๐บ๐ธ
TPI-Abuse
2026-08-27 07:12:45
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 37.140.223.88 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 37.140.223.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 03:12:41.126859 2026] [security2:error] [pid 8210:tid 8210] [client 37.140.223.88:48957] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||seagrovesrealty.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "seagrovesrealty.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ao_jaQ93Umia-8daLu12kgAAABo"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-08-27 05:48:01
(3 hours ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 37.140.223.88 (US/United States/-): 1 in the l ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 37.140.223.88 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 37.140.223.88 - - [27/Aug/2026:07:47:57 +0200] "GET /wp-json/wp/v2/users HTTP/1.1" 200 4724 "https://www.facebook.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" "-" host=consac.eu
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-27 04:38:03
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 37.140.223.88 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 37.140.223.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 00:37:58.425444 2026] [security2:error] [pid 31737:tid 31737] [client 37.140.223.88:38429] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jolankagroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jolankagroup.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ao-_JofBNAhkso_AMSwzLQAAAAA"], referer: https://wordpress.org/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-08-26 21:13:36
(12 hours ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 37.140.223.88 (US/United States/-): 1 in the l ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 37.140.223.88 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 37.140.223.88 - - [26/Aug/2026:23:13:28 +0200] "GET /wp-json/wp/v2/users HTTP/1.1" 200 4746 "https://duckduckgo.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0" "-" host=confartigianato.pe.it
show less
Port Scan
๐ซ๐ท
dynamix
2026-08-20 10:00:24
(6 days ago)
WordPress wp-login.php Brute Force Attack
Brute-Force
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-08-19 15:42:28
(1 week ago)
Blocked by CSF 13 firewall - Rule: WPLOGIN
-
Web App Attack
๐ฉ๐ช
David Ferneding
2026-08-18 13:59:22
(1 week ago)
Blocked by UFW (TCP on 80)
Source port: 21483
TTL: 57
Packet length: 60
TOS: 0x08
This report (for ...
show more
Blocked by UFW (TCP on 80)
Source port: 21483
TTL: 57
Packet length: 60
TOS: 0x08
This report (for 37.140.223.88) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack
Anonymous
2026-08-14 21:58:29
(1 week ago)
Fail2Ban: WordPress brute-force attack detected.
Bad Web Bot
Web App Attack
Anonymous
2026-08-14 20:46:29
(1 week ago)
Failed Wordpress Logins
Web App Attack
๐ฉ๐ช
LRob
2026-08-06 09:17:40
(2 weeks ago)
CrowdSec: crowdsecurity/http-wordpress-scan | req: /wordpress/wp-content/plugins/podlove-podcasting- ...
show more
CrowdSec: crowdsecurity/http-wordpress-scan | req: /wordpress/wp-content/plugins/podlove-podcasting-plugin-for-wordpress/readme.txt | 4 distinct paths | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-05 21:29:22
(3 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฉ๐ช
FeG Deutschland
2026-08-05 20:31:16
(3 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
Anonymous
2026-08-05 20:17:07
(3 weeks ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐บ๐ธ
etu brutus
2026-08-05 17:09:46
(3 weeks ago)
37.140.223.88 has been banned for [WebApp Attack]
...
Hacking
Bad Web Bot
Web App Attack
๐ต๐ฑ
lns.bz
2026-08-05 16:27:03
(3 weeks ago)
Web app attack [PL.Lu]
Exploited Host
Web App Attack