Anonymous
2026-09-01 17:59:00
(1 day ago)
FPROCO WEBEXPLOIT 193.151.189.164 (193.151.189.164)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 22:03:34
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 193.151.189.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 193.151.189.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 18:03:28.491739 2026] [security2:error] [pid 30296:tid 30296] [client 193.151.189.164:21941] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||yogitunes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "yogitunes.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apX6MJAwRVnP0r6A2f5dTwAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-08-28 22:19:49
(4 days ago)
Web password guessing
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-12 20:28:57
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 193.151.189.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 193.151.189.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 16:28:49.973956 2026] [security2:error] [pid 3256535:tid 3256535] [client 193.151.189.164:64611] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tanny.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tanny.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anzXgbouPJNp3HWvDYUnWwAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 17:35:25
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 193.151.189.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 193.151.189.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 13:35:19.467228 2026] [security2:error] [pid 3738583:tid 3738583] [client 193.151.189.164:55335] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||socialstudiesforkids.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "socialstudiesforkids.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anYXV95uKv7bYIixBmlELwAAABA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-07-05 04:21:03
(1 month ago)
WP Armour Plugin detection
Web Spam
Brute-Force
๐ซ๐ท
Tilellit.PRO
2026-06-29 12:01:17
(2 months ago)
Fail2Ban banned 193.151.189.164 for security violations in jail wp-armour. Log: 2026/06/29 12:01:16 ...
show more
Fail2Ban banned 193.151.189.164 for security violations in jail wp-armour. Log: 2026/06/29 12:01:16 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 193.151.189.164 | Target: wplogin" , client: 193.151.189.164, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐บ๐ธ
TPI-Abuse
2026-06-20 00:14:48
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 193.151.189.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 193.151.189.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 20:14:43.939546 2026] [security2:error] [pid 23246:tid 23246] [client 193.151.189.164:14445] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||benny-wong.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "benny-wong.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ajXbc4AQ_Ce47vMALot4awAAAA4"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
ptlab
2026-04-21 00:47:09
(4 months ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-17 20:29:32
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 193.151.189.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 193.151.189.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 17 16:29:29.104799 2026] [security2:error] [pid 36397:tid 36397] [client 193.151.189.164:65027] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||celltechs.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "celltechs.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aeKYKbP03h2ALOWpq55WfAAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-17 07:40:58
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 193.151.189.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 193.151.189.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 17 03:40:52.612034 2026] [security2:error] [pid 1476240:tid 1476266] [client 193.151.189.164:33247] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ceol.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ceol.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aeHkBPpi_-k3q38qheiCggAAABc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TRoden
2026-04-06 18:18:59
(4 months ago)
Geo Block Plugin: Escalation flag(s): rce_attempt
Hacking
๐ซ๐ท
Tilellit.PRO
2026-04-06 17:50:12
(4 months ago)
Fail2Ban banned 193.151.189.164 for security violations in jail wp-armour. Log: 2026/04/06 17:50:12 ...
show more
Fail2Ban banned 193.151.189.164 for security violations in jail wp-armour. Log: 2026/04/06 17:50:12 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 193.151.189.164 | Target: wplogin" , client: 193.151.189.164, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://espsformacion.com/wp-login.php"
...
show less
Web Spam
๐ซ๐ท
mrcrassi
2026-04-03 07:59:56
(4 months ago)
Triggered Cloudflare WAF (firewallCustom) from FI.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST meth ...
show more
Triggered Cloudflare WAF (firewallCustom) from FI.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /wp-login.php
UA: curl/7.88.1
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
stinpriza
2026-03-09 07:28:49
(5 months ago)
Web App Attack
Web App Attack