๐ฉ๐ช
todix
2026-07-29 06:52:58
(14 hours ago)
Web App Attack Exploid from 185.61.217.13
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-06-14 16:27:48
(1 month ago)
WordPress login attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-29 09:16:32
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 185.61.217.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 185.61.217.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 29 05:16:27.902129 2026] [security2:error] [pid 23818:tid 23818] [client 185.61.217.13:19825] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||hazeltrane.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "hazeltrane.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahlZa4lInDvdo_GQqS9myQAAABg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-25 10:56:11
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 185.61.217.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 185.61.217.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 25 06:56:06.831803 2026] [security2:error] [pid 17452:tid 17452] [client 185.61.217.13:17937] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||marveldirectory.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "marveldirectory.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahQqxiu9nessZEgjTp_k_wAAABI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-05-22 01:54:14
(2 months ago)
Fail2Ban banned 185.61.217.13 for security violations in jail wp-armour. Log: 2026/05/22 01:54:13 [e ...
show more
Fail2Ban banned 185.61.217.13 for security violations in jail wp-armour. Log: 2026/05/22 01:54:13 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 185.61.217.13 | Target: wplogin" , client: 185.61.217.13, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ซ๐ท
Tilellit.PRO
2026-05-20 02:20:01
(2 months ago)
Fail2Ban banned 185.61.217.13 for security violations in jail wp-armour. Log: 2026/05/20 02:20:01 [e ...
show more
Fail2Ban banned 185.61.217.13 for security violations in jail wp-armour. Log: 2026/05/20 02:20:01 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 185.61.217.13 | Target: wplogin" , client: 185.61.217.13, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://espsformacion.com/wp-login.php"
...
show less
Web Spam
๐บ๐ธ
TPI-Abuse
2026-05-03 19:25:17
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 185.61.217.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 185.61.217.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 03 15:25:10.887618 2026] [security2:error] [pid 30617:tid 30617] [client 185.61.217.13:46329] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||egret.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "egret.us"] [uri "/wp-json/wp/v2/users"] [unique_id "afehFirbgWZiWKMCUx8XcgAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-30 14:16:26
(2 months ago)
(mod_security) mod_security (id:210350) triggered by 185.61.217.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 185.61.217.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 10:16:19.451008 2026] [security2:error] [pid 15696:tid 15696] [client 185.61.217.13:63421] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||diepeveen.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "diepeveen.com"] [uri "/"] [unique_id "afNkM7VqYBR_WHwwo5a6-gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-25 21:43:41
(5 months ago)
(mod_security) mod_security (id:210350) triggered by 185.61.217.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 185.61.217.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 25 16:43:34.196792 2026] [security2:error] [pid 11083:tid 11083] [client 185.61.217.13:48113] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||g-h2o.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "g-h2o.com"] [uri "/"] [unique_id "aZ9tBlI6i_TrxI6BssXQXQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-02-13 17:55:19
(5 months ago)
HTTP header is restricted by policy (/content-encoding/). String match within "/accept-charset/ /con ...
show more
HTTP header is restricted by policy (/content-encoding/). String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_content-encoding. (920450-123)
show less
Bad Web Bot
๐จ๐ฆ
SSH-Admin
2026-02-07 17:12:28
(5 months ago)
Probing for Exploits
Exploited Host
Web App Attack
๐จ๐ฆ
SSH-Admin
2025-12-27 13:45:08
(7 months ago)
Probing for Exploits
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-15 16:42:55
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 185.61.217.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 185.61.217.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 15 11:42:46.676209 2025] [security2:error] [pid 20379:tid 20379] [client 185.61.217.13:38307] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||birdlovers.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "birdlovers.net"] [uri "/"] [unique_id "aRithh6vtyc0nir8rkyzYQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-08-31 18:08:58
(10 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐ฎ๐น
Rosh
2025-08-06 19:42:13
(11 months ago)
[08/06/25 21:42:13] 1 attack: /wp-login.php (severity 10);
Web App Attack