๐บ๐ธ
TPI-Abuse
2024-04-26 10:56:20
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 148.66.145.137 (sg3plcpnl0012.prod.sin3.secures ...
show more
(mod_security) mod_security (id:225170) triggered by 148.66.145.137 (sg3plcpnl0012.prod.sin3.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 26 06:56:14.273649 2024] [security2:error] [pid 29367:tid 47753835128576] [client 148.66.145.137:51765] [client 148.66.145.137] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.munatseng.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.munatseng.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ZiuIToAOYH5LWme1E_2fywAAARg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-25 21:35:46
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 148.66.145.137 (sg3plcpnl0012.prod.sin3.secures ...
show more
(mod_security) mod_security (id:225170) triggered by 148.66.145.137 (sg3plcpnl0012.prod.sin3.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 25 17:35:41.673100 2024] [security2:error] [pid 28367] [client 148.66.145.137:34260] [client 148.66.145.137] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||int.mavikalem.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "int.mavikalem.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ZirMrev3m-ZyXvyA6JBL5gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-25 15:14:26
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 148.66.145.137 (sg3plcpnl0012.prod.sin3.secures ...
show more
(mod_security) mod_security (id:225170) triggered by 148.66.145.137 (sg3plcpnl0012.prod.sin3.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 25 11:14:21.980517 2024] [security2:error] [pid 3614857] [client 148.66.145.137:23589] [client 148.66.145.137] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rockinr.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rockinr.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ZipzTVvqsoVM_8S5IXasdQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-25 14:43:35
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 148.66.145.137 (sg3plcpnl0012.prod.sin3.secures ...
show more
(mod_security) mod_security (id:225170) triggered by 148.66.145.137 (sg3plcpnl0012.prod.sin3.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 25 10:43:31.647372 2024] [security2:error] [pid 302832] [client 148.66.145.137:26286] [client 148.66.145.137] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||frederickayers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "frederickayers.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZipsE3k54zzj9xEjxsuVHwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-25 12:17:06
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 148.66.145.137 (sg3plcpnl0012.prod.sin3.secures ...
show more
(mod_security) mod_security (id:225170) triggered by 148.66.145.137 (sg3plcpnl0012.prod.sin3.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 25 08:17:00.498397 2024] [security2:error] [pid 26393] [client 148.66.145.137:22414] [client 148.66.145.137] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||constructionloansfunding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "constructionloansfunding.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZipJvCHZNAzrywoPSCh_rAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
weblite
2024-04-25 08:18:22
(2 years ago)
WP_AUTHOR_SCANNING WP_XMLRPC_ABUSE
Brute-Force
Web App Attack
๐ง๐ช
taivas.nl
2024-04-25 04:32:23
(2 years ago)
Many_bad_calls
Web App Attack
๐ง๐ช
taivas.nl
2024-04-25 02:02:12
(2 years ago)
Bad_requests
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-04-11 21:04:24
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 148.66.145.137 (sg3plcpnl0012.prod.sin3.secures ...
show more
(mod_security) mod_security (id:225170) triggered by 148.66.145.137 (sg3plcpnl0012.prod.sin3.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 11 17:04:16.867820 2024] [security2:error] [pid 25276] [client 148.66.145.137:27114] [client 148.66.145.137] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mail.nomorenicenice.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mail.nomorenicenice.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ZhhQUFYcrdePZDAaUSuz5wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-11 13:47:27
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 148.66.145.137 (sg3plcpnl0012.prod.sin3.secures ...
show more
(mod_security) mod_security (id:225170) triggered by 148.66.145.137 (sg3plcpnl0012.prod.sin3.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 11 09:47:21.118651 2024] [security2:error] [pid 3159350] [client 148.66.145.137:63306] [client 148.66.145.137] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ohanameetup.party|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ohanameetup.party"] [uri "/wp-json/wp/v2/users"] [unique_id "Zhfp6S8EPOTOHxhUUHF9qwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-04-11 09:11:00
(2 years ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
Anonymous
2024-04-03 05:22:08
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2024-03-31 07:53:08
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฌ๐ง
Swiptly
2024-03-25 20:36:34
(2 years ago)
WordPress xmlrpc spam or enumeration
...
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-16 13:50:15
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 148.66.145.137 (sg3plcpnl0012.prod.sin3.secures ...
show more
(mod_security) mod_security (id:225170) triggered by 148.66.145.137 (sg3plcpnl0012.prod.sin3.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 16 08:50:10.357268 2024] [security2:error] [pid 30876] [client 148.66.145.137:53885] [client 148.66.145.137] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||metavalve.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "metavalve.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZaaJkoRS6vfSY0rKWHb6DAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack