๐ฌ๐ง
consul.to
2026-04-02 14:09:51
(2 months ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-01 23:42:48
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 212.56.53.158 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 212.56.53.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 18:42:41.947066 2026] [security2:error] [pid 854309:tid 854309] [client 212.56.53.158:32921] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||intercite.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "intercite.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aX_k8UIHe5OSkpHLPyDbHQAAAAM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-01 22:47:32
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 212.56.53.158 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 212.56.53.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 17:47:26.159097 2026] [security2:error] [pid 16083:tid 16083] [client 212.56.53.158:44425] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gonzalez.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gonzalez.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aX_X_m7LBozmdL6JP2WF8wAAAAM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-01 21:31:44
(4 months ago)
Failed Wordpress login
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-01 18:37:12
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 212.56.53.158 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 212.56.53.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 13:37:04.336487 2026] [security2:error] [pid 13978:tid 13978] [client 212.56.53.158:25016] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||moellerlaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "moellerlaw.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aX-dUCPFrcujYrf7gieYYgAAAAw"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-01 17:18:20
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 212.56.53.158 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 212.56.53.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 12:18:13.076880 2026] [security2:error] [pid 12949:tid 13067] [client 212.56.53.158:36850] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nrgla.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nrgla.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aX-K1cABjuxpzwdCOxdtoAAAAEA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-01 16:17:38
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 212.56.53.158 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 212.56.53.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 11:17:33.524509 2026] [security2:error] [pid 18168:tid 18168] [client 212.56.53.158:23306] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tremulant.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tremulant.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aX98nS14pqmsc-yppLZOTgAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-02-01 15:29:45
(4 months ago)
Accessed trap at '/xmlrpc.php'
Web App Attack
Anonymous
2025-11-25 11:45:06
(6 months ago)
botnet
DDoS Attack
Anonymous
2025-10-18 04:30:17
(7 months ago)
Failed login attempt detected by Fail2Ban in plesk-postfix jail
Brute-Force
๐ท๐ด
INTEQ
2025-10-17 21:13:11
(7 months ago)
Brute force attack from 212.56.53.158
Brute-Force
๐ฉ๐ช
pigro
2025-08-08 13:11:39
(10 months ago)
212.56.53.158 - - [08/Aug/2025:15:11:38 +0200] "\x12\x01\x00&\x00\x00\x00\x00\x00\x00\x00\x00\x00\x0 ...
show more
212.56.53.158 - - [08/Aug/2025:15:11:38 +0200] "\x12\x01\x00&\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\xFF" 400 157 "-" "-"
212.56.53.158 - - [08/Aug/2025:15:11:39 +0200] "\x16\x03\x01\x00O\x01\x00\x00K\x03\x03De[\xFDv\x07y\xB9\x04\xAD\x81\xC3\xA2\xD9\x10n\x83aU0N\x00FE\xF8[v[{\x87Eb\x00\x00\x0C\xC0/\xC0+\x00\x9E\xCC\xA8\x13\x01\x13\x02\x01\x00\x00\x16\x00\x00\x00\x12\x00\x10\x00\x00" 400 157 "-" "-"
...
show less
Web App Attack
๐ธ๐ฌ
mypatricks
2025-07-20 05:28:15
(10 months ago)
212.56.53.158 | Port: 37056 | DNS: 212.56.53.158 2025-07-20T13:28:14+08:00 America/Los_Angeles | IPs ...
show more
212.56.53.158 | Port: 37056 | DNS: 212.56.53.158 2025-07-20T13:28:14+08:00 America/Los_Angeles | IPs Spam list | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.1.1 Safari/605.1.15 HTTP/1.1 443 GET | URL: /cart/?ea864fe16b0dbae4d80747e525ae2cd0=1751174712b | Ref: - | Country: US/United States/-08:00 IP City: Los Angeles 96200dcfa967e9e0-LAX/Los Angeles, CA, United States 1 hits/0 secs Robots 2
show less
Web Spam
Blog Spam
Brute-Force
Exploited Host
Web App Attack
๐ต๐ฑ
sefinek.net
2025-04-30 01:00:08
(1 year ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Edg/114.0.1264.71
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot