๐บ๐ธ
octageeks.com
2025-02-28 05:19:46
(1 year ago)
Wordpress malicious attack:[octaxmlrpc]
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-12 10:09:28
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 104.167.26.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 104.167.26.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 12 05:09:21.986322 2025] [security2:error] [pid 1013370:tid 1013370] [client 104.167.26.64:41585] [client 104.167.26.64] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fintastic.co.za|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fintastic.co.za"] [uri "/wp-json/wp/v2/users"] [unique_id "Z4OU0TVIoFPyLGA_5ifClwAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-01-11 13:35:54
(1 year ago)
WP Login Scan Activities
Web App Attack
๐ซ๐ท
Sklurk
2025-01-11 01:42:33
(1 year ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-03 18:44:37
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 104.167.26.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 104.167.26.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 03 13:44:29.954187 2025] [security2:error] [pid 4164059:tid 4164059] [client 104.167.26.64:26365] [client 104.167.26.64] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||intersession.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "intersession.net"] [uri "/wp-json/wp/v2/users"] [unique_id "Z3gwDWDOkHLrIi5z2qkFfAAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-12-30 06:59:39
(1 year ago)
Attempted brute force login to web vpn 17 time(s); last attempt for 2024.12.30 is noted in report ti ...
show more
Attempted brute force login to web vpn 17 time(s); last attempt for 2024.12.30 is noted in report timestamp
show less
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-12-28 21:35:25
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 104.167.26.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 104.167.26.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 28 16:35:18.954166 2024] [security2:error] [pid 25604:tid 25604] [client 104.167.26.64:32197] [client 104.167.26.64] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||idahostem.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "idahostem.org"] [uri "/wp-json/wp/v2/users"] [unique_id "Z3BvFme8zcj86y7pKeOhUgAAAAg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-28 19:56:39
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 104.167.26.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 104.167.26.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 28 14:56:35.067040 2024] [security2:error] [pid 187787:tid 187787] [client 104.167.26.64:46065] [client 104.167.26.64] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||riverflow.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "riverflow.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z3BX8xpQJaOnBoFXNvzbtgAAAAU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-12-28 01:14:35
(1 year ago)
104.167.26.64 - - [28/Dec/2024:02:14:29 +0100] "GET /wp-login.php HTTP/1.1" 404 47 "https://www.goog ...
show more
104.167.26.64 - - [28/Dec/2024:02:14:29 +0100] "GET /wp-login.php HTTP/1.1" 404 47 "https://www.google.com" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-24 20:15:02
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 104.167.26.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 104.167.26.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 24 15:14:58.298799 2024] [security2:error] [pid 9857:tid 9857] [client 104.167.26.64:44651] [client 104.167.26.64] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||swwpccpa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "swwpccpa.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z2sWQs7RxUjqIcvK2rMjJgAAABY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-12-24 17:39:12
(1 year ago)
xmlrpc attack blocked attempt from fail2ban
...
Web App Attack
Anonymous
2024-11-20 10:59:12
(1 year ago)
"Failed VPN brute force attack on invalid and valid accounts"
Brute-Force
๐บ๐ธ
octageeks.com
2024-11-20 05:07:16
(1 year ago)
Wordpress malicious attack:[octaflood]
Web App Attack