๐บ๐ธ
TPI-Abuse
2026-06-29 00:14:06
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 82.165.90.45 (infong-eu-sd0064.clienthosting.eu ...
show more
(mod_security) mod_security (id:225170) triggered by 82.165.90.45 (infong-eu-sd0064.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 20:14:02.063626 2026] [security2:error] [pid 30603:tid 30603] [client 82.165.90.45:48664] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cnphilos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cnphilos.com"] [uri "/wp-json/wp/v2/users/5"] [unique_id "akG4yhjwSJvVrQfSd6cwjwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ambor
2026-06-28 22:39:01
(9 hours ago)
Honeypot access: PHP file scan attempt: /blog/xmlrpc.php. Path: /blog/xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-28 20:35:13
(11 hours ago)
(mod_security) mod_security (id:225170) triggered by 82.165.90.45 (infong-eu-sd0064.clienthosting.eu ...
show more
(mod_security) mod_security (id:225170) triggered by 82.165.90.45 (infong-eu-sd0064.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 16:35:05.143428 2026] [security2:error] [pid 26482:tid 26482] [client 82.165.90.45:36924] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||instalatoribucuresti.com.apexhumanoidrobots.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "instalatoribucuresti.com.apexhumanoidrobots.com"] [uri "/wp-json/wp/v2/users"] [unique_id "akGFeRnkbYrF0hCB-6aDZAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-28 20:01:56
(11 hours ago)
(mod_security) mod_security (id:225170) triggered by 82.165.90.45 (infong-eu-sd0064.clienthosting.eu ...
show more
(mod_security) mod_security (id:225170) triggered by 82.165.90.45 (infong-eu-sd0064.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 16:01:49.995610 2026] [security2:error] [pid 6518:tid 6518] [client 82.165.90.45:49488] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||brainstormer.visionremota.info|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "brainstormer.visionremota.info"] [uri "/wp-json/wp/v2/users"] [unique_id "akF9rS95hoFTZppKJicW7gAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-28 17:59:12
(13 hours ago)
(mod_security) mod_security (id:225170) triggered by 82.165.90.45 (infong-eu-sd0064.clienthosting.eu ...
show more
(mod_security) mod_security (id:225170) triggered by 82.165.90.45 (infong-eu-sd0064.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 13:59:06.452856 2026] [security2:error] [pid 4887:tid 4887] [client 82.165.90.45:49666] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||midway-island.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "midway-island.com"] [uri "/wp-json/wp/v2/users/2"] [unique_id "akFg6mbz5kLt8VfZa437HwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-28 03:48:50
(1 day ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 82.165.90.45 (DE/Germany/infong-eu-sd0064.cli ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 82.165.90.45 (DE/Germany/infong-eu-sd0064.clienthosting.eu): 1 in the last 3600 secs (0-196)
show less
Hacking
๐ซ๐ท
tecnicorioja
2026-06-27 22:01:11
(1 day ago)
wp-login attack [27/Jun/2026:13:33:10
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 19:49:07
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 82.165.90.45 (infong-eu-sd0064.clienthosting.eu ...
show more
(mod_security) mod_security (id:225170) triggered by 82.165.90.45 (infong-eu-sd0064.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 15:49:00.775790 2026] [security2:error] [pid 7651:tid 7651] [client 82.165.90.45:37630] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tenmenband.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tenmenband.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajrjLOqfOH1fed0uI5JwQwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 15:16:27
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 82.165.90.45 (infong-eu-sd0064.clienthosting.eu ...
show more
(mod_security) mod_security (id:225170) triggered by 82.165.90.45 (infong-eu-sd0064.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 11:16:20.493250 2026] [security2:error] [pid 11999:tid 11999] [client 82.165.90.45:41636] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||brushmileage.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "brushmileage.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ajqjRE8rYRTAJEydok3izwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ท
setupgr
2026-06-22 17:14:03
(6 days ago)
(mod_security) mod_security (id:900001) triggered by 82.165.90.45 (DE/Germany/Baden-Wurttemberg/Karl ...
show more
(mod_security) mod_security (id:900001) triggered by 82.165.90.45 (DE/Germany/Baden-Wurttemberg/Karlsruhe/-/[AS8560 IONOS-AS This is the joint network for IONOS, Fasthosts, Arsys, 1&1 Mail and Media and 1&1 Telecom. Formerly known as 1&1 Internet SE.]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Mon Jun 22 20:14:01.568740 2026] [security2:error] [pid 1934693:tid 1934717] [remote 82.165.90.45:52352] ModSecurity: Access denied with code 403 (phase 1). Match of "rx ^(www\\\\.)?(pankoskal\\\\.gr|sea-sound\\\\.com)$" against "REQUEST_HEADERS:Host" required. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "75"] [id "900001"] [msg "Blocked WP Login attempt on domain: pose.gr"] [severity "CRITICAL"] [tag "security"] [hostname "pose.gr"] [uri "/wp-login.php"] [unique_id "ajltWWyIwtP6yf56A0qoAAAARAE"]
show less
Port Scan
๐ฒ๐ฝ
octageeks.com
2026-06-20 04:20:02
(1 week ago)
Wordpress malicious attack:[octawp]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 19:47:11
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 82.165.90.45 (infong-eu-sd0064.clienthosting.eu ...
show more
(mod_security) mod_security (id:225170) triggered by 82.165.90.45 (infong-eu-sd0064.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 15:47:07.396612 2026] [security2:error] [pid 12297:tid 12297] [client 82.165.90.45:47264] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||btccasting.com.bamedica.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "btccasting.com.bamedica.com"] [uri "/wp-json/wp/v2/users/10"] [unique_id "ajWcu8lq6Qgqlh6gEh2vkwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-06-15 09:20:07
(1 week ago)
Wordfence waf block on registrymatters
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-13 02:21:08
(2 weeks ago)
Try to access /xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 21:13:02
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 82.165.90.45 (infong-eu-sd0064.clienthosting.eu ...
show more
(mod_security) mod_security (id:225170) triggered by 82.165.90.45 (infong-eu-sd0064.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 17:12:54.540571 2026] [security2:error] [pid 16650:tid 16650] [client 82.165.90.45:48736] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||abundancecompany.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "abundancecompany.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aix2Vr1R35xzpfF40Ce_EgAAAAI"], referer: https://abundancecompany.com/
show less
Brute-Force
Bad Web Bot
Web App Attack