๐ฌ๐ง
NotCool
2026-06-18 04:06:22
(12 hours ago)
[7200] (WPLOGIN,XMLRPC) Login failure/trigger from 85.10.154.175 (NL/The Netherlands/plesk2.sfera.ne ...
show more
[7200] (WPLOGIN,XMLRPC) Login failure/trigger from 85.10.154.175 (NL/The Netherlands/plesk2.sfera.net): 50 in the last 3600 secs
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-17 20:20:42
(20 hours ago)
(mod_security) mod_security (id:225170) triggered by 85.10.154.175 (plesk2.sfera.net): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 85.10.154.175 (plesk2.sfera.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 16:20:34.159950 2026] [security2:error] [pid 1037:tid 1037] [client 85.10.154.175:53132] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.greensandbeans.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.greensandbeans.us"] [uri "/wp-json/wp/v2/users"] [unique_id "ajMBkpjIO5yjn-YDfw42ZwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-17 02:50:17
(1 day ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ฌ๐ง
NotCool
2026-06-17 02:18:09
(1 day ago)
[7200] (WPLOGIN,XMLRPC) Login failure/trigger from 85.10.154.175 (NL/The Netherlands/plesk2.sfera.ne ...
show more
[7200] (WPLOGIN,XMLRPC) Login failure/trigger from 85.10.154.175 (NL/The Netherlands/plesk2.sfera.net): 50 in the last 3600 secs
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-16 23:20:12
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 85.10.154.175 (plesk2.sfera.net): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 85.10.154.175 (plesk2.sfera.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 19:20:08.811768 2026] [security2:error] [pid 30180:tid 30202] [client 85.10.154.175:38984] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||coasterdvdsonline.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "coasterdvdsonline.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajHaKLG0PTOBpIcoRnLt3AAAAJQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 08:08:21
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 85.10.154.175 (plesk2.sfera.net): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 85.10.154.175 (plesk2.sfera.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 04:08:15.564993 2026] [security2:error] [pid 2562:tid 2562] [client 85.10.154.175:56902] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.hawaiivacations.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.hawaiivacations.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajEEb_T203eMqJIF-A0QgQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 23:56:51
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 85.10.154.175 (plesk2.sfera.net): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 85.10.154.175 (plesk2.sfera.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 19:56:47.040215 2026] [security2:error] [pid 7864:tid 7864] [client 85.10.154.175:41702] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.crep-psych.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.crep-psych.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ai8_v9_6T-AtFawxndbBYAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-06-13 19:36:19
(4 days ago)
Blocked by CSF 13 firewall - Rule: FR/France/plesk2.sfera.net
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 13:10:32
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 85.10.154.175 (plesk2.sfera.net): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 85.10.154.175 (plesk2.sfera.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 09:10:27.259457 2026] [security2:error] [pid 14546:tid 14546] [client 85.10.154.175:48556] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tarekshohaieb.online|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tarekshohaieb.online"] [uri "/wp-json/wp/v2/users"] [unique_id "aiwFQ6G4UN_W7XtXgIwi4gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 09:29:38
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 85.10.154.175 (plesk2.sfera.net): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 85.10.154.175 (plesk2.sfera.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 05:29:34.672444 2026] [security2:error] [pid 8181:tid 8181] [client 85.10.154.175:55118] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.convtek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.convtek.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aivRfowMDMPoc2KdKJ2rlwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 17:39:17
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 85.10.154.175 (plesk2.sfera.net): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 85.10.154.175 (plesk2.sfera.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 13:39:11.545402 2026] [security2:error] [pid 29891:tid 29891] [client 85.10.154.175:48170] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.allotrope.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.allotrope.com"] [uri "/wp-json/wp/v2/users"] [unique_id "airyvza3MSpIebYgkZR1kwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 18:39:47
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 85.10.154.175 (plesk2.sfera.net): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 85.10.154.175 (plesk2.sfera.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 14:39:39.893675 2026] [security2:error] [pid 22208:tid 22233] [client 85.10.154.175:38818] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.datuinc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.datuinc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aimva9cqV9rOfKI5d1iwawAAAVQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 14:21:07
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 85.10.154.175 (plesk2.sfera.net): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 85.10.154.175 (plesk2.sfera.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 10:21:02.369885 2026] [security2:error] [pid 4625:tid 4625] [client 85.10.154.175:39132] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||joevallone.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "joevallone.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ailyzp8ZZD7w2rS3vUf8HgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 19:33:01
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 85.10.154.175 (plesk2.sfera.net): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 85.10.154.175 (plesk2.sfera.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 15:32:55.119405 2026] [security2:error] [pid 2552:tid 2552] [client 85.10.154.175:47834] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.littlecreekrvranch.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.littlecreekrvranch.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiXHZ0COwSmzhIXLd9uEVAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-07 11:03:19
(1 week ago)
[redacted] 85.10.154.175 - - [07/Jun/2026:13:03:16 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "M ...
show more
[redacted] 85.10.154.175 - - [07/Jun/2026:13:03:16 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:86.0) Gecko/20100101 Firefox/86.0"
[redacted] 85.10.154.175 - - [07/Jun/2026:13:03:16 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:48.0) Gecko/20100101 Firefox/48.0"
[redacted] 85.10.154.175 - - [07/Jun/2026:13:03:16 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:87.0) Gecko/20100101 Firefox/87.0"
[redacted] 85.10.154.175 - - [07/Jun/2026:13:03:16 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0"
[redacted] 85.10.154.175 - - [07/Jun/2026:13:03:16 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0"
[redacted] 85.10.154.1
...
show less
Hacking
Web App Attack