom/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 157.22.72.134 (GB/United Kingdom/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 157.22.72.134 - - [06/Aug/2026:16:59:24 +0000] "POST /xmlrpc.php HTTP/1.1"
[REDACTED] 200 2627 157.22.72.134 - - [06/Aug/2026:16:59:26 +0000] "GET /wp-login.php HTTP/1.1"
[REDACTED] 200 2627 157.22.72.134 - - [06/Aug/2026:16:59:27 +0000] "GET /wp-login.php HTTP/1.1"
[REDACTED] 200 2627 157.22.72.134 - - [06/Aug/2026:16:59:30 +0000] "POST /xmlrpc.php HTTP/1.1"
[REDACTED] 200 2627 157.22.72.134 - - [06/Aug/2026:16:59:30 +0000] "GET /wp-login.php HTTP/1.1"
show less
Port Scan
🇩🇪
4server
2026-07-30 17:16:06
(1 month ago)
[ThuJul3019:16:03.8536942026][security2:error][pid3227832:tid3227960][client157.22.72.134:0]ModSecur ...
show more
[ThuJul3019:16:03.8536942026][security2:error][pid3227832:tid3227960][client157.22.72.134:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"morandi-trasporti.ch\"][uri\"/xmlrpc.php\"][unique_id\"amuG01Ocy795QXlSBPgjRwAAARE\"]
show less
Port Scan
Brute-Force
Web App Attack
🇫🇷
dynamix
2026-07-27 18:19:39
(1 month ago)
Multiple WAF Violations
Web App Attack
🇫🇷
Yepngo
2026-07-14 05:45:45
(1 month ago)
157.22.72.134 - - [14/Jul/2026:07:37:53 +0200] "POST /wp-login.php HTTP/2.0" 200 11350 "https://yepn ...
show more
157.22.72.134 - - [14/Jul/2026:07:37:53 +0200] "POST /wp-login.php HTTP/2.0" 200 11350 "https://yepngo.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
157.22.72.134 - - [14/Jul/2026:07:45:45 +0200] "POST /wp-login.php HTTP/2.0" 200 11351 "https://yepngo.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
🇫🇷
Tilellit.PRO
2026-06-27 10:29:33
(2 months ago)
Fail2Ban banned 157.22.72.134 for security violations in jail wp-armour. Log: 2026/06/27 10:29:33 [e ...
show more
Fail2Ban banned 157.22.72.134 for security violations in jail wp-armour. Log: 2026/06/27 10:29:33 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 157.22.72.134 | Target: wplogin" , client: 157.22.72.134, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
🇺🇸
bigwavedave
2026-06-20 21:54:34
(2 months ago)
Wordpress Attack
Web App Attack
🇺🇸
TPI-Abuse
2026-06-19 18:32:45
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 157.22.72.134 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.72.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 14:32:40.340208 2026] [security2:error] [pid 3503:tid 3503] [client 157.22.72.134:28675] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||inlinesoftware.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "inlinesoftware.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ajWLSDDqsCDojEEu9fuVQQAAAA8"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
ambor
2026-05-22 01:07:36
(3 months ago)
Honeypot access: WordPress admin access attempt. Path: /wp-login.php
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-05-21 12:42:29
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 157.22.72.134 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.72.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 08:42:25.429098 2026] [security2:error] [pid 23061:tid 23081] [client 157.22.72.134:10159] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||aplinet.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "aplinet.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ag79sYAzHgc1qJfJmBg-rAAAAVI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
screwlooseit.com.au
2026-05-10 15:56:54
(3 months ago)
Blocked by CSF 13 firewall - Rule: WPLOGIN
US/United States/-
Web App Attack