๐บ๐ธ
TPI-Abuse
2025-06-05 16:12:45
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 138.199.22.231 (unn-138-199-22-231.datapacket.c ...
show more
(mod_security) mod_security (id:225170) triggered by 138.199.22.231 (unn-138-199-22-231.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 05 12:12:42.142666 2025] [security2:error] [pid 2536074:tid 2536074] [client 138.199.22.231:24264] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.1832wos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.1832wos.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aEHB-qcpOo5ICfMVho9TqwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
dot.mg
2025-05-10 03:51:04
(1 year ago)
XmlRpc Abuse
Bad Web Bot
Anonymous
2025-04-10 11:42:42
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฉ๐ช
Vegascosmetics
2025-03-26 22:52:24
(1 year ago)
Kingcopy(AI-IDS):IP is Probing for Wordpress vulnerabilities WTF:Banned
Hacking
Bad Web Bot
Web App Attack
๐ฌ๐ง
djboddington
2025-03-11 06:13:22
(1 year ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-01 18:48:20
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 138.199.22.231 (unn-138-199-22-231.datapacket.c ...
show more
(mod_security) mod_security (id:225170) triggered by 138.199.22.231 (unn-138-199-22-231.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 01 14:48:14.007755 2024] [security2:error] [pid 3953740:tid 3953761] [client 138.199.22.231:36543] [client 138.199.22.231] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.greaternorthmiamihistory.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.greaternorthmiamihistory.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZqvYbgkwo7hGcgB8HfyqqAAAAJE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-07-19 04:29:34
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2024-07-11 19:57:03
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 138.199.22.231 (unn-138-199-22-231.datapacket.c ...
show more
(mod_security) mod_security (id:225170) triggered by 138.199.22.231 (unn-138-199-22-231.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 11 15:56:55.141740 2024] [security2:error] [pid 11711:tid 47407997388544] [client 138.199.22.231:7588] [client 138.199.22.231] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||peluqueriabuhos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "peluqueriabuhos.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZpA5By0x1brRLcXxQ1FNXwAAAIQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-07-11 15:07:12
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 138.199.22.231 (unn-138-199-22-231.datapacket.c ...
show more
(mod_security) mod_security (id:225170) triggered by 138.199.22.231 (unn-138-199-22-231.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 11 11:07:06.022242 2024] [security2:error] [pid 17259] [client 138.199.22.231:54211] [client 138.199.22.231] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fromstlouis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fromstlouis.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Zo_1Gvbf1umE45kxlxWUTwAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-07-11 13:00:27
(2 years ago)
Unauthorized login attempts [ wordpress-xmlrpc]
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-13 05:03:25
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 138.199.22.231 (unn-138-199-22-231.datapacket.c ...
show more
(mod_security) mod_security (id:225170) triggered by 138.199.22.231 (unn-138-199-22-231.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 13 01:03:17.913100 2024] [security2:error] [pid 4716] [client 138.199.22.231:18142] [client 138.199.22.231] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mykidsdaycare.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mykidsdaycare.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "Zmp9lUotINPXLo_rX82ifAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
ozisp.com.au
2024-05-29 22:33:49
(2 years ago)
EU_RIPE_<33>1717022027 [1:2031502:4] ET INFO Request to Hidden Environment File - Inbound [Classific ...
show more
EU_RIPE_<33>1717022027 [1:2031502:4] ET INFO Request to Hidden Environment File - Inbound [Classification: Misc activity] [Priority: 3] {TCP} 138.199.22.231:2162
show less
Hacking
๐ช๐ธ
10dencehispahard SL
2024-05-29 14:00:06
(2 years ago)
Unauthorized login attempts [ wordpress-xmlrpc]
Brute-Force
Web App Attack
๐ฉ๐ช
applemooz
2024-05-22 05:30:33
(2 years ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-18 23:59:21
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 138.199.22.231 (unn-138-199-22-231.datapacket.c ...
show more
(mod_security) mod_security (id:225170) triggered by 138.199.22.231 (unn-138-199-22-231.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 18 19:59:18.504211 2024] [security2:error] [pid 5988] [client 138.199.22.231:37191] [client 138.199.22.231] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dgereviews.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dgereviews.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZiGz1u5sT6qsvh7dA-eonAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack