๐ฉ๐ช
BlueWire Hosting
2026-08-28 00:24:24
(11 minutes ago)
Probing websites for vulnerabilities
Web App Attack
SQL Injection
๐ซ๐ท
masterguru
2026-08-28 00:19:15
(17 minutes ago)
(PERMBLOCK) 209.42.31.213 (DE/Germany/d20348.fra1.stableserver.net) has had more than 4 temp blocks ...
show more
(PERMBLOCK) 209.42.31.213 (DE/Germany/d20348.fra1.stableserver.net) has had more than 4 temp blocks in the last 86400 secs (0-193)
show less
Hacking
๐ฉ๐ช
Marc
2026-08-28 00:14:23
(21 minutes ago)
209.42.31.213 - - [27/Aug/2026:22:54:34 +0200] "GET /wp-login.php HTTP/2.0" 200 3453 "-" "Mozilla/5. ...
show more
209.42.31.213 - - [27/Aug/2026:22:54:34 +0200] "GET /wp-login.php HTTP/2.0" 200 3453 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" 209.42.31.213 - - [27/Aug/2026:22:54:35 +0200] "POST /wp-login.php HTTP/2.0" 200 3290 "https://alsarnsberg.eu/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" 209.42.31.213 - - [28/Aug/2026:00:26:46 +0200] "GET /wp-login.php HTTP/2.0" 200 3923 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" 209.42.31.213 - - [28/Aug/2026:01:31:59 +0200] "GET /wp-login.php HTTP/2.0" 200 3922 "https://weiss-blau-hemer.de/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" 209.42.31.213 - - [28/Aug/2026:02:14:22 +0200] "GET /wp-login.php HTTP/2.0" 200 4256 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleW
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 00:05:14
(31 minutes ago)
(mod_security) mod_security (id:225170) triggered by 209.42.31.213 (d20348.fra1.stableserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 209.42.31.213 (d20348.fra1.stableserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 20:05:07.946527 2026] [security2:error] [pid 1031:tid 1031] [client 209.42.31.213:43658] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lambert-heating-and-air.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lambert-heating-and-air.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apDQs09oC4E5kilph1Q4VwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-28 00:02:15
(34 minutes ago)
(wordpress) Apache: Failed WordPress login from 209.42.31.213 (DE/Germany/d20348.fra1.stableserver.n ...
show more
(wordpress) Apache: Failed WordPress login from 209.42.31.213 (DE/Germany/d20348.fra1.stableserver.net): 10 in the last 3600 secs (0-201)
show less
Hacking
๐ฉ๐ช
expandmade.com
2026-08-27 23:17:52
(1 hour ago)
unauthorized rest api call [27/Aug/2026:23:17:52 "GET /wp-json/wp/v2/users/me"]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 23:05:26
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 209.42.31.213 (d20348.fra1.stableserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 209.42.31.213 (d20348.fra1.stableserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 19:05:22.299594 2026] [security2:error] [pid 10847:tid 10847] [client 209.42.31.213:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||avaliantlife.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "avaliantlife.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apDCsm17vPijOuoWnIMSuAAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
karger
2026-08-27 22:35:56
(2 hours ago)
Wordpress attack - soft filter
Brute-Force
Web App Attack
๐ฉ๐ช
Click-Networks
2026-08-27 22:11:15
(2 hours ago)
Web Spam
Brute-Force
Exploited Host
๐ซ๐ท
tecnicorioja
2026-08-27 22:01:17
(2 hours ago)
wp-login attack [27/Aug/2026:12:05:51
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-08-27 21:58:31
(2 hours ago)
WordPress login brute-force | path: /wp-login.php | 2026-08-27 21:58 UTC
Brute-Force
Web App Attack
๐ฉ๐ช
AlexEventfahrtenIPDB
2026-08-27 21:58:05
(2 hours ago)
[Thu Aug 27 23:58:03.256840 2026] [authz_core:error] [pid 1630:tid 1638] [remote 209.42.31.213:60842 ...
show more
[Thu Aug 27 23:58:03.256840 2026] [authz_core:error] [pid 1630:tid 1638] [remote 209.42.31.213:60842] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php
[Thu Aug 27 23:58:04.633729 2026] [authz_core:error] [pid 1630:tid 1635] [remote 209.42.31.213:60848] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php, referer: https://powerstar.spdns.de/wp-login.php
...
show less
Brute-Force
Web App Attack
๐ช๐ธ
alferez
2026-08-27 21:32:45
(3 hours ago)
Multiple WP Login Attack
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
etu brutus
2026-08-27 20:58:24
(3 hours ago)
209.42.31.213 Blocked by [Attack Vector List]
...
Hacking
Brute-Force
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-08-27 20:10:58
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 209.42.31.213 (d20348.fra1.stableserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 209.42.31.213 (d20348.fra1.stableserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 16:10:52.135038 2026] [security2:error] [pid 30268:tid 30397] [client 209.42.31.213:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mindgardens.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mindgardens.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apCZzOxOAJ3ND1LqEbKbYQAAAYo"]
show less
Brute-Force
Bad Web Bot
Web App Attack