๐บ๐ธ
TPI-Abuse
2026-07-22 19:56:50
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 185.201.138.219 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.138.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 15:56:42.136624 2026] [security2:error] [pid 1273623:tid 1273623] [client 185.201.138.219:33455] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||justinrudd.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "justinrudd.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amEgevaZ8NYKhZK2wDPUTAAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-07-02 05:45:12
(3 weeks ago)
tilellit/wp-armour-ban
Hacking
๐ซ๐ท
Tilellit.PRO
2026-06-28 08:36:14
(3 weeks ago)
Fail2Ban banned 185.201.138.219 for security violations in jail wp-armour. Log: 2026/06/28 08:36:14 ...
show more
Fail2Ban banned 185.201.138.219 for security violations in jail wp-armour. Log: 2026/06/28 08:36:14 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 185.201.138.219 | Target: wplogin" , client: 185.201.138.219, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ซ๐ท
Tilellit.PRO
2026-06-27 13:22:00
(3 weeks ago)
Fail2Ban banned 185.201.138.219 for security violations in jail wp-armour. Log: 2026/06/27 13:21:59 ...
show more
Fail2Ban banned 185.201.138.219 for security violations in jail wp-armour. Log: 2026/06/27 13:21:59 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 185.201.138.219 | Target: wplogin" , client: 185.201.138.219, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐บ๐ธ
TPI-Abuse
2026-06-23 00:19:51
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 185.201.138.219 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.138.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 20:19:47.450025 2026] [security2:error] [pid 4936:tid 4936] [client 185.201.138.219:22831] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mcbrearty.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mcbrearty.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ajnRI-SQdA1eoft9GrKmqAAAAA8"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
ptlab
2026-04-09 08:45:29
(3 months ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack
๐ณ๐ฟ
Tripwire
2026-04-09 02:52:44
(3 months ago)
Wordpress login attempts
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-29 17:58:28
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 185.201.138.219 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.138.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 29 13:58:24.608495 2026] [security2:error] [pid 19695:tid 19695] [client 185.201.138.219:50947] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||billthompsons.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "billthompsons.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acloQPxHmGPYClDwOd5vNAAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-27 23:04:37
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 185.201.138.219 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.138.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 27 19:04:33.806861 2026] [security2:error] [pid 9730:tid 9730] [client 185.201.138.219:53861] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cjmconsulting.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cjmconsulting.net"] [uri "/wp-json/wp/v2/users"] [unique_id "accNAS7k5YpvXY-BRtvzmwAAAA0"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-25 12:41:34
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 185.201.138.219 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.138.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 25 08:41:30.207985 2026] [security2:error] [pid 4374:tid 4374] [client 185.201.138.219:48281] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||solderhead.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "solderhead.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acPX-jvKYBxdwSlnThpijwAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-24 21:04:07
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 185.201.138.219 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.138.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 24 17:04:02.323720 2026] [security2:error] [pid 20370:tid 20378] [client 185.201.138.219:41249] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||heworeblack.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "heworeblack.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acL8QoDwb6E41iYeXwK4lQAAAMY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-24 19:24:51
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 185.201.138.219 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.138.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 24 15:24:46.885827 2026] [security2:error] [pid 5162:tid 5162] [client 185.201.138.219:17159] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ratalads.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ratalads.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acLk_kp7HBLKZYQIvRQxJwAAAA8"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 08:24:07
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 185.201.138.219 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.138.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 04:24:03.682425 2026] [security2:error] [pid 14829:tid 14829] [client 185.201.138.219:28347] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mwrn.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mwrn.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ab5Vo1xhvHeamz91g8KAVAAAAAg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ด
conexcol
2026-03-16 06:53:14
(4 months ago)
(mod_security) mod_security (id:99001) triggered by 185.201.138.219 (DE/Germany/-): 5 in the last 36 ...
show more
(mod_security) mod_security (id:99001) triggered by 185.201.138.219 (DE/Germany/-): 5 in the last 3600 secs
show less
Brute-Force