This IP address has been reported a total of
22
times from
15 distinct
sources.
157.230.213.133 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
(mod_security) mod_security (id:243420) triggered by 157.230.213.133 (-): 1 in the last 300 secs; Po ...
show more(mod_security) mod_security (id:243420) triggered by 157.230.213.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 15:20:54.541130 2026] [security2:error] [pid 8873:tid 8873] [client 157.230.213.133:39456] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:redirect" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||dymesich.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "dymesich.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "apHfkxgfKm3xYE_Qt9SKrQAAABk"]
show less
[WedAug2614:26:51.1878082026][security2:error][pid324373:tid324664][client157.230.213.133:0]ModSecur ...
show more[WedAug2614:26:51.1878082026][security2:error][pid324373:tid324664][client157.230.213.133:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\^/wp-content/plugins/[\^/] /\(readme\\\\\\\\.txt\|changelog\\\\\\\\.txt\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"635\"][id\"960828\"][msg\"WordPresspluginenumerationblocked\"][hostname\"vetreriaperletti.ch\"][uri\"/wp-content/plugins/updraftplus/readme.txt\"][unique_id\"ao7bi79R6iMMXPymeeGcrAAAAIw\"]
show less
Attack attempt against Interwebbi servers; (WPNINJA) Ninja Firewall attack on mp-tuki.fi (WP vulnera ...
show moreAttack attempt against Interwebbi servers; (WPNINJA) Ninja Firewall attack on mp-tuki.fi (WP vulnerability) 157.230.213.133 (US/United States/-): 1 in the last 3600 secs (CF_ENABLE); IP: 157.230.213.133; Ports: *; Direction: 0; Trigger: LF_CUSTOMTRIGGER;
show less
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show moreMalicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-content/plugins/updraftplus/readme.txt | 2026-08-25 11:49 UTC
show less
(modsec_5015) ModSec 5015: Suspicious User-Agent from 157.230.213.133 (US/United States/-): 1 in the ...
show more(modsec_5015) ModSec 5015: Suspicious User-Agent from 157.230.213.133 (US/United States/-): 1 in the last 3600 secs (0-195)
show less
Attack attempt against Interwebbi servers; (WPNINJA) Ninja Firewall attack on eightamagency.com (WP ...
show moreAttack attempt against Interwebbi servers; (WPNINJA) Ninja Firewall attack on eightamagency.com (WP vulnerability) 157.230.213.133 (US/United States/-): 1 in the last 3600 secs (CF_ENABLE); IP: 157.230.213.133; Ports: *; Direction: 0; Trigger: LF_CUSTOMTRIGGER;
show less
Web App Attack
Anonymous
Attack detected: 157.230.213.133 [2026-08-23]
Categories: 21
--- wp2shell/batch exploit (1 hits) --- ...
show moreAttack detected: 157.230.213.133 [2026-08-23]
Categories: 21
--- wp2shell/batch exploit (1 hits) ---
157.230.213.133 - - [23/Aug/2026:09:42:17 +0000] "POST /?rest_route=/batch/v1 HTTP/1.1" 500 2282 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36"
show less
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 157.230.213.133 (US/United States/-): ...
show more(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 157.230.213.133 (US/United States/-): 1 in the last 3600 secs (0-197)
show less