๐บ๐ธ
TPI-Abuse
2026-08-26 23:53:52
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 166.1.131.166 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 166.1.131.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 19:53:42.994128 2026] [security2:error] [pid 28090:tid 28090] [client 166.1.131.166:10419] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rogerandcarol.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rogerandcarol.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ao98hlzF8a7IY9fzkvK-5gAAABE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-08-24 07:46:42
(1 week ago)
Web password guessing
Brute-Force
๐ซ๐ท
Yepngo
2026-08-23 23:35:27
(1 week ago)
166.1.131.166 - - [24/Aug/2026:01:24:59 +0200] "POST /wp-login.php HTTP/2.0" 200 12487 "https://yepn ...
show more
166.1.131.166 - - [24/Aug/2026:01:24:59 +0200] "POST /wp-login.php HTTP/2.0" 200 12487 "https://yepngo.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
166.1.131.166 - - [24/Aug/2026:01:35:26 +0200] "POST /wp-login.php HTTP/2.0" 200 12489 "https://yepngo.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-08-13 01:40:03
(2 weeks ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 04:28:52
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 166.1.131.166 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 166.1.131.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 00:28:46.566949 2026] [security2:error] [pid 356854:tid 356854] [client 166.1.131.166:49779] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||unified-dispatch.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "unified-dispatch.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anqk_iZQd2o0DaGVJAUEzAAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-11 04:05:35
(2 weeks ago)
FPROCO WEBEXPLOIT 166.1.131.166 (166.1.131.166)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-06 19:56:11
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 166.1.131.166 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 166.1.131.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 15:56:05.728825 2026] [security2:error] [pid 15181:tid 15181] [client 166.1.131.166:52693] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||securityzonepr.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "securityzonepr.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anTm1U6P4Y1IoNSQGI6CSwAAABM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-08-03 16:54:29
(4 weeks ago)
Web password guessing
Brute-Force
Anonymous
2026-07-30 19:38:01
(1 month ago)
Suspicious or malicious traffic has been detected
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-07-02 04:17:53
(1 month ago)
tilellit/wp-armour-ban
Hacking
๐ซ๐ท
Tilellit.PRO
2026-06-27 06:23:45
(2 months ago)
Fail2Ban banned 166.1.131.166 for security violations in jail wp-armour. Log: 2026/06/27 06:23:44 [e ...
show more
Fail2Ban banned 166.1.131.166 for security violations in jail wp-armour. Log: 2026/06/27 06:23:44 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 166.1.131.166 | Target: wplogin" , client: 166.1.131.166, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
Anonymous
2026-06-22 02:01:50
(2 months ago)
166.1.131.166 - - [22/Jun/2026:04:01:48 +0200] "GET /wp-login.php HTTP/1.1" 404 178 "https://www.goo ...
show more
166.1.131.166 - - [22/Jun/2026:04:01:48 +0200] "GET /wp-login.php HTTP/1.1" 404 178 "https://www.google.com" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
166.1.131.166 - - [22/Jun/2026:04:01:48 +0200] "GET /wp-login.php HTTP/1.1" 404 178 "https://www.google.com" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ฉ๐ช
kjaerulff
2026-03-10 10:06:29
(5 months ago)
Failed Wordpress login using wp-login.php
Web App Attack
๐จ๐ณ
ThreatBook.io
2025-01-31 22:09:41
(1 year ago)
ThreatBook Intelligence: Spam,cdn more details on https://threatbook.io/ip/166.1.131.166
2025-01-31 ...
show more
ThreatBook Intelligence: Spam,cdn more details on https://threatbook.io/ip/166.1.131.166
2025-01-31 05:23:55 /bower_components/jquery-ui/themes/base/jquery-ui.min.css
2025-01-31 05:23:55 /styles/main.css
2025-01-31 05:23:57 /scripts/main.js
show less
Web App Attack
Anonymous
2024-09-21 13:40:00
(1 year ago)
Spam
Web Spam