๐บ๐ธ
TPI-Abuse
2025-10-04 12:48:54
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 156.233.84.34 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 156.233.84.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 04 08:48:49.041355 2025] [security2:error] [pid 24748:tid 24748] [client 156.233.84.34:46911] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||braintechsoftwaresolutions.com:80|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "braintechsoftwaresolutions.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aOEXseHSkarsezZDuZqXtAAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2025-10-04 00:05:08
(8 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-09-29 22:18:29
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 156.233.84.34 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 156.233.84.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 29 18:18:26.131066 2025] [security2:error] [pid 16745:tid 16745] [client 156.233.84.34:19141] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||madisonmedia.ai|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "madisonmedia.ai"] [uri "/wp-json/wp/v2/users/"] [unique_id "aNsFsjw68T613ddqvtbkSAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2025-09-28 21:51:00
(8 months ago)
Kingcopy(AI-IDS):IP is Probing for Wordpress vulnerabilities WTF:Banned
Hacking
Bad Web Bot
Web App Attack
Anonymous
2025-09-26 21:01:33
(8 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฉ๐ช
Packets-Decreaser.NET
2025-09-15 21:46:43
(8 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
Anonymous
2025-09-11 22:37:10
(8 months ago)
2025-09-12T00:37:09.637109+02:00 zanati wp(www.sahpa.co.za)[2492421]: Blocked authentication attempt ...
show more
2025-09-12T00:37:09.637109+02:00 zanati wp(www.sahpa.co.za)[2492421]: Blocked authentication attempt for [email protected] from 156.233.84.34
...
show less
Web App Attack
Anonymous
2025-09-02 11:12:46
(9 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-08-30 04:02:07
(9 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-08-28 14:46:02
(9 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2024-12-30 07:35:30
(1 year ago)
Attempted brute force login to web vpn 10 time(s); last attempt for 2024.12.30 is noted in report ti ...
show more
Attempted brute force login to web vpn 10 time(s); last attempt for 2024.12.30 is noted in report timestamp
show less
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-12-08 21:59:20
(1 year ago)
(mod_security) mod_security (id:217280) triggered by 156.233.84.34 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:217280) triggered by 156.233.84.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 08 16:59:13.447813 2024] [security2:error] [pid 29410:tid 29410] [client 156.233.84.34:55633] [client 156.233.84.34] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:\\\\n|\\\\r)+(?:get|post|head|options|connect|put|delete|trace|propfind|propatch|mkcol|copy|move|lock|unlock)\\\\s+" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "137"] [id "217280"] [rev "6"] [msg "COMODO WAF: HTTP Request Smuggling Attack||www.elenacampo.com|F|2"] [data "Matched Data: get found within MATCHED_VAR"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "www.elenacampo.com"] [uri "/es/contacto.php"] [unique_id "Z1YWseNu4aek67poZBsQTQAAAAA"], referer: https://www.elenacampo.com/es/contacto.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
hostseries
2024-10-13 19:01:39
(1 year ago)
Trigger: LF_DISTATTACK
Brute-Force