๐บ๐ธ
TPI-Abuse
2025-03-19 12:00:32
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 160.153.154.27 (n3plwpweb056.prod.ams3.securese ...
show more
(mod_security) mod_security (id:225170) triggered by 160.153.154.27 (n3plwpweb056.prod.ams3.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 19 08:00:24.527099 2025] [security2:error] [pid 1553566:tid 1553566] [client 160.153.154.27:39336] [client 160.153.154.27] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||myvdi.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "myvdi.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z9qx2PfAyFuWIDQYw1FVswAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-25 03:33:24
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 160.153.154.27 (n3plwpweb056.prod.ams3.securese ...
show more
(mod_security) mod_security (id:225170) triggered by 160.153.154.27 (n3plwpweb056.prod.ams3.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 24 22:33:19.163502 2024] [security2:error] [pid 10598:tid 10598] [client 160.153.154.27:38770] [client 160.153.154.27] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||frenchla.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "frenchla.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z2t8_-FGHvpFr8WmdP7whQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-25 01:26:24
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 160.153.154.27 (n3plwpweb056.prod.ams3.securese ...
show more
(mod_security) mod_security (id:225170) triggered by 160.153.154.27 (n3plwpweb056.prod.ams3.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 24 20:26:20.320415 2024] [security2:error] [pid 192325:tid 192325] [client 160.153.154.27:35008] [client 160.153.154.27] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||losbarbarosdelnorte.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "losbarbarosdelnorte.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z2tfPExkYua7XqHHVlUw6AAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-25 01:10:36
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 160.153.154.27 (n3plwpweb056.prod.ams3.securese ...
show more
(mod_security) mod_security (id:225170) triggered by 160.153.154.27 (n3plwpweb056.prod.ams3.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 24 20:10:30.820150 2024] [security2:error] [pid 30630:tid 30630] [client 160.153.154.27:33214] [client 160.153.154.27] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.billwegener.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.billwegener.net"] [uri "/wp-json/wp/v2/users"] [unique_id "Z2tbho0J4Hmew8CQzOAZMAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-24 13:15:05
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 160.153.154.27 (n3plwpweb056.prod.ams3.securese ...
show more
(mod_security) mod_security (id:225170) triggered by 160.153.154.27 (n3plwpweb056.prod.ams3.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 24 08:15:00.796593 2024] [security2:error] [pid 25576:tid 25576] [client 160.153.154.27:55006] [client 160.153.154.27] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.susanleeward.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.susanleeward.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z2qz1G1xbmAk0IORkZACswAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-24 09:34:31
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 160.153.154.27 (n3plwpweb056.prod.ams3.securese ...
show more
(mod_security) mod_security (id:225170) triggered by 160.153.154.27 (n3plwpweb056.prod.ams3.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 24 04:34:24.986657 2024] [security2:error] [pid 1586:tid 1611] [client 160.153.154.27:41752] [client 160.153.154.27] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sweeneyzone.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sweeneyzone.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z2qAIIHMGPMumzJUDLULAgAAARY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-24 07:10:48
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 160.153.154.27 (n3plwpweb056.prod.ams3.securese ...
show more
(mod_security) mod_security (id:225170) triggered by 160.153.154.27 (n3plwpweb056.prod.ams3.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 24 02:10:44.351474 2024] [security2:error] [pid 11824:tid 11824] [client 160.153.154.27:59650] [client 160.153.154.27] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.maprada92.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.maprada92.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z2pedAC-yPFczOeRpdZlAQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
QT
2024-12-12 01:55:11
(1 year ago)
Unauthorised WordPress admin login attempted at 2024-12-12 11:55:05 +1000
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2024-01-04 21:18:08
(2 years ago)
Probing for Wordpress vulnerabilities
Bad Web Bot
Web App Attack
๐ซ๐ฎ
bittiguru.fi
2022-08-11 08:56:00
(4 years ago)
160.153.154.27 - - \[11/Aug/2022:15:55:59 +0300\] "POST /xmlrpc.php HTTP/1.1" 200 428 "-" "Mozilla/5 ...
show more
160.153.154.27 - - \[11/Aug/2022:15:55:59 +0300\] "POST /xmlrpc.php HTTP/1.1" 200 428 "-" "Mozilla/5.0 \(Linux\; Android 10\; SM-A102U\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/91.0.4472.114 Mobile Safari/537.36" "-"
160.153.154.27 - - \[11/Aug/2022:15:56:00 +0300\] "POST /xmlrpc.php HTTP/1.1" 200 428 "-" "Mozilla/5.0 \(Linux\; Android 10\; SM-A102U\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/91.0.4472.114 Mobile Safari/537.36" "-"
...
show less
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
SCHAPPY
2022-08-02 21:00:35
(4 years ago)
Wordpress attack
Web App Attack
๐บ๐ธ
octageeks.com
2022-08-01 00:06:06
(4 years ago)
Wordpress malicious attack:[octaxmlrpc]
Web App Attack
๐ง๐ช
taivas.nl
2022-07-31 08:32:07
(4 years ago)
Wordpress_xmlrpc_attack
Bad Web Bot
๐ฉ๐ช
maxxsense
2022-07-31 00:25:40
(4 years ago)
(wordpress) Failed wordpress login from 160.153.154.27 (NL/Netherlands/n3nlwpweb056.prod.ams3.secure ...
show more
(wordpress) Failed wordpress login from 160.153.154.27 (NL/Netherlands/n3nlwpweb056.prod.ams3.secureserver.net)
show less
Brute-Force
๐จ๐ฟ
akac
2022-07-30 21:33:50
(4 years ago)
WordPress XML-RPC attack attempt.
Request: POST /xmlrpc.php
User-Agent: Mozilla/5.0 (Windows NT 10.0 ...
show more
WordPress XML-RPC attack attempt.
Request: POST /xmlrpc.php
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36
Body: <methodCall><methodName>wp.getUsersBlogs</methodName><params><param><value>chynna</value></param><param><value>1234567890</value></param></params></methodCall>
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack