๐ฉ๐ช
4server
2026-07-20 09:52:39
(2 days ago)
[MonJul2011:52:35.1789212026][security2:error][pid1445932:tid1445940][client178.20.215.205:0]ModSecu ...
show more
[MonJul2011:52:35.1789212026][security2:error][pid1445932:tid1445940][client178.20.215.205:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"www.allegraravizza.it\"][uri\"/xmlrpc.php\"][unique_id\"al3v4xj2F8lLMDjJh01x5AAAAQU\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
Victor Lรณpez
2026-05-11 00:19:56
(2 months ago)
178.20.215.205 - - [10/May/2026:19:19:50 -0500] "GET /wp-login.php HTTP/1.1" 404 2631 "-" "Mozilla/5 ...
show more
178.20.215.205 - - [10/May/2026:19:19:50 -0500] "GET /wp-login.php HTTP/1.1" 404 2631 "-" "Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10"
178.20.215.205 - - [10/May/2026:19:19:56 -0500] "GET /wp-login.php HTTP/1.1" 404 2626 "-" "Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-09 23:56:08
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 178.20.215.205 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 178.20.215.205 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 09 19:56:03.771739 2026] [security2:error] [pid 1255004:tid 1255004] [client 178.20.215.205:48379] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||barigby.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "barigby.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adg8k0slg17LRV_yCsyMvwAAABA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-04 09:35:47
(3 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-04-03 05:30:24
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 178.20.215.205 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 178.20.215.205 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 01:30:15.483105 2026] [security2:error] [pid 30865:tid 30865] [client 178.20.215.205:12267] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||turtletaekwondo.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "turtletaekwondo.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ac9QZ83PzmXiwePw9_4zsgAAAAg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-03-29 14:51:57
(3 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฎ๐น
VHosting
2026-03-26 20:21:59
(3 months ago)
Detected attack and reported by a human
Brute-Force
Web App Attack
SSH
DDoS Attack
Exploited Host
Bad Web Bot
๐ง๐ช
voormedia
2026-03-15 06:55:16
(4 months ago)
Accessed trap at '/wp-login.php'
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 22:04:29
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 178.20.215.205 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 178.20.215.205 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 17:04:22.863769 2025] [security2:error] [pid 27136:tid 27136] [client 178.20.215.205:33647] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||gewgawdesigns.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "gewgawdesigns.com"] [uri "/"] [unique_id "aSd5Zh5Bed-R0YuvGQQ_3AAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-21 15:30:54
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 178.20.215.205 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 178.20.215.205 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 21 10:30:47.309276 2025] [security2:error] [pid 16383:tid 16470] [client 178.20.215.205:32723] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||martinbenes.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "martinbenes.com"] [uri "/"] [unique_id "aSCFp8pDedhvjf9r4xrpJgAAAQY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-15 16:43:37
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 178.20.215.205 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 178.20.215.205 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 15 11:43:30.875233 2025] [security2:error] [pid 985:tid 985] [client 178.20.215.205:31285] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||macryder.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "macryder.com"] [uri "/"] [unique_id "aRitshL7XU-krlp0iqHjqwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
sms.ru
2024-09-28 04:10:06
(1 year ago)
SMS pumping attack from foreign country
DDoS Attack
Anonymous
2022-03-19 22:30:00
(4 years ago)
Password Spary Attack
Brute-Force
Exploited Host