πΊπΈ
TPI-Abuse
2026-06-19 23:16:46
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 210.5.50.135 (plesk-lnx02.1stdomains.net.nz): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 210.5.50.135 (plesk-lnx02.1stdomains.net.nz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 19:16:40.216064 2026] [security2:error] [pid 1327:tid 1327] [client 210.5.50.135:57294] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||vintageamptubes.ink2wear.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "vintageamptubes.ink2wear.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajXN2BmV_RJoFSPoD8qEtwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-06-19 12:21:22
(2 days ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 210.5.50.135 (NZ/New Zealand/plesk-lnx02.1std ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 210.5.50.135 (NZ/New Zealand/plesk-lnx02.1stdomains.net.nz): 1 in the last 3600 secs (0-195)
show less
Hacking
π©πͺ
FeG Deutschland
2026-06-19 09:07:25
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-18 05:16:33
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 210.5.50.135 (plesk-lnx02.1stdomains.net.nz): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 210.5.50.135 (plesk-lnx02.1stdomains.net.nz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 01:16:28.102660 2026] [security2:error] [pid 31731:tid 31731] [client 210.5.50.135:59164] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dev.jeanniemorrislaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dev.jeanniemorrislaw.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ajN_LH0zi8z7WRwRbCCuzAAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
tecnicorioja
2026-06-17 22:01:05
(4 days ago)
wp-login attack [17/Jun/2026:06:20:30
Brute-Force
Web App Attack
π©πͺ
AlexEventfahrtenIPDB
2026-06-17 18:01:24
(4 days ago)
[Wed Jun 17 20:01:21.146685 2026] [authz_core:error] [pid 1097631:tid 1097631] [client 210.5.50.135: ...
show more
[Wed Jun 17 20:01:21.146685 2026] [authz_core:error] [pid 1097631:tid 1097631] [client 210.5.50.135:46880] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php
[Wed Jun 17 20:01:24.251340 2026] [authz_core:error] [pid 1097648:tid 1097648] [client 210.5.50.135:46992] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php, referer: https://alex-eventfahrten.spdns.de/wp-login.php
...
show less
Brute-Force
Web App Attack
π«π·
masterguru
2026-06-17 03:46:51
(4 days ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 210.5.50.135 (NZ/New Zealand/plesk-lnx02.1std ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 210.5.50.135 (NZ/New Zealand/plesk-lnx02.1stdomains.net.nz): 1 in the last 3600 secs (0-196)
show less
Hacking
πΊπΈ
TPI-Abuse
2026-06-16 17:21:12
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 210.5.50.135 (plesk-lnx02.1stdomains.net.nz): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 210.5.50.135 (plesk-lnx02.1stdomains.net.nz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 13:21:07.669048 2026] [security2:error] [pid 20191:tid 20196] [client 210.5.50.135:53270] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||councilofforeignministers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "councilofforeignministers.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ajGGA713JVhgiepTSsGRcgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Hazzard
2026-06-16 09:28:23
(5 days ago)
(wordpress) Failed wordpress login from 210.5.50.135 (NZ/New Zealand/-/-/plesk-lnx02.1stdomains.net. ...
show more
(wordpress) Failed wordpress login from 210.5.50.135 (NZ/New Zealand/-/-/plesk-lnx02.1stdomains.net.nz/[redacted]): (CF_ENABLE)
show less
Brute-Force
πΊπΈ
TPI-Abuse
2026-06-15 22:48:56
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 210.5.50.135 (plesk-lnx02.1stdomains.net.nz): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 210.5.50.135 (plesk-lnx02.1stdomains.net.nz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 18:48:50.923818 2026] [security2:error] [pid 5329:tid 5329] [client 210.5.50.135:48282] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||yerevanpress.am|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "yerevanpress.am"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ajCBUueFXD06ZvIMmuUMfgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-30 21:01:48
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 210.5.50.135 (plesk-lnx02.1stdomains.net.nz): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 210.5.50.135 (plesk-lnx02.1stdomains.net.nz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 17:01:42.594714 2026] [security2:error] [pid 28508:tid 28508] [client 210.5.50.135:48094] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||alsetsystems.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "alsetsystems.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahtQNpZbks92RmT5tdCAGAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-05-23 08:33:15
(4 weeks ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 210.5.50.135 (NZ/New Zealand/plesk-lnx02.1std ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 210.5.50.135 (NZ/New Zealand/plesk-lnx02.1stdomains.net.nz): 1 in the last 3600 secs (0-195)
show less
Hacking
π©πͺ
FeG Deutschland
2026-05-21 04:52:35
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
πͺπΈ
librebit
2026-05-21 00:14:28
(1 month ago)
Brute force
Brute-Force
π©πͺ
FeG Deutschland
2026-05-15 03:03:51
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack