๐ฌ๐ง
thetomtaylor.co.uk
2025-10-03 12:02:52
(8 months ago)
Fail2Ban - [NGINX]WordPress Logins Sniffings on nginx-wordpress-sniffer
... [wa02]
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-29 18:23:53
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 156.253.168.191 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.253.168.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 29 14:23:50.149544 2025] [security2:error] [pid 3821:tid 3821] [client 156.253.168.191:33143] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||evolinc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "evolinc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aNrOtjDycjXJh83k3QE0vAAAAAM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
neogenius
2025-09-29 15:35:16
(9 months ago)
Web App Attack
Brute-Force
Web App Attack
๐ฉ๐ช
bsoft.de
2025-08-05 09:13:20
(10 months ago)
156.253.168.191 - - [05/Aug/2025:11:12:50 +0200] "GET /wp-json/wp/v2/users HTTP/1.1" 404 144 "https: ...
show more
156.253.168.191 - - [05/Aug/2025:11:12:50 +0200] "GET /wp-json/wp/v2/users HTTP/1.1" 404 144 "https://www.google.com" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
156.253.168.191 - - [05/Aug/2025:11:13:09 +0200] "POST /xmlrpc.php HTTP/1.1" 200 181 "-" "Apache-HttpClient/4.5.13 (Java/11.0.28)"
156.253.168.191 - - [05/Aug/2025:11:13:19 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Apache-HttpClient/4.5.13 (Java/11.0.28)"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-31 19:48:56
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 156.253.168.191 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.253.168.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 31 15:48:53.872548 2025] [security2:error] [pid 600:tid 600] [client 156.253.168.191:28381] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ploverdyne.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ploverdyne.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aIvIpSI5Q8PcmWX6Av2fYgAAAAs"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-07-30 20:05:27
(10 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-07-25 12:26:05
(11 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-05-20 00:00:44
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 156.253.168.191 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.253.168.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 19 20:00:41.187113 2025] [security2:error] [pid 3664168:tid 3664168] [client 156.253.168.191:42593] [client 156.253.168.191] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||calvarycavaliers.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "calvarycavaliers.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aCvGKcL_Qd0_UDdG8M5ltgAAAA4"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-05-18 05:27:34
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-05-13 19:22:26
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 156.253.168.191 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.253.168.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 13 15:22:22.355657 2025] [security2:error] [pid 2995287:tid 2995312] [client 156.253.168.191:21475] [client 156.253.168.191] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||progenicyte.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "progenicyte.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aCOb7tHgAcZ_6FR4DG7whgAAAFM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-05-02 11:09:47
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-04-30 12:10:26
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-04-24 10:11:37
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฆ๐บ
oncord
2025-04-23 01:48:10
(1 year ago)
Form spam
Web Spam
๐ฆ๐บ
oncord
2025-04-21 16:18:59
(1 year ago)
Form spam
Web Spam