๐บ๐ธ
TPI-Abuse
2025-10-04 22:18:18
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 154.94.12.227 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 154.94.12.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 04 18:18:11.682652 2025] [security2:error] [pid 30137:tid 30137] [client 154.94.12.227:47863] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||drwolberg.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "drwolberg.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aOGdI-U1Q7sHJAcjHS3PdgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WeekendWeb
2025-10-04 21:10:05
(8 months ago)
Wordpress Vunerability attack
Web App Attack
๐ท๐บ
6o6ep
2025-10-02 03:45:48
(8 months ago)
xmlrpc.php trap
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-30 22:39:16
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 154.94.12.227 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 154.94.12.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 30 18:39:10.688533 2025] [security2:error] [pid 30439:tid 30439] [client 154.94.12.227:34801] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||vendor21.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "vendor21.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aNxcDt_H2X9UemgaRzGpIwAAADk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
jjnxpct
2025-09-30 03:45:04
(8 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /wp-json/wp/v2/users (Rule ID: 225170)
show less
Hacking
Web App Attack
๐ซ๐ท
dynamix
2025-09-29 00:01:11
(8 months ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ฆ๐บ
AWW-Admin
2025-09-24 22:45:13
(8 months ago)
(wordpress) Failed wordpress login from 154.94.12.227 (-)
Brute-Force
Anonymous
2025-09-20 04:35:34
(9 months ago)
[redacted] 154.94.12.227 - - [20/Sep/2025:06:35:25 +0200] "POST /xmlrpc.php HTTP/1.1" 200 401 "-" "M ...
show more
[redacted] 154.94.12.227 - - [20/Sep/2025:06:35:25 +0200] "POST /xmlrpc.php HTTP/1.1" 200 401 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:54.0) Gecko/20100101 Firefox/54.0"
[redacted] 154.94.12.227 - - [20/Sep/2025:06:35:26 +0200] "POST /xmlrpc.php HTTP/1.1" 200 401 "-" "Mozilla/5.0 (Windows NT 5.1; rv:40.0) Gecko/20100101 Firefox/40.0"
[redacted] 154.94.12.227 - - [20/Sep/2025:06:35:27 +0200] "POST /xmlrpc.php HTTP/1.1" 200 401 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6; en-us) AppleWebKit/531.9 (KHTML, like Gecko) Version/4.0.3 Safari/531.9"
[redacted] 154.94.12.227 - - [20/Sep/2025:06:35:28 +0200] "POST /xmlrpc.php HTTP/1.1" 200 401 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en) AppleWebKit/419 (KHTML, like Gecko) Safari/419.3"
[redacted] 154.94.12.227 - - [20/Sep/2025:06:35:29 +0200] "POST /xmlrpc.php HTTP/1.1" 200 401 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 8_0_2 like Mac OS X) AppleW
...
show less
Hacking
Web App Attack
๐ฉ๐ช
bsoft.de
2025-09-08 02:22:57
(9 months ago)
154.94.12.227 - - [08/Sep/2025:03:10:46 +0200] "POST /xmlrpc.php HTTP/1.1" 200 426 "-" "Mozilla/5.0 ...
show more
154.94.12.227 - - [08/Sep/2025:03:10:46 +0200] "POST /xmlrpc.php HTTP/1.1" 200 426 "-" "Mozilla/5.0 (Linux; Android 7.1.1; Moto E (4) Plus) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.64 Mobile Safari/537.36"
154.94.12.227 - - [08/Sep/2025:03:52:14 +0200] "POST /xmlrpc.php HTTP/1.1" 200 426 "-" "Mozilla/5.0 (Linux; Android 7.0; TRT-LX3 Build/HUAWEITRT-LX3; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/69.0.3497.100 Mobile Safari/537.36 [FB_IAB/FB4A;FBAV/194.0.0.42.99;]"
154.94.12.227 - - [08/Sep/2025:04:22:55 +0200] "POST /xmlrpc.php HTTP/1.1" 200 426 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
show less
Web App Attack
๐ฉ๐ช
Ba-Yu
2025-08-25 03:45:41
(9 months ago)
WP-xmlrpc exploit
Web Spam
Blog Spam
Hacking
Exploited Host
Web App Attack
Anonymous
2025-07-29 16:08:17
(10 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
COMPLEX
2025-04-29 12:50:35
(1 year ago)
Triggered Cloudflare WAF (firewallCustom) from ES.
Action taken: MANAGED_CHALLENGE
ASN: 200373 (DREI ...
show more
Triggered Cloudflare WAF (firewallCustom) from ES.
Action taken: MANAGED_CHALLENGE
ASN: 200373 (DREI-K-TECH-GMBH)
Protocol: HTTP/2 (GET method)
Timestamp: 2025-04-29T01:36:10Z
show less
Bad Web Bot
Anonymous
2025-03-22 02:04:32
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-03-06 03:52:48
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2024-12-30 01:28:31
(1 year ago)
Attempted brute force login to web vpn 10 time(s); last attempt for 2024.12.30 is noted in report ti ...
show more
Attempted brute force login to web vpn 10 time(s); last attempt for 2024.12.30 is noted in report timestamp
show less
Hacking
Brute-Force