Anonymous
2026-06-13 04:05:23
(4 days ago)
Unauthorized VPN login attempts
Hacking
Brute-Force
๐ฉ๐ช
filstal.org
2026-06-12 09:06:26
(5 days ago)
Automated bot: spoofed/impossible user-agent, web scraping or automated request patterns detected. U ...
show more
Automated bot: spoofed/impossible user-agent, web scraping or automated request patterns detected. UA: Opera/9.93.(X11; Linux i686; my-MM) Presto/2.9.181 Version/12.00
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-05-16 02:49:21
(1 month ago)
Unauthorized access to webpage admin
Web App Attack
๐บ๐ธ
xmission.com
2026-04-09 12:37:28
(2 months ago)
Blocked by UFW (TCP on 9101)
Source port: 64162
TTL: 113
Packet length: 52
TOS: 0x00
This report (f ...
show more
Blocked by UFW (TCP on 9101)
Source port: 64162
TTL: 113
Packet length: 52
TOS: 0x00
This report (for 158.140.166.13) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ฆ๐บ
screwlooseit.com.au
2026-02-08 12:18:56
(4 months ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
ID/Indonesia/host-158.140.166-13.myrepublic.co.id
Web App Attack
๐บ๐ธ
ambor
2026-02-08 10:45:22
(4 months ago)
Honeypot access: WordPress XML-RPC attack attempt. Path: /xmlrpc.php
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-08 06:17:09
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 158.140.166.13 (host-158.140.166-13.myrepublic. ...
show more
(mod_security) mod_security (id:225170) triggered by 158.140.166.13 (host-158.140.166-13.myrepublic.co.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 08 01:17:02.647931 2026] [security2:error] [pid 14403:tid 14403] [client 158.140.166.13:14502] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||beirutbazar.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "beirutbazar.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aYgqXig-GYbhDTo1jOeiOgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
maxxsense
2026-02-08 02:11:35
(4 months ago)
(wordpress) Failed wordpress login from 158.140.166.13 (ID/Indonesia/host-158.140.166-13.myrepublic. ...
show more
(wordpress) Failed wordpress login from 158.140.166.13 (ID/Indonesia/host-158.140.166-13.myrepublic.co.id)
show less
Brute-Force
Anonymous
2026-02-07 23:35:20
(4 months ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-02-05 18:20:50
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 158.140.166.13 (host-158.140.166-13.myrepublic. ...
show more
(mod_security) mod_security (id:225170) triggered by 158.140.166.13 (host-158.140.166-13.myrepublic.co.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 05 13:20:45.585009 2026] [security2:error] [pid 5362:tid 5362] [client 158.140.166.13:53430] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||caddydad.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "caddydad.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aYTffQHDf3WnaxeXP5-RugAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-02-03 09:19:09
(4 months ago)
Try to access /xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-03 04:13:38
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 158.140.166.13 (host-158.140.166-13.myrepublic. ...
show more
(mod_security) mod_security (id:225170) triggered by 158.140.166.13 (host-158.140.166-13.myrepublic.co.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 02 23:13:33.238377 2026] [security2:error] [pid 17957:tid 17957] [client 158.140.166.13:28965] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ideaofauniversity.website|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ideaofauniversity.website"] [uri "/wp-json/wp/v2/users"] [unique_id "aYF17RNvbWsv-nOoO94avgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ช
Jim Keir
2026-02-03 03:14:31
(4 months ago)
2026-02-03 03:14:30 158.140.166.13 File scanning, blocking 158.140.166.13 for 5 minutes
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-02 20:46:22
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 158.140.166.13 (host-158.140.166-13.myrepublic. ...
show more
(mod_security) mod_security (id:225170) triggered by 158.140.166.13 (host-158.140.166-13.myrepublic.co.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 02 15:46:16.603665 2026] [security2:error] [pid 15070:tid 15070] [client 158.140.166.13:42263] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fractalsky.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fractalsky.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aYENGAIR_IasT0DKcD-s9gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-01 23:22:50
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 158.140.166.13 (host-158.140.166-13.myrepublic. ...
show more
(mod_security) mod_security (id:225170) triggered by 158.140.166.13 (host-158.140.166-13.myrepublic.co.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 18:22:41.066159 2026] [security2:error] [pid 1946:tid 1946] [client 158.140.166.13:53996] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||clipper1970.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "clipper1970.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aX_gQVj-zmy70XwuhuVGzwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack