🇪🇸
librebit
2026-09-01 12:34:55
(4 days ago)
Brute force
Brute-Force
🇮🇹
VHosting
2026-03-26 20:22:00
(5 months ago)
Detected attack and reported by a human
Brute-Force
Web App Attack
SSH
DDoS Attack
Exploited Host
Bad Web Bot
🇺🇸
TPI-Abuse
2026-03-15 00:22:04
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 5.183.255.216 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 5.183.255.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 20:21:50.107754 2026] [security2:error] [pid 14201:tid 14201] [client 5.183.255.216:9671] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thehappywillow.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thehappywillow.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abX7nri6g4yQm9pSuo3g2AAAABw"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-14 23:47:45
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 5.183.255.216 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 5.183.255.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 19:47:32.217460 2026] [security2:error] [pid 22362:tid 22362] [client 5.183.255.216:52739] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||starfi.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "starfi.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abXzlIWVILPBXM3kjfh9zAAAAAo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-14 20:49:36
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 5.183.255.216 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 5.183.255.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 16:49:20.384760 2026] [security2:error] [pid 18889:tid 18889] [client 5.183.255.216:58451] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||yogitunes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "yogitunes.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abXJ0FEz1M2liHWh_w9TFAAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-20 20:27:03
(6 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
🇮🇹
VHosting
2026-02-20 14:20:03
(6 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
🇦🇹
René Hickersberger
2026-02-19 21:47:19
(6 months ago)
[2026-02-19T21:47:19Z] Malicious request to /wp-login.php
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-01-23 01:10:30
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 5.183.255.216 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 5.183.255.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 20:09:53.575673 2026] [security2:error] [pid 14876:tid 14876] [client 5.183.255.216:33125] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bonnesfrequences.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bonnesfrequences.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aXLKYfzMWQukye16iH5fhQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
OnTheEdge
2025-03-12 09:04:18
(1 year ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
🇸🇪
OnTheEdge
2025-03-10 06:11:33
(1 year ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
🇸🇪
OnTheEdge
2025-03-10 06:11:33
(1 year ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
🇨🇿
lp
2025-03-05 02:50:08
(1 year ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 5.183.255.216
2025-03-05T03:10:08+01: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 5.183.255.216
2025-03-05T03:10:08+01:00 vpn Access-Reject 'qian' station: 5.183.255.216 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
🇨🇿
lp
2025-03-02 13:21:41
(1 year ago)
Unauthorized VPN login attempts: 2 attempts were recorded from 5.183.255.216
2025-03-02T12:48:08+01: ...
show more
Unauthorized VPN login attempts: 2 attempts were recorded from 5.183.255.216
2025-03-02T12:48:08+01:00 vpn Access-Reject 'arina' station: 5.183.255.216 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2025-03-02T13:56:27+01:00 vpn Access-Reject 'azariah' station: 5.183.255.216 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
🇨🇿
lp
2025-03-01 17:49:44
(1 year ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 5.183.255.216
2025-03-01T18:32:36+01: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 5.183.255.216
2025-03-01T18:32:36+01:00 vpn Access-Reject 'amos' station: 5.183.255.216 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack