๐บ๐ธ
WeekendWeb
2025-10-06 20:35:55
(8 months ago)
Wordpress Vunerability attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-05 16:43:46
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 156.253.171.96 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 156.253.171.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 05 12:43:40.949206 2025] [security2:error] [pid 12652:tid 12652] [client 156.253.171.96:56633] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jennyfiore.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jennyfiore.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aOKgPKjYFIyrk1BnrMlAPgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-09-30 17:16:19
(8 months ago)
[redacted] 156.253.171.96 - - [30/Sep/2025:19:15:52 +0200] "POST /xmlrpc.php HTTP/1.1" 200 448 "-" " ...
show more
[redacted] 156.253.171.96 - - [30/Sep/2025:19:15:52 +0200] "POST /xmlrpc.php HTTP/1.1" 200 448 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_3; en-us) AppleWebKit/531.21.11 (KHTML, like Gecko) Version/4.0.4 Safari/531.21.10"
[redacted] 156.253.171.96 - - [30/Sep/2025:19:16:01 +0200] "POST /xmlrpc.php HTTP/1.1" 200 448 "-" "Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.2.10) Gecko/20100914 Firefox/3.6.10"
[redacted] 156.253.171.96 - - [30/Sep/2025:19:16:03 +0200] "POST /xmlrpc.php HTTP/1.1" 200 448 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/65.0.3325.181 Safari/537.36"
[redacted] 156.253.171.96 - - [30/Sep/2025:19:16:08 +0200] "POST /xmlrpc.php HTTP/1.1" 200 448 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 10_3_1 like Mac OS X) AppleWebKit/602.1.50 (KHTML, like Gecko) GSA/26.0.154727556 Mobile/14E304 Safari/602.1"
[redacted] 156.253.171.96 - - [30/Sep/2025:19:16:08 +0200] "POST /xmlrpc.php HTTP/1.1" 200 448 "-"
...
show less
Hacking
Web App Attack
๐ฉ๐ช
applemooz
2025-09-26 22:35:26
(8 months ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
Anonymous
2025-09-23 19:34:18
(8 months ago)
WordPress Brute Force
Brute-Force
๐ฉ๐ช
Packets-Decreaser.NET
2025-09-15 04:04:55
(8 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
Rip
2025-09-13 05:33:23
(8 months ago)
Apache Authentication attack. CMS Brute Force - Access Forbidden
Brute-Force
Web App Attack
๐ฉ๐ช
Ba-Yu
2025-08-25 03:43:44
(9 months ago)
WP-xmlrpc exploit
Web Spam
Blog Spam
Hacking
Exploited Host
Web App Attack
๐ฉ๐ช
Admins@FBN
2025-07-03 13:06:56
(11 months ago)
VPN Logon Failed: AAA user authentication Rejected user = <vpntest>
Brute-Force
Exploited Host
Anonymous
2025-07-03 05:33:11
(11 months ago)
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.07.03 is noted in report tim ...
show more
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.07.03 is noted in report timestamp
show less
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-06-06 07:54:33
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 156.253.171.96 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 156.253.171.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 06 03:54:28.721448 2025] [security2:error] [pid 1606519:tid 1606646] [client 156.253.171.96:45479] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gryphix.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gryphix.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aEKetOmleefJlY_dTjMzVAAAAIk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2025-06-05 04:30:05
(1 year ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐ฎ๐ฉ
Burayot
2025-05-30 18:56:18
(1 year ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 156.253.171.96 (GB/United Kingdom/- ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 156.253.171.96 (GB/United Kingdom/-): 1 in the last 3600 secs
show less
Web App Attack
๐ฆ๐บ
MAGIC
2025-05-02 23:04:55
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ฉ๐ช
ps-center
2025-05-02 14:08:21
(1 year ago)
C1: Web Attack GET /wp-login.php
Web Spam
Hacking
Bad Web Bot
Web App Attack