URAN Publishing Service
2024-09-08 09:37:29
(2 hours ago)
124.6.178.213 - - [08/Sep/2024:12:37:27 +0300] "GET /wp-login.php HTTP/1.1" 404 2618 "-" "Mozilla/5. ... show more 124.6.178.213 - - [08/Sep/2024:12:37:27 +0300] "GET /wp-login.php HTTP/1.1" 404 2618 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko"
124.6.178.213 - - [08/Sep/2024:12:37:29 +0300] "GET /xmlrpc.php HTTP/1.1" 404 366 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko"
... show less
Web App Attack
MAGIC
2024-09-06 04:12:14
(2 days ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
TPI-Abuse
2024-09-03 07:42:18
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 124.6.178.213 (-): 1 in the last 300 secs; Port ... show more (mod_security) mod_security (id:225170) triggered by 124.6.178.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 03 03:42:11.469397 2024] [security2:error] [pid 13638:tid 13638] [client 124.6.178.213:60510] [client 124.6.178.213] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tradersworldmarket.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tradersworldmarket.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "Zta90w_dT4nZMhl1KOEppwAAAAs"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2024-09-02 23:30:07
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 124.6.178.213 (-): 1 in the last 300 secs; Port ... show more (mod_security) mod_security (id:225170) triggered by 124.6.178.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 02 19:29:56.002856 2024] [security2:error] [pid 28668:tid 28668] [client 124.6.178.213:55902] [client 124.6.178.213] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.waterspell.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.waterspell.net"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ZtZKdCaKadxG7mfxg4rG8QAAAAc"] show less
Brute-Force
Bad Web Bot
Web App Attack
nationaleventpros.com
2024-08-31 22:12:50
(1 week ago)
WordPress login attempt
Brute-Force
statistics indonesia
2024-08-30 08:03:46
(1 week ago)
XML RPC Scan Activities
Brute-Force
Web App Attack
MAGIC
2024-08-29 05:06:31
(1 week ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Ba-Yu
2024-08-27 02:29:43
(1 week ago)
WordPress hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
axllent
2024-08-25 23:24:48
(1 week ago)
Wordpress login scanning
Brute-Force
Web App Attack
rdpguard.com
2024-08-24 18:50:08
(2 weeks ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
bigorre.org
2024-08-19 01:12:22
(2 weeks ago)
suspicious query, Sniffing for wordpress log:/wp-login.php
Web App Attack
TPI-Abuse
2024-08-15 09:21:59
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 124.6.178.213 (-): 1 in the last 300 secs; Port ... show more (mod_security) mod_security (id:225170) triggered by 124.6.178.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 15 05:21:51.094884 2024] [security2:error] [pid 19707:tid 19823] [client 124.6.178.213:50029] [client 124.6.178.213] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.wdmtexas.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.wdmtexas.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "Zr3Ir97kPHwghXgYUZic7gAAARE"] show less
Brute-Force
Bad Web Bot
Web App Attack
MAGIC
2024-08-15 00:06:30
(3 weeks ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
URAN Publishing Service
2024-08-13 08:59:39
(3 weeks ago)
124.6.178.213 - - [13/Aug/2024:11:59:34 +0300] "GET /wp-login.php HTTP/1.1" 404 2620 "-" "Mozilla/5. ... show more 124.6.178.213 - - [13/Aug/2024:11:59:34 +0300] "GET /wp-login.php HTTP/1.1" 404 2620 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko"
124.6.178.213 - - [13/Aug/2024:11:59:37 +0300] "GET /xmlrpc.php HTTP/1.1" 404 366 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko"
... show less
Web App Attack
TPI-Abuse
2024-08-09 04:20:46
(4 weeks ago)
(mod_security) mod_security (id:225170) triggered by 124.6.178.213 (-): 1 in the last 300 secs; Port ... show more (mod_security) mod_security (id:225170) triggered by 124.6.178.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 00:20:39.400368 2024] [security2:error] [pid 28740:tid 28754] [client 124.6.178.213:56061] [client 124.6.178.213] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.killasgarage.bike|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.killasgarage.bike"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ZrWZF133jwYa2g_3NZ_2YAAAAAw"] show less
Brute-Force
Bad Web Bot
Web App Attack