🇺🇸
TPI-Abuse
2026-09-04 21:17:45
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 45.159.21.243 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.159.21.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:17:41.431909 2026] [security2:error] [pid 2103:tid 2103] [client 45.159.21.243:42423] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||szeliga.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "szeliga.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aps1dUqk72uJY_asRugDJgAAAAs"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-09-01 00:49:05
(1 week ago)
Web password guessing
Brute-Force
🇺🇸
TPI-Abuse
2026-08-26 19:20:55
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 45.159.21.243 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.159.21.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 15:20:50.839463 2026] [security2:error] [pid 28838:tid 28838] [client 45.159.21.243:40075] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jmgrigg.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jmgrigg.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ao88ktz4uLDYA4HQ5LghoQAAAAw"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-08-18 21:06:29
(3 weeks ago)
Web password guessing
Brute-Force
🇮🇹
VHosting
2026-08-18 19:50:04
(3 weeks ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇮🇹
VHosting
2026-08-11 10:25:03
(4 weeks ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
🇫🇷
dynamix
2026-08-06 01:24:27
(1 month ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-08-05 21:13:47
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 45.159.21.243 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.159.21.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 05 17:13:40.829045 2026] [security2:error] [pid 3626652:tid 3626652] [client 45.159.21.243:19925] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||maffiniandbearce.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "maffiniandbearce.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anOnhMKqW35Gfaz3Z3ZBgAAAAA0"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-08-03 17:19:55
(1 month ago)
Web password guessing
Brute-Force
🇺🇸
TPI-Abuse
2026-07-27 11:24:56
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 45.159.21.243 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.159.21.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 07:24:48.363529 2026] [security2:error] [pid 148946:tid 148946] [client 45.159.21.243:32755] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||brewerfs.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "brewerfs.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amdAAFmCeas_bVOo9e4fVwAAAA8"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-07-25 15:25:03
(1 month ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
🇫🇷
Tilellit.PRO
2026-06-29 08:35:46
(2 months ago)
Fail2Ban banned 45.159.21.243 for security violations in jail wp-armour. Log: 2026/06/29 08:35:45 [e ...
show more
Fail2Ban banned 45.159.21.243 for security violations in jail wp-armour. Log: 2026/06/29 08:35:45 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 45.159.21.243 | Target: wplogin" , client: 45.159.21.243, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
🇫🇷
Tilellit.PRO
2026-06-27 08:50:32
(2 months ago)
Fail2Ban banned 45.159.21.243 for security violations in jail wp-armour. Log: 2026/06/27 08:50:31 [e ...
show more
Fail2Ban banned 45.159.21.243 for security violations in jail wp-armour. Log: 2026/06/27 08:50:31 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 45.159.21.243 | Target: wplogin" , client: 45.159.21.243, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
🇪🇸
librebit
2026-06-14 05:27:16
(2 months ago)
Brute force
Brute-Force
🇺🇸
TPI-Abuse
2026-06-09 09:18:40
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 45.159.21.243 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.159.21.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 05:18:35.704664 2026] [security2:error] [pid 2561:tid 2561] [client 45.159.21.243:33655] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jkperis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jkperis.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aifaa_TswcrqX-jL0Wc9gwAAAA8"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack