๐บ๐ธ
TPI-Abuse
2026-01-03 09:59:18
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 82.165.87.158 (infongwp-eu62.clienthosting.eu): ...
show more
(mod_security) mod_security (id:225170) triggered by 82.165.87.158 (infongwp-eu62.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 03 04:59:12.318320 2026] [security2:error] [pid 9371:tid 9371] [client 82.165.87.158:52930] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pschitchat.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pschitchat.com"] [uri "/wp-json/wp/v2/usErs"] [unique_id "aVjocOjNBLeW4EhYl8g1jAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-01-02 10:04:48
(9 months ago)
Blocking for trying to access an exploit file: /xmlrpc.php
Hacking
๐บ๐ธ
TPI-Abuse
2025-12-12 03:30:22
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 82.165.87.158 (infongwp-eu62.clienthosting.eu): ...
show more
(mod_security) mod_security (id:225170) triggered by 82.165.87.158 (infongwp-eu62.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 11 22:30:19.048283 2025] [security2:error] [pid 5482:tid 5482] [client 82.165.87.158:52618] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||36sovereignchambers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "36sovereignchambers.com"] [uri "/index.php/wp-json/wp/v2/users"] [unique_id "aTuMS7yNSUbPBe6-RcGsegAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-10 19:36:28
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 82.165.87.158 (infongwp-eu62.clienthosting.eu): ...
show more
(mod_security) mod_security (id:225170) triggered by 82.165.87.158 (infongwp-eu62.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 10 14:36:24.724444 2025] [security2:error] [pid 20464:tid 20464] [client 82.165.87.158:33370] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.drayvian.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.drayvian.com"] [uri "/wp-json/wp/V2/users"] [unique_id "aTnLuJercmQl-XNLzXtu9wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2025-12-09 17:09:23
(9 months ago)
(xmlrpc) Apache: Failed xmlrpc access from 82.165.87.158 (DE/Germany/infongwp-eu62.clienthosting.eu) ...
show more
(xmlrpc) Apache: Failed xmlrpc access from 82.165.87.158 (DE/Germany/infongwp-eu62.clienthosting.eu): 10 in the last 3600 secs (0-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2025-12-09 16:02:01
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 82.165.87.158 (infongwp-eu62.clienthosting.eu): ...
show more
(mod_security) mod_security (id:225170) triggered by 82.165.87.158 (infongwp-eu62.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 09 11:01:54.952817 2025] [security2:error] [pid 7513:tid 7513] [client 82.165.87.158:41802] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||talentstar2025.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "talentstar2025.com"] [uri "/Wp-JsOn/Wp/V2/UsErS"] [unique_id "aThH8hlK0qvDzuWlp7GXjAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-08 20:04:39
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 82.165.87.158 (infongwp-eu62.clienthosting.eu): ...
show more
(mod_security) mod_security (id:225170) triggered by 82.165.87.158 (infongwp-eu62.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 08 15:04:31.301533 2025] [security2:error] [pid 8248:tid 8248] [client 82.165.87.158:34630] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.gilgoinn.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.gilgoinn.com"] [uri "/index.php/wp-json/wp/v2/users"] [unique_id "aTcvT9bWqIZ8WfJ8Hb3AiAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-28 21:54:59
(10 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ซ๐ท
dynamix
2025-11-27 21:47:18
(10 months ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ฒ๐น
Malta
2025-11-26 08:37:58
(10 months ago)
82.165.87.158 - - [26/Nov/2025:09:37:57 +0100] "POST /xmlrpc.php HTTP/1.1" "Mozilla/4.0 (compatible; ...
show more
82.165.87.158 - - [26/Nov/2025:09:37:57 +0100] "POST /xmlrpc.php HTTP/1.1" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; Touch; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; Tablet PC 2.0)"
Brute-force password attempt
show less
Hacking
Brute-Force
Web App Attack
๐จ๐ฟ
ddw
2025-11-25 12:35:41
(10 months ago)
WordPress Brute Force Attack.
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
octageeks.com
2025-10-23 04:06:39
(11 months ago)
Wordpress malicious attack:[octawp]
Web App Attack
๐บ๐ธ
etu brutus
2025-10-22 19:06:38
(11 months ago)
82.165.87.158 has been banned for [WebApp Attack]
...
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
dtorrer
2025-10-21 12:53:14
(11 months ago)
Forged login request.
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-10-16 07:44:13
(11 months ago)
(mod_security) mod_security (id:240335) triggered by 82.165.87.158 (infongwp-eu62.clienthosting.eu): ...
show more
(mod_security) mod_security (id:240335) triggered by 82.165.87.158 (infongwp-eu62.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 16 03:44:07.217110 2025] [security2:error] [pid 14850:tid 14850] [client 82.165.87.158:44300] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 82.165.87.158 (+1 hits since last alert)|www.bradleybarefoot.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.bradleybarefoot.com"] [uri "/xmlrpc.php"] [unique_id "aPCiRzkk1WPTNDjIJCxpiAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack