๐บ๐ธ
TPI-Abuse
2026-06-22 15:34:56
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 209.42.21.165 (d7803.lon1.stableserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 209.42.21.165 (d7803.lon1.stableserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 11:34:50.115694 2026] [security2:error] [pid 4393:tid 4393] [client 209.42.21.165:58280] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.realclean.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.realclean.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ajlWGia14JfIO6nnC8QRgQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
lns.bz
2026-06-22 04:46:39
(6 days ago)
Web app attack [PL.Lu]
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-21 23:43:34
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 209.42.21.165 (d7803.lon1.stableserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 209.42.21.165 (d7803.lon1.stableserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 19:43:27.777656 2026] [security2:error] [pid 10649:tid 10649] [client 209.42.21.165:47890] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||major33.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "major33.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajh3H8U36CKWIoRjU286MAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-06-21 22:38:20
(6 days ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
GB/United Kingdom/d7803.lon1.stableserver.net
Web App Attack
๐ฉ๐ช
reznekcs
2026-06-21 12:59:10
(1 week ago)
F2B wordpress ban. Logs: 209.42.21.165 - - [21/Jun/2026:14:59:09 +0200] "POST /xmlrpc.php HTTP/1.1" ...
show more
F2B wordpress ban. Logs: 209.42.21.165 - - [21/Jun/2026:14:59:09 +0200] "POST /xmlrpc.php HTTP/1.1" 200 458 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:62.0) Gecko/20100101 Firefox/62.0"
209.42.21.165 - - [21/Jun/2026:14:59:09 +0200] "POST /xmlrpc.php HTTP/1.1" 200 420 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-21 12:40:31
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 209.42.21.165 (d7803.lon1.stableserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 209.42.21.165 (d7803.lon1.stableserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 08:40:26.641211 2026] [security2:error] [pid 5174:tid 5174] [client 209.42.21.165:52680] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||doublenaughtspycar.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "doublenaughtspycar.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajfbuk1GentZlzM9TG7WYAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
netclix.gr
2026-06-20 23:34:43
(1 week ago)
(wordpress) Failed wordpress login from 209.42.21.165 (GB/United Kingdom/d7803.lon1.stableserver.net ...
show more
(wordpress) Failed wordpress login from 209.42.21.165 (GB/United Kingdom/d7803.lon1.stableserver.net): (CF_ENABLE)
show less
Brute-Force
๐ณ๐ฑ
Site.eu
2026-06-14 12:59:02
(2 weeks ago)
Excessive 404/403 errors
Brute-Force
Anonymous
2026-06-14 06:16:10
(2 weeks ago)
CMS (WordPress or Joomla) brute force attempt.
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-14 00:16:20
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 209.42.21.165 (d7803.lon1.stableserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 209.42.21.165 (d7803.lon1.stableserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 20:16:15.648398 2026] [security2:error] [pid 5208:tid 5208] [client 209.42.21.165:45066] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.sizefinder.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.sizefinder.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai3yz_ElmIkuBmZ6mvTC9gAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-06-13 03:31:39
(2 weeks ago)
(wp_login_try) srv103 WP Login Attempt 209.42.21.165 (GB/United Kingdom/d7803.lon1.stableserver.net) ...
show more
(wp_login_try) srv103 WP Login Attempt 209.42.21.165 (GB/United Kingdom/d7803.lon1.stableserver.net): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
mnsf
2026-05-11 06:06:20
(1 month ago)
Too many Status 40X (12)
Scanning/Probing (12)
Brute-Force
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-05-11 05:31:38
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-10 20:41:45
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 209.42.21.165 (d7803.lon1.stableserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 209.42.21.165 (d7803.lon1.stableserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 16:41:39.667645 2026] [security2:error] [pid 21007:tid 21007] [client 209.42.21.165:44502] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||epetsure.co|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "epetsure.co"] [uri "/wp-json/wp/v2/users"] [unique_id "agDtg-KrHhkINQ9tFe3h-gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack