๐บ๐ธ
TPI-Abuse
2025-09-10 12:03:37
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 138.199.22.229 (unn-138-199-22-229.datapacket.c ...
show more
(mod_security) mod_security (id:225170) triggered by 138.199.22.229 (unn-138-199-22-229.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 10 08:03:32.191376 2025] [security2:error] [pid 18314:tid 18314] [client 138.199.22.229:6864] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.creationorevolution.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.creationorevolution.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "aMFpFMmdACW-sfDgGMnoowAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-28 09:42:03
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 138.199.22.229 (unn-138-199-22-229.datapacket.c ...
show more
(mod_security) mod_security (id:225170) triggered by 138.199.22.229 (unn-138-199-22-229.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 28 05:41:59.043104 2025] [security2:error] [pid 1831:tid 1831] [client 138.199.22.229:24534] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.crystaljohns.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.crystaljohns.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aIdF5yTXhlxrzH-OEsZ5MQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
rtbh.com.tr
2025-06-24 20:07:20
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐น๐ท
rtbh.com.tr
2025-06-23 20:07:18
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐ซ๐ท
ELYAZ
2025-06-14 17:23:01
(1 year ago)
(wordpress) Failed wordpress login from 138.199.22.229 (JP/Japan/unn-138-199-22-229.datapacket.com)
Brute-Force
Anonymous
2025-04-18 15:15:01
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐น๐ท
rtbh.com.tr
2025-04-10 00:06:00
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐น๐ท
rtbh.com.tr
2025-04-09 20:06:00
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐ฎ๐ฉ
Burayot
2025-03-20 21:08:23
(1 year ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 138.199.22.229 (JP/Japan/unn-138-19 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 138.199.22.229 (JP/Japan/unn-138-199-22-229.datapacket.com): 1 in the last 3600 secs
show less
Web App Attack
๐ฉ๐ช
Blexyel
2025-02-22 06:04:57
(1 year ago)
138.199.22.229 - - [22/Feb/2025:07:04:56 +0100] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 1832 ...
show more
138.199.22.229 - - [22/Feb/2025:07:04:56 +0100] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 1832 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐ฏ๐ต
UJP
2024-11-23 14:05:00
(1 year ago)
SQL
DDoS Attack
SQL Injection
Anonymous
2024-11-20 16:03:52
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ธ๐ช
Lemmy
2024-11-01 12:35:18
(1 year ago)
apache-noscript
Web App Attack
๐บ๐ธ
hostseries
2024-10-28 19:41:59
(1 year ago)
Trigger: LF_DISTATTACK
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-10-09 01:52:03
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 138.199.22.229 (unn-138-199-22-229.datapacket.c ...
show more
(mod_security) mod_security (id:225170) triggered by 138.199.22.229 (unn-138-199-22-229.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 08 21:51:59.770307 2024] [security2:error] [pid 16153:tid 16153] [client 138.199.22.229:16753] [client 138.199.22.229] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.lgbtqhistoryinaustin.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.lgbtqhistoryinaustin.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZwXhvw099izlYJ2Nxn1hsgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack