๐บ๐ธ
TPI-Abuse
2026-06-12 10:38:49
(16 hours ago)
(mod_security) mod_security (id:225170) triggered by 82.159.176.21 (82.159.176.21.static.user.ono.co ...
show more
(mod_security) mod_security (id:225170) triggered by 82.159.176.21 (82.159.176.21.static.user.ono.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 06:38:42.131356 2026] [security2:error] [pid 31251:tid 31268] [client 82.159.176.21:44632] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.amazinglips.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.amazinglips.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aivhstuKFSSM0t0fnhgvvgAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 08:54:51
(17 hours ago)
(mod_security) mod_security (id:225170) triggered by 82.159.176.21 (82.159.176.21.static.user.ono.co ...
show more
(mod_security) mod_security (id:225170) triggered by 82.159.176.21 (82.159.176.21.static.user.ono.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 04:54:48.065390 2026] [security2:error] [pid 9956:tid 9956] [client 82.159.176.21:33687] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.alsetsystems.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.alsetsystems.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aivJWAg5gIE13fSsJ9HRzAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-06-12 00:25:31
(1 day ago)
Unauthorized access to webpage admin
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-12 00:20:39
(1 day ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-11 23:13:46
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 82.159.176.21 (82.159.176.21.static.user.ono.co ...
show more
(mod_security) mod_security (id:225170) triggered by 82.159.176.21 (82.159.176.21.static.user.ono.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 19:13:38.557214 2026] [security2:error] [pid 1079:tid 1079] [client 82.159.176.21:36019] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.badgerkelley.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.badgerkelley.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aitBIsk4sw6AjfBz2HyJ8QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 22:06:35
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 82.159.176.21 (82.159.176.21.static.user.ono.co ...
show more
(mod_security) mod_security (id:225170) triggered by 82.159.176.21 (82.159.176.21.static.user.ono.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 18:06:28.648014 2026] [security2:error] [pid 10107:tid 10107] [client 82.159.176.21:45387] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.fundingangelinvestors.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.fundingangelinvestors.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aisxZGG-NHETfIVl9_cOXAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 18:00:08
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 82.159.176.21 (82.159.176.21.static.user.ono.co ...
show more
(mod_security) mod_security (id:225170) triggered by 82.159.176.21 (82.159.176.21.static.user.ono.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 13:59:59.110225 2026] [security2:error] [pid 5438:tid 5438] [client 82.159.176.21:11483] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.soundtrax.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.soundtrax.net"] [uri "/wp-json/wp/v2/users"] [unique_id "air3n1YNr__0u8ppZl_d7AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 11:29:19
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 82.159.176.21 (82.159.176.21.static.user.ono.co ...
show more
(mod_security) mod_security (id:225170) triggered by 82.159.176.21 (82.159.176.21.static.user.ono.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 07:29:15.996484 2026] [security2:error] [pid 24703:tid 24703] [client 82.159.176.21:39300] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.kathydumesnilart.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.kathydumesnilart.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiqcC6trHEzG_c4DolvXKwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-11 10:28:00
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
Anonymous
2026-06-11 07:44:23
(1 day ago)
82.159.176.21 - - [11/Jun/2026:09:44:18 +0200] "POST /xmlrpc.php HTTP/1.1" 200 206 "-" "Mozilla/5.0 ...
show more
82.159.176.21 - - [11/Jun/2026:09:44:18 +0200] "POST /xmlrpc.php HTTP/1.1" 200 206 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:53.0) Gecko/20100101 Firefox/53.0"
82.159.176.21 - - [11/Jun/2026:09:44:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 577 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:53.0) Gecko/20100101 Firefox/53.0"
82.159.176.21 - - [11/Jun/2026:09:44:21 +0200] "POST /xmlrpc.php HTTP/1.1" 200 206 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0"
82.159.176.21 - - [11/Jun/2026:09:44:15 +0200] "POST /xmlrpc.php HTTP/1.1" 200 577 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0"
82.159.176.21 - - [11/Jun/2026:09:44:23 +0200] "POST /xmlrpc.php HTTP/1.1" 200 206 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101 Firefox/91.0"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 02:44:52
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 82.159.176.21 (82.159.176.21.static.user.ono.co ...
show more
(mod_security) mod_security (id:225170) triggered by 82.159.176.21 (82.159.176.21.static.user.ono.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 22:44:47.002510 2026] [security2:error] [pid 31608:tid 31632] [client 82.159.176.21:45922] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.tkfay.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.tkfay.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiohHoIXe11BrYU8L_PYhgAAANY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-06-10 22:33:06
(2 days ago)
Brute-Force
Web App Attack
๐ณ๐ฑ
debestelapp
2026-06-10 11:55:03
(2 days ago)
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-06-10 05:22:36
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 82.159.176.21 (82.159.176.21.static.user.ono.co ...
show more
(mod_security) mod_security (id:225170) triggered by 82.159.176.21 (82.159.176.21.static.user.ono.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 01:22:32.804753 2026] [security2:error] [pid 29158:tid 29158] [client 82.159.176.21:42878] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.havenlaneministries.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.havenlaneministries.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aij0mH17H_F1lz1FZSHWHAAAAFA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
rsiddall
2026-06-10 02:47:45
(2 days ago)
82.159.176.21 - - [09/Jun/2026:22:47:45 -0400] "POST /xmlrpc.php HTTP/1.1" 403 1809 "-" "Mozilla/5.0 ...
show more
82.159.176.21 - - [09/Jun/2026:22:47:45 -0400] "POST /xmlrpc.php HTTP/1.1" 403 1809 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:64.0) Gecko/20100101 Firefox/64.0"
82.159.176.21 - - [09/Jun/2026:22:47:45 -0400] "POST /xmlrpc.php HTTP/1.1" 403 1809 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0"
...
show less
Brute-Force