🇩🇪
LRob
2026-09-07 13:33:55
(17 hours ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /xmlrpc.php | 2026-09-07 13:33 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-07-03 06:39:46
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 185.77.220.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.77.220.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 02:39:40.846024 2026] [security2:error] [pid 3980:tid 3980] [client 185.77.220.213:41247] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||robotsinme.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "robotsinme.org"] [uri "/wp-json/wp/v2/users"] [unique_id "akdZLJlD0aDT1A6qNxU2TAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-20 20:02:47
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 185.77.220.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 185.77.220.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 16:02:40.544003 2026] [security2:error] [pid 31075:tid 31075] [client 185.77.220.213:24605] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dpcfab.com"] [uri "/wp-config.php.bak"] [unique_id "ag4TYMxm2r5lF_GaLAUbrQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-20 16:16:59
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 185.77.220.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 185.77.220.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 12:16:50.258585 2026] [security2:error] [pid 5215:tid 5223] [client 185.77.220.213:44967] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "executiveconsultingpr.com"] [uri "/wp-config.php.old"] [unique_id "ag3ecpFCf_iRIFpi0OScbgAAAMM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-20 15:20:24
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 185.77.220.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 185.77.220.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 11:20:16.870072 2026] [security2:error] [pid 20066:tid 20066] [client 185.77.220.213:64771] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fuentevictoria.com"] [uri "/wp-config.php.dist"] [unique_id "ag3RMI5u6-D238C4cKHNfgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-20 12:17:54
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 185.77.220.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 185.77.220.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 08:17:48.464526 2026] [security2:error] [pid 10044:tid 10044] [client 185.77.220.213:37119] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drgracetomastolentino.com"] [uri "/wp-config.php.old"] [unique_id "ag2mbHkbVRyvPBHSqmQipAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-05-16 18:45:08
(3 months ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
🇺🇸
TPI-Abuse
2026-04-16 02:41:18
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 185.77.220.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 185.77.220.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 15 22:41:14.950807 2026] [security2:error] [pid 2321831:tid 2321831] [client 185.77.220.213:47401] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Barcalounger/Images/Churchill II Recliner/Art Burl 2/originals/Thumbs.db"] [unique_id "aeBMSjp7TBJlKTcaJofpaQAAAAQ"], referer: https://vitalitywebb.com/backstore/Barcalounger/Images/Churchill%20II%20Recliner/Art%20Burl%202/originals/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
BlueWire Hosting
2026-04-15 13:46:20
(4 months ago)
Probing websites for vulnerabilities
Web App Attack
SQL Injection
🇫🇷
Tilellit.PRO
2026-02-06 15:37:14
(7 months ago)
Fail2Ban banned 185.77.220.213 for security violations in jail wp-armour. Log: 2026/02/06 15:37:14 [ ...
show more
Fail2Ban banned 185.77.220.213 for security violations in jail wp-armour. Log: 2026/02/06 15:37:14 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 185.77.220.213 | Target: wplogin" , client: 185.77.220.213, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
Anonymous
2026-01-21 20:50:15
(7 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2026.01.21 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2026.01.21 is noted in report timestamp
show less
Hacking
Brute-Force
🇨🇭
backslash
2025-11-19 21:55:06
(9 months ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
🇩🇪
Packets-Decreaser.NET
2025-11-17 16:50:31
(9 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
🇺🇸
TPI-Abuse
2024-09-16 23:57:21
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 185.77.220.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.77.220.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 16 19:57:14.591319 2024] [security2:error] [pid 3729326:tid 3729345] [client 185.77.220.213:13943] [client 185.77.220.213] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gryphix.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gryphix.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZujF2hnq6-NAvkzxBRj_agAAAIs"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇩
BPS-StatisticsIndonesia
2024-09-08 00:50:51
(2 years ago)
XML RPC Scan Activities
Brute-Force
Web App Attack