Kieran Courtney
2025-01-14 21:48:02
(4 weeks ago)
ONTAR-40 (Velcom INC)
DNS Compromise
rtbh.com.tr
2025-01-14 20:50:48
(4 weeks ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
WeekendWeb
2025-01-14 06:14:08
(4 weeks ago)
Wordpress Vunerability attack
Web App Attack
TPI-Abuse
2025-01-14 06:00:53
(4 weeks ago)
(mod_security) mod_security (id:225170) triggered by 104.234.205.116 (-): 1 in the last 300 secs; Po ... show more (mod_security) mod_security (id:225170) triggered by 104.234.205.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 14 01:00:45.320191 2025] [security2:error] [pid 29057:tid 29057] [client 104.234.205.116:64569] [client 104.234.205.116] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.laura-stone.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.laura-stone.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Z4X9jdifmKdxxrz83yxD2wAAAAI"] show less
Brute-Force
Bad Web Bot
Web App Attack
kosada.com
2025-01-14 05:39:22
(4 weeks ago)
Web vulnerability probing
Web App Attack
Anonymous
2025-01-14 01:58:42
(4 weeks ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
taivas.nl
2025-01-14 00:02:14
(4 weeks ago)
Bad_requests
Bad Web Bot
TPI-Abuse
2025-01-13 23:40:47
(4 weeks ago)
(mod_security) mod_security (id:225170) triggered by 104.234.205.116 (-): 1 in the last 300 secs; Po ... show more (mod_security) mod_security (id:225170) triggered by 104.234.205.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 13 18:40:42.701463 2025] [security2:error] [pid 22121:tid 22121] [client 104.234.205.116:60740] [client 104.234.205.116] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||honigcpa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "honigcpa.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Z4WkemchWlL4jrMs0IRhMQAAACM"] show less
Brute-Force
Bad Web Bot
Web App Attack
bittiguru.fi
2025-01-13 21:52:01
(4 weeks ago)
WordPress brute force
Brute-Force
TPI-Abuse
2025-01-13 20:28:31
(4 weeks ago)
(mod_security) mod_security (id:225170) triggered by 104.234.205.116 (-): 1 in the last 300 secs; Po ... show more (mod_security) mod_security (id:225170) triggered by 104.234.205.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 13 15:28:23.796708 2025] [security2:error] [pid 14075:tid 14075] [client 104.234.205.116:57295] [client 104.234.205.116] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ultratecnologia.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ultratecnologia.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Z4V3Z-HEu0Fv_eV7WtGGHgAAAAE"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-01-13 15:50:58
(4 weeks ago)
(mod_security) mod_security (id:225170) triggered by 104.234.205.116 (-): 1 in the last 300 secs; Po ... show more (mod_security) mod_security (id:225170) triggered by 104.234.205.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 13 10:50:53.548957 2025] [security2:error] [pid 4154436:tid 4154436] [client 104.234.205.116:49563] [client 104.234.205.116] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.jessicalevant.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.jessicalevant.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Z4U2XZKaS9kP8znB0Iq1zwAAAAg"] show less
Brute-Force
Bad Web Bot
Web App Attack
Dolphi
2025-01-13 13:40:03
(4 weeks ago)
POST //xmlrpc.php
Brute-Force
Web App Attack
TPI-Abuse
2025-01-13 12:58:37
(4 weeks ago)
(mod_security) mod_security (id:225170) triggered by 104.234.205.116 (-): 1 in the last 300 secs; Po ... show more (mod_security) mod_security (id:225170) triggered by 104.234.205.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 13 07:58:32.012949 2025] [security2:error] [pid 30090:tid 30090] [client 104.234.205.116:49559] [client 104.234.205.116] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.calvaryadminservices.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.calvaryadminservices.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Z4UN-OAPcJiGGR-vBX3qcQAAAAc"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-01-13 10:17:58
(4 weeks ago)
(mod_security) mod_security (id:225170) triggered by 104.234.205.116 (-): 1 in the last 300 secs; Po ... show more (mod_security) mod_security (id:225170) triggered by 104.234.205.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 13 05:17:52.565995 2025] [security2:error] [pid 28382:tid 28382] [client 104.234.205.116:62010] [client 104.234.205.116] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thepercussionworks.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thepercussionworks.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Z4ToUM6nly9T5tze1aidJgAAAAM"] show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-01-13 10:17:34
(4 weeks ago)
Bot / scanning and/or hacking attempts: POST //xmlrpc.php HTTP/1.1, GET / HTTP/1.1
Hacking
Web App Attack