π«π·
dynamix
2026-06-10 16:44:23
(1 hour ago)
WordPress wp-login.php Brute Force Attack
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-09 23:43:16
(18 hours ago)
(mod_security) mod_security (id:225170) triggered by 162.19.59.210 (ns3227468.ip-162-19-59.eu): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 162.19.59.210 (ns3227468.ip-162-19-59.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 19:43:10.664391 2026] [security2:error] [pid 24433:tid 24433] [client 162.19.59.210:43644] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.inquisitivequincie.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.inquisitivequincie.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiilDgej6k5lNIgYAlvz9gAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-09 16:58:40
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 162.19.59.210 (ns3227468.ip-162-19-59.eu): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 162.19.59.210 (ns3227468.ip-162-19-59.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 12:58:34.979544 2026] [security2:error] [pid 1951:tid 1951] [client 162.19.59.210:35548] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rotentendales.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rotentendales.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aihGOmSjogkqn56cQGSb_wAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-07 07:30:13
(3 days ago)
[server.tmg.gr] httpd-suspicious-path: sites=crisis-management2018.eu; logs=/var/log/httpd/domains/c ...
show more
[server.tmg.gr] httpd-suspicious-path: sites=crisis-management2018.eu; logs=/var/log/httpd/domains/crisis-management2018.eu.log; samples=/wp-json/wp/v2/users | /?author=1 | /author/admin/
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-07 02:51:00
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 162.19.59.210 (ns3227468.ip-162-19-59.eu): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 162.19.59.210 (ns3227468.ip-162-19-59.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 22:50:56.272033 2026] [security2:error] [pid 1908:tid 1908] [client 162.19.59.210:45714] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.gasoilliquidsdaily.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.gasoilliquidsdaily.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiTckIsrb7SxquM0cPVVOgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-07 02:17:48
(3 days ago)
[redacted] 162.19.59.210 - - [07/Jun/2026:04:17:46 +0200] "POST /xmlrpc.php HTTP/1.1" 200 230 "-" "M ...
show more
[redacted] 162.19.59.210 - - [07/Jun/2026:04:17:46 +0200] "POST /xmlrpc.php HTTP/1.1" 200 230 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:50.0) Gecko/20100101 Firefox/50.0"
[redacted] 162.19.59.210 - - [07/Jun/2026:04:17:46 +0200] "POST /xmlrpc.php HTTP/1.1" 200 230 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/93.0"
[redacted] 162.19.59.210 - - [07/Jun/2026:04:17:46 +0200] "POST /xmlrpc.php HTTP/1.1" 200 230 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:70.0) Gecko/20100101 Firefox/70.0"
[redacted] 162.19.59.210 - - [07/Jun/2026:04:17:46 +0200] "POST /xmlrpc.php HTTP/1.1" 200 230 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:63.0) Gecko/20100101 Firefox/63.0"
[redacted] 162.19.59.210 - - [07/Jun/2026:04:17:46 +0200] "POST /xmlrpc.php HTTP/1.1" 200 230 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:49.0) Gecko/20100101 Firefox/49.0"
[redacted] 162.19.59.210 - - [07/Jun/2026:04:17:46 +0200] "POST /xmlrpc.php HTTP/1.1" 200 230
...
show less
Hacking
Web App Attack
πΊπΈ
Dolphi
2026-06-06 08:00:04
(4 days ago)
Excessive POST /wp-login.php requests
Brute-Force
Web App Attack
Anonymous
2026-06-04 00:22:16
(6 days ago)
[redacted] 162.19.59.210 - - [04/Jun/2026:02:22:14 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "M ...
show more
[redacted] 162.19.59.210 - - [04/Jun/2026:02:22:14 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0"
[redacted] 162.19.59.210 - - [04/Jun/2026:02:22:14 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:86.0) Gecko/20100101 Firefox/86.0"
[redacted] 162.19.59.210 - - [04/Jun/2026:02:22:14 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:92.0) Gecko/20100101 Firefox/92.0"
[redacted] 162.19.59.210 - - [04/Jun/2026:02:22:14 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0"
[redacted] 162.19.59.210 - - [04/Jun/2026:02:22:14 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:42.0) Gecko/20100101 Firefox/42.0"
[redacted] 162.19.59.2
...
show less
Hacking
Web App Attack
π«π·
dynamix
2026-06-02 09:35:28
(1 week ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-01 15:27:53
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 162.19.59.210 (ns3227468.ip-162-19-59.eu): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 162.19.59.210 (ns3227468.ip-162-19-59.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 11:27:49.591517 2026] [security2:error] [pid 10682:tid 10705] [client 162.19.59.210:47060] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.ccgparquitectos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.ccgparquitectos.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ah2k9Bs2y0MbNtZ1AzttqAAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-31 14:41:02
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 162.19.59.210 (ns3227468.ip-162-19-59.eu): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 162.19.59.210 (ns3227468.ip-162-19-59.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 10:40:55.901509 2026] [security2:error] [pid 27759:tid 27759] [client 162.19.59.210:56330] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.randymcelroy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.randymcelroy.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahxId9VHVYLZRGf8DJzL7QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-31 12:52:13
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 162.19.59.210 (ns3227468.ip-162-19-59.eu): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 162.19.59.210 (ns3227468.ip-162-19-59.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 08:52:08.758402 2026] [security2:error] [pid 30206:tid 30206] [client 162.19.59.210:51908] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.mosheimlib.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.mosheimlib.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ahwu-HpJpZJePWGb2GC2MgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-30 19:51:05
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 162.19.59.210 (ns3227468.ip-162-19-59.eu): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 162.19.59.210 (ns3227468.ip-162-19-59.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 15:50:59.868048 2026] [security2:error] [pid 17928:tid 17928] [client 162.19.59.210:42124] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||phalanxemail.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "phalanxemail.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ahs_o0y-45pPQLHPQf7GqwAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-30 16:48:26
(1 week ago)
[redacted] 162.19.59.210 - - [30/May/2026:18:48:23 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "M ...
show more
[redacted] 162.19.59.210 - - [30/May/2026:18:48:23 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0"
[redacted] 162.19.59.210 - - [30/May/2026:18:48:23 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:50.0) Gecko/20100101 Firefox/50.0"
[redacted] 162.19.59.210 - - [30/May/2026:18:48:23 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:58.0) Gecko/20100101 Firefox/58.0"
[redacted] 162.19.59.210 - - [30/May/2026:18:48:24 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0"
[redacted] 162.19.59.210 - - [30/May/2026:18:48:24 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:46.0) Gecko/20100101 Firefox/46.0"
[redacted] 162.19.59.2
...
show less
Hacking
Web App Attack
π¨π¦
SSH-Admin
2026-05-29 19:00:05
(1 week ago)
Probing for Exploits on ns200
Exploited Host
Web App Attack