๐บ๐ธ
TPI-Abuse
2026-06-22 19:50:38
(21 hours ago)
(mod_security) mod_security (id:225170) triggered by 209.42.18.232 (d7110.lon1.stableserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 209.42.18.232 (d7110.lon1.stableserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 15:50:33.052592 2026] [security2:error] [pid 24395:tid 24409] [client 209.42.18.232:50456] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.scottspencergfx.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.scottspencergfx.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajmSCYaj_FdJxouc7e5i2QAAAUo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 11:15:09
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 209.42.18.232 (d7110.lon1.stableserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 209.42.18.232 (d7110.lon1.stableserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 07:15:00.426161 2026] [security2:error] [pid 29321:tid 29321] [client 209.42.18.232:51742] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||drgtek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "drgtek.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajkZNKc25LFICnRSXENGdwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 08:42:20
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 209.42.18.232 (d7110.lon1.stableserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 209.42.18.232 (d7110.lon1.stableserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 04:42:15.166193 2026] [security2:error] [pid 7552:tid 7552] [client 209.42.18.232:39118] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.btccasting.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.btccasting.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajj1Z6MCnVjSbZ76USNtMQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-21 17:19:39
(1 day ago)
[server.tmg.gr] httpd-suspicious-path: sites=ird2021.gr; logs=/var/log/httpd/domains/ird2021.gr.log; ...
show more
[server.tmg.gr] httpd-suspicious-path: sites=ird2021.gr; logs=/var/log/httpd/domains/ird2021.gr.log; samples=/wp-json/wp/v2/users | /?author=1 | /?author=2
show less
Hacking
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-06-21 14:02:37
(2 days ago)
(wp_login_try) srv104 WP Login Attempt 209.42.18.232 (GB/United Kingdom/d7110.lon1.stableserver.net) ...
show more
(wp_login_try) srv104 WP Login Attempt 209.42.18.232 (GB/United Kingdom/d7110.lon1.stableserver.net): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-21 13:17:17
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 209.42.18.232 (d7110.lon1.stableserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 209.42.18.232 (d7110.lon1.stableserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 09:17:13.122720 2026] [security2:error] [pid 4707:tid 4707] [client 209.42.18.232:48622] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.vzan.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.vzan.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ajfkWQG266jQNpSIXJgBWAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-21 12:42:35
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 209.42.18.232 (d7110.lon1.stableserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 209.42.18.232 (d7110.lon1.stableserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 08:42:31.115489 2026] [security2:error] [pid 2953:tid 2953] [client 209.42.18.232:42694] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.truthsabouthealthcare.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.truthsabouthealthcare.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajfcN7u4herbj-SjFzxNyQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-21 10:06:05
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 209.42.18.232 (d7110.lon1.stableserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 209.42.18.232 (d7110.lon1.stableserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 06:06:00.209214 2026] [security2:error] [pid 3360:tid 3360] [client 209.42.18.232:46816] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||iplantotravel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "iplantotravel.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aje3iOwmkXJWMGgVxcsCqgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-21 06:36:11
(2 days ago)
[redacted] 209.42.18.232 - - [21/Jun/2026:08:36:10 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "M ...
show more
[redacted] 209.42.18.232 - - [21/Jun/2026:08:36:10 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0"
[redacted] 209.42.18.232 - - [21/Jun/2026:08:36:10 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
[redacted] 209.42.18.232 - - [21/Jun/2026:08:36:10 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:45.0) Gecko/20100101 Firefox/45.0"
[redacted] 209.42.18.232 - - [21/Jun/2026:08:36:10 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:99.0) Gecko/20100101 Firefox/99.0"
[redacted] 209.42.18.232 - - [21/Jun/2026:08:36:10 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0"
[redacted] 209.42.18.232 - - [21/Jun/2026:08:36:10 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Window
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 18:58:52
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 209.42.18.232 (d7110.lon1.stableserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 209.42.18.232 (d7110.lon1.stableserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 14:58:46.528694 2026] [security2:error] [pid 3448:tid 3448] [client 209.42.18.232:44862] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.n4fh.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.n4fh.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajbi5mMIFyBNG563VWqfywAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 17:10:34
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 209.42.18.232 (d7110.lon1.stableserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 209.42.18.232 (d7110.lon1.stableserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 13:10:27.296810 2026] [security2:error] [pid 6119:tid 6119] [client 209.42.18.232:44300] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||major33.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "major33.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajbJgylfmKfwboio3Q2BjAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
fazar
2026-06-20 16:00:02
(3 days ago)
bad-behavior: 10 attempts from 209.42.18.232 on node: sgp01
Exploited Host
Web App Attack
๐ฎ๐ฑ
Dolphi
2026-06-20 14:30:02
(3 days ago)
Excessive POST /wp-login.php requests
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 20:40:05
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 209.42.18.232 (d7110.lon1.stableserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 209.42.18.232 (d7110.lon1.stableserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 16:39:56.885156 2026] [security2:error] [pid 29295:tid 29295] [client 209.42.18.232:53672] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.alsetsystems.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.alsetsystems.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai3AHE6eEbiykE25DEmqlAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 20:01:31
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 209.42.18.232 (d7110.lon1.stableserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 209.42.18.232 (d7110.lon1.stableserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 16:01:23.379524 2026] [security2:error] [pid 15611:tid 15611] [client 209.42.18.232:56350] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rotentendales.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rotentendales.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai23E8ewP6mZjOEGMapDGAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack