๐น๐ท
rtbh.com.tr
2025-09-25 20:09:00
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐น๐ท
rtbh.com.tr
2025-09-24 20:08:59
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐บ๐ธ
octageeks.com
2025-09-24 04:06:16
(1 year ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐ณ๐ฑ
Site.eu
2025-09-23 22:56:36
(1 year ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
SpaceHost-Server
2025-09-23 22:25:50
(1 year ago)
Brute-Force
Web App Attack
๐ณ๐ฑ
Roderic
2025-09-23 21:35:09
(1 year ago)
(wordpress-404) Searching for non-existent wordpress installs from 13.220.124.172 (US/United States/ ...
show more
(wordpress-404) Searching for non-existent wordpress installs from 13.220.124.172 (US/United States/Virginia/Ashburn/ec2-13-220-124-172.compute-1.amazonaws.com/[redacted])
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-09-23 21:04:32
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 13.220.124.172 (ec2-13-220-124-172.compute-1.am ...
show more
(mod_security) mod_security (id:225170) triggered by 13.220.124.172 (ec2-13-220-124-172.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 23 17:04:24.599173 2025] [security2:error] [pid 1468114:tid 1468156] [client 13.220.124.172:55267] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bortec-corp.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bortec-corp.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aNMLWG2nzO6BKmWiHXN6ywAAAQk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-23 20:25:24
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 13.220.124.172 (ec2-13-220-124-172.compute-1.am ...
show more
(mod_security) mod_security (id:225170) triggered by 13.220.124.172 (ec2-13-220-124-172.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 23 16:25:17.349107 2025] [security2:error] [pid 83085:tid 83085] [client 13.220.124.172:64335] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.bonvivantorganics.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.bonvivantorganics.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aNMCLemjV8KldrTzV6mGGgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-23 18:02:02
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 13.220.124.172 (ec2-13-220-124-172.compute-1.am ...
show more
(mod_security) mod_security (id:225170) triggered by 13.220.124.172 (ec2-13-220-124-172.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 23 14:01:56.718954 2025] [security2:error] [pid 17205:tid 17205] [client 13.220.124.172:51794] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||blfmarine.com.lakesidedetectiveagency.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "blfmarine.com.lakesidedetectiveagency.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aNLglDtsJhCrQSpBVnkI5gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Blexyel
2025-09-23 18:01:39
(1 year ago)
13.220.124.172 - - [23/Sep/2025:20:01:39 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 555 ...
show more
13.220.124.172 - - [23/Sep/2025:20:01:39 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "pingusmc.org"
...
show less
Brute-Force
Web App Attack
Anonymous
2025-09-23 17:51:37
(1 year ago)
Logfile match
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-23 17:46:24
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 13.220.124.172 (ec2-13-220-124-172.compute-1.am ...
show more
(mod_security) mod_security (id:225170) triggered by 13.220.124.172 (ec2-13-220-124-172.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 23 13:46:18.613848 2025] [security2:error] [pid 21392:tid 21392] [client 13.220.124.172:55553] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.blacktieokc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.blacktieokc.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aNLc6oIgUqxTC1Yodey4egAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
mondor.ro
2025-09-23 16:47:15
(1 year ago)
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 13.220.124.172, Reason ...
show more
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 13.220.124.172, Reason:[(manifest) WordPress wlwmanifest.xml Attack 13.220.124.172 (US/United States/ec2-13-220-124-172.compute-1.amazonaws.com): 10 in the last 3600 secs]; Ports: *; Direction: inout; Trigger: LF_CLUSTER; Logs:
show less
Port Scan
๐ซ๐ท
Sklurk
2025-09-23 16:42:39
(1 year ago)
Web App Attack
Web App Attack
๐ฉ๐ช
macrob
2025-09-23 16:29:48
(1 year ago)
2025/09/23 16:29:47 [error] 2480815#2480815: *1096042 access forbidden by rule, client: 13.220.124.1 ...
show more
2025/09/23 16:29:47 [error] 2480815#2480815: *1096042 access forbidden by rule, client: 13.220.124.172, server: binixo.lk, request: "GET //wp-includes/wlwmanifest.xml HTTP/2.0", host: "binixo.lk"
2025/09/23 16:29:47 [error] 2480815#2480815: *1096044 access forbidden by rule, client: 13.220.124.172, server: binixo.lk, request: "GET //xmlrpc.php?rsd HTTP/2.0", host: "binixo.lk"
2025/09/23 16:29:47 [error] 2480815#2480815: *1095982 access forbidden by rule, client: 13.220.124.172, server: binixo.lk, request: "GET //blog/wp-includes/wlwmanifest.xml HTTP/2.0", host: "binixo.lk"
...
show less
Web App Attack