๐ฉ๐ช
4server
2026-08-19 20:22:41
(5 days ago)
[WedAug1922:22:34.6090062026][security2:error][pid2903331:tid2903446][client213.108.0.149:0]ModSecur ...
show more
[WedAug1922:22:34.6090062026][security2:error][pid2903331:tid2903446][client213.108.0.149:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"www.gustotondo.ch\"][uri\"/xmlrpc.php\"][unique_id\"aoYQit-KkMNb9DhS0VO1aQAAAQQ\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
stinpriza
2026-08-19 17:12:30
(5 days ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 04:26:07
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 213.108.0.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 213.108.0.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 00:26:03.926875 2026] [security2:error] [pid 1783744:tid 1783747] [client 213.108.0.149:19817] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||frmoto.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "frmoto.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amQ623Qw0U3JIxUOVGMShAAAAEE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 03:18:11
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 213.108.0.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 213.108.0.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 23:18:05.359804 2026] [security2:error] [pid 1818493:tid 1818493] [client 213.108.0.149:59289] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||vaezi.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "vaezi.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amGH7Zj2Hy3mDJOycc5ixwAAABQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-06-29 09:20:30
(1 month ago)
Fail2Ban banned 213.108.0.149 for security violations in jail wp-armour. Log: 2026/06/29 09:20:30 [e ...
show more
Fail2Ban banned 213.108.0.149 for security violations in jail wp-armour. Log: 2026/06/29 09:20:30 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 213.108.0.149 | Target: wplogin" , client: 213.108.0.149, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ซ๐ท
Tilellit.PRO
2026-06-27 19:23:44
(1 month ago)
Fail2Ban banned 213.108.0.149 for security violations in jail wp-armour. Log: 2026/06/27 19:23:43 [e ...
show more
Fail2Ban banned 213.108.0.149 for security violations in jail wp-armour. Log: 2026/06/27 19:23:43 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 213.108.0.149 | Target: wplogin" , client: 213.108.0.149, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ซ๐ท
Tilellit.PRO
2026-06-27 05:59:40
(1 month ago)
Fail2Ban banned 213.108.0.149 for security violations in jail wp-armour. Log: 2026/06/27 05:59:40 [e ...
show more
Fail2Ban banned 213.108.0.149 for security violations in jail wp-armour. Log: 2026/06/27 05:59:40 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 213.108.0.149 | Target: wplogin" , client: 213.108.0.149, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐จ๐ฟ
ptlab
2026-06-26 20:46:05
(1 month ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack
๐ซ๐ท
โจ
2026-06-22 03:21:20
(2 months ago)
Domain : 6prog.org
Rule : wp-login
2026-06-22 01:02:35 ***hidden-privacy*** GET /wp-login.php - 443 ...
show more
Domain : 6prog.org
Rule : wp-login
2026-06-22 01:02:35 ***hidden-privacy*** GET /wp-login.php - 443 - 213.108.0.149 HTTP/1.1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36 https://www.google.com 6prog.org 404 0 2 1555 250 241 - -
show less
Web App Attack
๐ฎ๐ณ
Yashgarg@123
2026-06-19 13:29:00
(2 months ago)
this ip address "213.108.0.149" is trying to compromise the environment and tried the brute force at ...
show more
this ip address "213.108.0.149" is trying to compromise the environment and tried the brute force attack and ddos
show less
DDoS Attack
Open Proxy
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-16 10:47:03
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 213.108.0.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 213.108.0.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 06:46:55.386639 2026] [security2:error] [pid 31931:tid 31931] [client 213.108.0.149:61853] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||texaslawman.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "texaslawman.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ajEpn5bgnEdn8sgE3FG1AgAAABk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 22:08:09
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 213.108.0.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 213.108.0.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 18:08:02.125534 2026] [security2:error] [pid 28320:tid 28320] [client 213.108.0.149:21753] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||phoneresponse.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "phoneresponse.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ah4CwgCbKd03bAzCqJfm6QAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-30 18:37:00
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 213.108.0.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 213.108.0.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 14:36:53.515513 2026] [security2:error] [pid 367:tid 367] [client 213.108.0.149:59763] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thestardance.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thestardance.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahsuRROIh15VQMxlWfB7ggAAAA8"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 10:49:27
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 213.108.0.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 213.108.0.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 06:49:22.020519 2026] [security2:error] [pid 24941:tid 24941] [client 213.108.0.149:23841] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cgautomatizacion.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cgautomatizacion.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahV6sogWmk1bgvISdfDUTwAAAAg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-21 04:57:42
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 213.108.0.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 213.108.0.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 00:57:37.057238 2026] [security2:error] [pid 5292:tid 5296] [client 213.108.0.149:36783] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fostexlaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fostexlaw.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ag6QwcKFKslX00dD9hLydQAAAMI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack