๐ซ๐ท
SpaceHost-Server
2026-06-20 22:31:19
(1 day ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 16:43:06
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 5.175.40.183 (cloud-358674-mix.servidor.hosting ...
show more
(mod_security) mod_security (id:225170) triggered by 5.175.40.183 (cloud-358674-mix.servidor.hosting): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 12:42:55.825176 2026] [security2:error] [pid 1216:tid 1216] [client 5.175.40.183:33190] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.texascottagebakers.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.texascottagebakers.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ajbDD8v_x7rkkx4iuu_vSwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-20 16:27:46
(1 day ago)
[redacted] 5.175.40.183 - - [20/Jun/2026:18:27:45 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mo ...
show more
[redacted] 5.175.40.183 - - [20/Jun/2026:18:27:45 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:63.0) Gecko/20100101 Firefox/63.0"
[redacted] 5.175.40.183 - - [20/Jun/2026:18:27:45 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0"
[redacted] 5.175.40.183 - - [20/Jun/2026:18:27:45 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0"
[redacted] 5.175.40.183 - - [20/Jun/2026:18:27:45 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:45.0) Gecko/20100101 Firefox/45.0"
[redacted] 5.175.40.183 - - [20/Jun/2026:18:27:45 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0"
[redacted] 5.175.40.183 - - [20/Jun/2026:18:27:45 +0200] "POST /xmlrpc.php HTTP/1
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 15:37:12
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 5.175.40.183 (cloud-358674-mix.servidor.hosting ...
show more
(mod_security) mod_security (id:225170) triggered by 5.175.40.183 (cloud-358674-mix.servidor.hosting): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 11:37:07.783588 2026] [security2:error] [pid 13980:tid 13980] [client 5.175.40.183:46352] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.jellisonrepair.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.jellisonrepair.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajazoy3OfC9giIsTB5mGEAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 14:00:51
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 5.175.40.183 (cloud-358674-mix.servidor.hosting ...
show more
(mod_security) mod_security (id:225170) triggered by 5.175.40.183 (cloud-358674-mix.servidor.hosting): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 10:00:46.700252 2026] [security2:error] [pid 7117:tid 7117] [client 5.175.40.183:58340] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.rohanbyles.com.au|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.rohanbyles.com.au"] [uri "/wp-json/wp/v2/users"] [unique_id "ajadDm_jwnu8MiWJJZ3XIwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-19 20:45:57
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 18:22:07
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 5.175.40.183 (cloud-358674-mix.servidor.hosting ...
show more
(mod_security) mod_security (id:225170) triggered by 5.175.40.183 (cloud-358674-mix.servidor.hosting): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 14:22:01.747360 2026] [security2:error] [pid 4049:tid 4049] [client 5.175.40.183:33982] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.nancyscafeandcatering.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.nancyscafeandcatering.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajWIya5ReNT8_D7uUGutwgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-19 01:33:00
(3 days ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ซ๐ท
โจ
2026-06-18 00:46:13
(4 days ago)
Domain : gherkindomains.co.uk
Rule : xmlrpc
2026-06-18 00:45:11 217.194.210.153 POST /xmlrpc.php - 8 ...
show more
Domain : gherkindomains.co.uk
Rule : xmlrpc
2026-06-18 00:45:11 217.194.210.153 POST /xmlrpc.php - 80 - 5.175.40.183 HTTP/1.1 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:68.0) Gecko/20100101 Firefox/68.0 - www.gherkindomains.co.uk 404 5 0 1455 399 351 - -
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 19:39:23
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 5.175.40.183 (cloud-358674-mix.servidor.hosting ...
show more
(mod_security) mod_security (id:225170) triggered by 5.175.40.183 (cloud-358674-mix.servidor.hosting): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 15:39:14.379341 2026] [security2:error] [pid 23368:tid 23368] [client 5.175.40.183:43250] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.greensandbeans.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.greensandbeans.us"] [uri "/wp-json/wp/v2/users"] [unique_id "ajL34mbrNnqXi9e0YfF5aAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 09:11:54
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 5.175.40.183 (cloud-358674-mix.servidor.hosting ...
show more
(mod_security) mod_security (id:225170) triggered by 5.175.40.183 (cloud-358674-mix.servidor.hosting): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 05:11:45.847326 2026] [security2:error] [pid 27446:tid 27446] [client 5.175.40.183:43014] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.genevainvestors.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.genevainvestors.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajJk0ebg5xsGILZ8a14rBgAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 21:10:06
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 5.175.40.183 (cloud-358674-mix.servidor.hosting ...
show more
(mod_security) mod_security (id:225170) triggered by 5.175.40.183 (cloud-358674-mix.servidor.hosting): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 17:09:55.867036 2026] [security2:error] [pid 13715:tid 13715] [client 5.175.40.183:37018] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.doctoredwinalvarez.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.doctoredwinalvarez.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajG7oyfB_JpmpcBrKB9sFQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 19:37:12
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 5.175.40.183 (cloud-358674-mix.servidor.hosting ...
show more
(mod_security) mod_security (id:225170) triggered by 5.175.40.183 (cloud-358674-mix.servidor.hosting): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 15:37:07.050581 2026] [security2:error] [pid 15927:tid 15927] [client 5.175.40.183:43436] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.benchmarkbcs.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.benchmarkbcs.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajGl47N-h3yo6PaIm5UwBQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 09:18:54
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 5.175.40.183 (cloud-358674-mix.servidor.hosting ...
show more
(mod_security) mod_security (id:225170) triggered by 5.175.40.183 (cloud-358674-mix.servidor.hosting): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 05:18:49.915374 2026] [security2:error] [pid 3741:tid 3741] [client 5.175.40.183:60136] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.doctorbalog.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.doctorbalog.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajEU-VTkRNouwanCdeRMDwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 09:58:36
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 5.175.40.183 (cloud-358674-mix.servidor.hosting ...
show more
(mod_security) mod_security (id:225170) triggered by 5.175.40.183 (cloud-358674-mix.servidor.hosting): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 05:58:31.173095 2026] [security2:error] [pid 4307:tid 4307] [client 5.175.40.183:36974] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nessmonsters.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nessmonsters.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiaSRx4ti-wJL326gyunUgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack