๐ฉ๐ช
stinpriza
2026-09-25 06:28:24
(3 days ago)
Web App Attack
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-24 07:35:50
(4 days ago)
cloudlinux2 fail2ban: 2026-09-24 09:24:13,541 fail2ban.filter [1603]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-24 09:24:13,541 fail2ban.filter [1603]: INFO [plesk-wordpress] Found 193.56.116.92 - 2026-09-24 09:24:12cloudlinux2 fail2ban: 2026-09-24 09:25:08,713 fail2ban.filter [1603]: INFO [plesk-modsecurity] Found 180.153.236.240 - 2026-09-24 09:25:08cloudlinux2 fail2ban: 2026-09-24 09:25:44,897 fail2ban.filter [1603]: INFO [plesk-wordpress] Found 173.239.213.67 - 2026-09-24 09:25:44cloudlinux2 fail2ban: 2026-09-24 09:25:44,719 fail2ban.filter [1603]: INFO [plesk-modsecurity] Found 199.96.167.128 - 2026-09-24 09:25:44cloudlinux2 fail2ban: 2026-09-24 09:25:47,500 fail2ban.filter [1603]: INFO [plesk-modsecurity] Found 45.136.27.215 - 2026-09-24 09:25:47cloudlinux2 fail2ban: 2026-09-24 09:25:41,006 fail2ban.filter [1603]: INFO [plesk-wordpress] Found 173.239.213.67 - 2026-09-24 09:25:40cloudlinux2 fail2ban: 2026-09-24 09:25:47,827 fail2ban.filter [1603]: INFO [plesk-wordpress] Found 199.96.167.128 - 2026-09-24 09:25
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 06:55:39
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 199.96.167.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 199.96.167.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 02:55:33.872956 2026] [security2:error] [pid 15819:tid 15819] [client 199.96.167.128:47787] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||primacomm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "primacomm.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arTJZTrrX9Gy1rdpyJM__AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-09-10 08:21:00
(2 weeks ago)
Web Spam
๐ซ๐ท
masterguru
2026-06-17 01:18:49
(3 months ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 199.96.167.128 (US/United States/-): 1 in the ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 199.96.167.128 (US/United States/-): 1 in the last 3600 secs (0-196)
show less
Hacking
๐ซ๐ท
ingroscart.it
2026-03-11 23:22:44
(6 months ago)
(mod_security) mod_security triggered on hostname [redacted] 199.96.167.128 (US/United States/-)
SQL Injection
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2026-02-25 08:13:15
(7 months ago)
WP Login Scan Activities: "2026-02-25T15:13:15.215+07:00" "/wp-login.php" "199.96.167.128" "Mozilla/ ...
show more
WP Login Scan Activities: "2026-02-25T15:13:15.215+07:00" "/wp-login.php" "199.96.167.128" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
show less
Web App Attack
๐ฎ๐ฉ
Burayot
2026-02-22 07:42:18
(7 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 199.96.167.128 (US/United States/-) ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 199.96.167.128 (US/United States/-): 2 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
mind5t0rm
2026-02-06 15:36:29
(7 months ago)
(XMLRPC) WP XMLPRC Attack 199.96.167.128 (US/United States/-): 3 in the last 3600 secs; Ports: *; Di ...
show more
(XMLRPC) WP XMLPRC Attack 199.96.167.128 (US/United States/-): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: 199.96.167.128 - - [06/Feb/2026:22:36:24 +0700] "POST /xmlrpc.php HTTP/2.0" 403 154 "-" "curl/7.88.1"
199.96.167.128 - - [06/Feb/2026:22:36:25 +0700] "POST /xmlrpc.php HTTP/2.0" 403 154 "-" "curl/7.88.1"
199.96.167.128 - - [06/Feb/2026:22:36:26 +0700] "POST /xmlrpc.php HTTP/2.0" 403 154 "-" "curl/7.88.1"
show less
Port Scan
๐บ๐ธ
Psycho Solutions LLC
2026-02-02 17:42:01
(7 months ago)
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-login.php - User Agent: N ...
show more
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-login.php - User Agent: N/A - Timestamp: 2/2/2026 5:42 pm (UTC-6)
show less
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2026-01-27 21:28:13
(8 months ago)
WP Login Scan Activities
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2026-01-24 21:04:54
(8 months ago)
WP Login Scan Activities
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-20 05:04:53
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 199.96.167.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 199.96.167.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 20 00:04:46.025957 2026] [security2:error] [pid 25066:tid 25066] [client 199.96.167.128:48823] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||admin.turedinmobiliaria.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "admin.turedinmobiliaria.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aW8M7rn2RTDsFTasoRQfYgAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-14 12:56:04
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 199.96.167.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 199.96.167.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 14 07:55:57.387511 2026] [security2:error] [pid 9591:tid 9591] [client 199.96.167.128:15395] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.televisonic.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.televisonic.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aWeSXfKtiXfYGWGrhukAewAAAAg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-29 11:29:23
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 199.96.167.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 199.96.167.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 29 07:29:16.784099 2025] [security2:error] [pid 6456:tid 6456] [client 199.96.167.128:32985] [client 199.96.167.128] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jolankagroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jolankagroup.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aBC4DAIP01L8NaAtSRNTmAAAAAk"], referer: https://jolankagroup.com/wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack