๐จ๐ญ
backslash
2026-06-08 04:42:00
(6 days ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-22 11:30:16
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 167.253.18.39 (167-253-18-39.cloudairone.com): ...
show more
(mod_security) mod_security (id:210492) triggered by 167.253.18.39 (167-253-18-39.cloudairone.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 07:30:12.324253 2026] [security2:error] [pid 4564:tid 4564] [client 167.253.18.39:65227] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "support.leonardodecaprio.com"] [uri "/wp-config.php.save"] [unique_id "ahA-RMDZGEITMW9zKzpF2AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 11:50:26
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 167.253.18.39 (167-253-18-39.cloudairone.com): ...
show more
(mod_security) mod_security (id:210492) triggered by 167.253.18.39 (167-253-18-39.cloudairone.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 07:50:20.405526 2026] [security2:error] [pid 3046:tid 3046] [client 167.253.18.39:58425] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.txt" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "advantagept.org"] [uri "/wp-config.txt"] [unique_id "ag2f_KBY3nFgDlJy65aUmQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
tilellit.pro
2026-05-19 02:58:22
(3 weeks ago)
Fail2Ban banned 167.253.18.39 for security violations in jail wp-armour. Log: 2026/05/19 02:58:22 [e ...
show more
Fail2Ban banned 167.253.18.39 for security violations in jail wp-armour. Log: 2026/05/19 02:58:22 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 167.253.18.39 | Target: wplogin" , client: 167.253.18.39, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ซ๐ท
masterguru
2026-05-17 14:08:37
(3 weeks ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐ฉ๐ช
ardexter
2026-05-17 01:54:26
(4 weeks ago)
Wordpress attack and DDOS
DDoS Attack
Web App Attack
๐บ๐ธ
NicoID
2026-05-02 00:10:22
(1 month ago)
167.253.18.39 - - [01/May/2026:00:39:26 -0600] "GET /xmlrpc.php HTTP/1.1" 405 3384 "-" "Mozilla/5.0 ...
show more
167.253.18.39 - - [01/May/2026:00:39:26 -0600] "GET /xmlrpc.php HTTP/1.1" 405 3384 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Brute-Force
๐ฉ๐ช
london2038.com
2026-04-14 19:52:01
(1 month ago)
Too many failed requests
167.253.18.39 - - [14/Apr/2026:21:51:55 +0200] "HEAD /wp-content/plugins/sv ...
show more
Too many failed requests
167.253.18.39 - - [14/Apr/2026:21:51:55 +0200] "HEAD /wp-content/plugins/svg-support/readme.txt HTTP/1.1" 404 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
167.253.18.39 - - [14/Apr/2026:21:51:55 +0200] "HEAD /wp-content/plugins/woocommerce/readme.txt HTTP/1.1" 404 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
167.253.18.39 - - [14/Apr/2026:21:51:55 +0200] "HEAD /wp-content/plugins/google-site-kit/readme.txt HTTP/1.1" 404 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
167.253.18.39 - - [14/Apr/2026:21:51:55 +0200] "HEAD /wp-content/plugins/better-wp-security/readme.txt HTTP/1.1" 404 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
167.253.18.39 - - [14/Apr/2026:21:51:55 +0200] "HEAD /wp-content
...
show less
Web Spam
Bad Web Bot