๐ท๐ด
INTEQ
2026-04-10 19:12:54
(2 months ago)
Web attack from 191.96.255.180
Web App Attack
๐ฎ๐น
VHosting
2025-12-23 16:40:09
(5 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
๐ฎ๐น
Progetto1
2025-11-07 14:20:04
(7 months ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-07 14:18:28
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 191.96.255.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 191.96.255.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 07 09:18:22.329149 2025] [security2:error] [pid 11162:tid 11162] [client 191.96.255.180:22179] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||muslera.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "muslera.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQ3_rsVqT32HSzBBe1UFzAAAAA8"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Tripwire
2025-11-07 12:34:37
(7 months ago)
Wordpress login attempts
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-07 12:32:50
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 191.96.255.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 191.96.255.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 07 07:32:46.342655 2025] [security2:error] [pid 12251:tid 12251] [client 191.96.255.180:3935] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||michaelhick.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "michaelhick.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQ3m7nU0VBROa8F_YGCe4wAAABA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2025-11-07 10:50:16
(7 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 191.96.255.180 (US/United States/-) ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 191.96.255.180 (US/United States/-): 1 in the last 3600 secs
show less
Web App Attack
Anonymous
2025-08-16 22:56:53
(9 months ago)
WordPress Brute Force
Brute-Force
๐ช๐ธ
10dencehispahard SL
2025-07-29 05:56:55
(10 months ago)
WP probing for vulnerabilities
Hacking
Exploited Host
Anonymous
2025-06-20 14:20:50
(11 months ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
Anonymous
2025-04-20 03:10:01
(1 year ago)
Apr 20 05:05:54 dell postfix-submission/smtpd[778]: warning: unknown[191.96.255.180]: SASL LOGIN aut ...
show more
Apr 20 05:05:54 dell postfix-submission/smtpd[778]: warning: unknown[191.96.255.180]: SASL LOGIN authentication failed: authentication failure
show less
Brute-Force
๐ฉ๐ช
John Chrys.
2025-04-20 03:08:53
(1 year ago)
Apr 20 06:08:51 diego postfix/smtpd[433305]: warning: unknown[191.96.255.180]: SASL LOGIN authentica ...
show more
Apr 20 06:08:51 diego postfix/smtpd[433305]: warning: unknown[191.96.255.180]: SASL LOGIN authentication failed: authentication failure
...
show less
Email Spam
Brute-Force
๐ต๐ฑ
sefinek.net
2025-03-14 14:00:12
(1 year ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
ASN: 174 (COGENT- ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
ASN: 174 (COGENT-174)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2025-03-14T13:45:51Z
Ray ID: 920436c0fa30fad2
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 YaBrowser/22.7.0 Yowser/2.5 Safari/537.36
Report generated by Cloudflare-WAF-To-AbuseIPDB:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐จ๐ฆ
Julio Covolato
2025-02-19 04:55:01
(1 year ago)
Imap or Submission login brute-force attacks.
Brute-Force
๐ฉ๐ช
nyuuzyou
2024-12-09 03:58:03
(1 year ago)
Intensive scraping: /web?s=%22spip.php%3F%22&country=vi-vi&scraper=yep. User-Agent: Mozilla/5.0 (X11 ...
show more
Intensive scraping: /web?s=%22spip.php%3F%22&country=vi-vi&scraper=yep. User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:114.0) Gecko/20100101 Firefox/114.0.
show less
Bad Web Bot