๐ฉ๐ช
rh24
2026-10-01 15:08:03
(7 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 213.232.122.187 (RU/ ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 213.232.122.187 (RU/Russia/-)
show less
Bad Web Bot
๐ฉ๐ช
ger-stg-sifi1
2026-09-27 02:04:34
(4 days ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐ฆ๐บ
FireGuard Server
2026-09-09 18:35:06
(3 weeks ago)
Blocked by os-abuseipdb; 8 hits, proto=tcp, ports=443
Port Scan
Hacking
๐บ๐ธ
nationaleventpros.com
2026-09-05 05:54:18
(3 weeks ago)
WordPress login attempt
Brute-Force
๐บ๐ธ
nationaleventpros.com
2026-09-03 06:09:48
(4 weeks ago)
WordPress login attempt
Brute-Force
๐ฉ๐ช
4server
2026-09-02 23:56:41
(4 weeks ago)
[ThuSep0301:56:28.4937842026][security2:error][pid2122258:tid2122332][client213.232.122.187:0]ModSec ...
show more
[ThuSep0301:56:28.4937842026][security2:error][pid2122258:tid2122332][client213.232.122.187:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"alessandrolucchini.ch\"][uri\"/xmlrpc.php\"][unique_id\"api3rE3ciHjSu72nP2M9CwAAAMU\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
ne1for23
2026-09-02 23:38:12
(4 weeks ago)
213.232.122.187 - - [02/Sep/2026:23:38:11 +0000] "POST /xmlrpc.php HTTP/1.1" 403 153 "-" "Apache-Htt ...
show more
213.232.122.187 - - [02/Sep/2026:23:38:11 +0000] "POST /xmlrpc.php HTTP/1.1" 403 153 "-" "Apache-HttpClient/4.5.13 (Java/17.0.18)"
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 22:43:17
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 213.232.122.187 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 213.232.122.187 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 18:43:00.761044 2026] [security2:error] [pid 6576:tid 6576] [client 213.232.122.187:30591] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||goodpage.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "goodpage.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aot3dCBqu-eSa840mf02SgAAAAw"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
librebit
2026-08-20 05:19:55
(1 month ago)
Brute force
Brute-Force
๐บ๐ธ
Victor Lรณpez
2026-08-18 13:42:37
(1 month ago)
empresarioexpress.com 213.232.122.187 - - [18/Aug/2026:08:42:18 -0500] "GET / HTTP/1.1" 444 0 "-" "M ...
show more
empresarioexpress.com 213.232.122.187 - - [18/Aug/2026:08:42:18 -0500] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36" -
empresarioexpress.com 213.232.122.187 - - [18/Aug/2026:08:42:27 -0500] "POST /?rest_route=/batch/v1 HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36" -
empresarioexpress.com 213.232.122.187 - - [18/Aug/2026:08:42:36 -0500] "POST / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36" -
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-05 21:14:44
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 213.232.122.187 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 213.232.122.187 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 05 17:14:26.650229 2026] [security2:error] [pid 3733751:tid 3733751] [client 213.232.122.187:64809] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||geriterry.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "geriterry.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anOnstPPly4Ctm2b8lzggAAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-07-05 04:04:54
(2 months ago)
WP Armour Plugin detection
Web Spam
Brute-Force
๐ซ๐ท
Tilellit.PRO
2026-06-29 13:10:27
(3 months ago)
Fail2Ban banned 213.232.122.187 for security violations in jail wp-armour. Log: 2026/06/29 13:10:26 ...
show more
Fail2Ban banned 213.232.122.187 for security violations in jail wp-armour. Log: 2026/06/29 13:10:26 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 213.232.122.187 | Target: wplogin" , client: 213.232.122.187, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ซ๐ท
Tilellit.PRO
2026-06-28 08:50:15
(3 months ago)
Fail2Ban banned 213.232.122.187 for security violations in jail wp-armour. Log: 2026/06/28 08:50:14 ...
show more
Fail2Ban banned 213.232.122.187 for security violations in jail wp-armour. Log: 2026/06/28 08:50:14 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 213.232.122.187 | Target: wplogin" , client: 213.232.122.187, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ซ๐ท
Tilellit.PRO
2026-06-27 08:59:14
(3 months ago)
Fail2Ban banned 213.232.122.187 for security violations in jail wp-armour. Log: 2026/06/27 08:59:14 ...
show more
Fail2Ban banned 213.232.122.187 for security violations in jail wp-armour. Log: 2026/06/27 08:59:14 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 213.232.122.187 | Target: wplogin" , client: 213.232.122.187, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam