AbuseIPDB » 178.149.210.133
178.149.210.133 was found in our database!
This IP was reported 5 times. Confidence of
Abuse
is 30% : ?
ISP
Serbia BroadBand
Usage Type
Fixed Line ISP
ASN
AS31042
Hostname(s)
cable-178-149-210-133.dynamic.sbb.rs
Domain Name
united.group
Country
π·πΈ
Serbia
City
Nis, Central Serbia
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 178.149.210.133 :
This IP address has been reported a total of
5
times from
4 distinct
sources.
178.149.210.133 was first reported on
July 24th 2026 , and the most recent report was
3 days ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
π©πͺ
ghostwarriors
2026-07-24 20:51:01
(3 days ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-24 20:43:12
(3 days ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-24 14:56:46
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 178.149.210.133 (cable-178-149-210-133.dynamic. ...
show more
(mod_security) mod_security (id:240335) triggered by 178.149.210.133 (cable-178-149-210-133.dynamic.sbb.rs): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 10:56:38.425366 2026] [security2:error] [pid 338883:tid 338883] [client 178.149.210.133:50007] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 178.149.210.133 (+1 hits since last alert)|lahamradio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lahamradio.com"] [uri "/xmlrpc.php"] [unique_id "amN9JlseUe1SA7RM0l6O5wAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
F242
2026-07-24 12:39:21
(4 days ago)
Wordpress soft lock
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-24 09:27:26
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 178.149.210.133 (cable-178-149-210-133.dynamic. ...
show more
(mod_security) mod_security (id:240335) triggered by 178.149.210.133 (cable-178-149-210-133.dynamic.sbb.rs): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 05:27:21.458133 2026] [security2:error] [pid 72728:tid 72728] [client 178.149.210.133:60030] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 178.149.210.133 (+1 hits since last alert)|36sovereignchambers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "36sovereignchambers.com"] [uri "/xmlrpc.php"] [unique_id "amMv-Y5-Owwz537WDESVeAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Showing 1 to
5
of 5 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown π©
Recently Reported IPs: