๐ซ๐ท
N3ilawx
2024-11-08 20:24:49
(1 year ago)
Fail2Ban detect something wrong with this ip 165.232.165.58 - GET - 404 - [08/Nov/2024:20:24:46 +000 ...
show more
Fail2Ban detect something wrong with this ip 165.232.165.58 - GET - 404 - [08/Nov/2024:20:24:46 +0000]
165.232.165.58 - GET - 404 - [08/Nov/2024:20:24:46 +0000]
165.232.165.58 - GET - 404 - [08/Nov/2024:20:24:46 +0000]
165.232.165.58 - GET - 404 - [08/Nov/2024:20:24:47 +0000]
165.232.165.58 - GET - 404 - [08/Nov/2024:20:24:47 +0000]
165.232.165.58 - GET - 404 - [08/Nov/2024:20:24:47 +0000]
165.232.165.58 - GET - 404 - [08/Nov/2024:20:24:47 +0000]
165.232.165.58 - GET - 404 - [08/Nov/2024:20:24:47 +0000]
165.232.165.58 - GET - 404 - [08/Nov/2024:20:24:48 +0000]
165.232.165.58 - GET - 404 - [08/Nov/2024:20:24:48 +0000]
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
Major Hostility
2024-11-08 04:26:27
(1 year ago)
"GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /xmlrpc.php?rsd HTTP/1.1" 403
"GET /blog/wp-inc ...
show more
"GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /xmlrpc.php?rsd HTTP/1.1" 403
"GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /website/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /wp/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /news/wp-includes/wlwmanifest.xml HTTP/1.1" 404
show less
Web App Attack
Anonymous
2024-11-08 00:35:52
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ง๐ช
cmbplf
2024-11-07 16:31:22
(1 year ago)
2.352 requests to */wp-includes/wlwmanifest.xml
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-11-07 02:15:47
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 165.232.165.58 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 165.232.165.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 06 21:15:43.939989 2024] [security2:error] [pid 27165:tid 27165] [client 165.232.165.58:56554] [client 165.232.165.58] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.abilityengraving.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.abilityengraving.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Zywiz0UtwcXhO4y35juG9gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-11-06 15:56:58
(1 year ago)
[redacted]to 165.232.165.58 - - [06/Nov/2024:16:56:53 +0100] "POST //xmlrpc.php HTTP/1.1" 200 404 "- ...
show more
[redacted]to 165.232.165.58 - - [06/Nov/2024:16:56:53 +0100] "POST //xmlrpc.php HTTP/1.1" 200 404 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
[redacted]to 165.232.165.58 - - [06/Nov/2024:16:56:54 +0100] "POST //xmlrpc.php HTTP/1.1" 200 404 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
[redacted]to 165.232.165.58 - - [06/Nov/2024:16:56:54 +0100] "POST //xmlrpc.php HTTP/1.1" 200 404 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
[redacted]to 165.232.165.58 - - [06/Nov/2024:16:56:55 +0100] "POST //xmlrpc.php HTTP/1.1" 200 404 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
[redacted]to 165.232.165.58 - - [06/Nov/2024:16:56:55 +0100] "POST //xmlrpc.php HTTP/1.1" 200 404 "-" "Mozilla/5.0 (Windows NT
...
show less
Web App Attack
Anonymous
2024-11-06 05:41:06
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2024-11-06 03:48:12
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 165.232.165.58 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 165.232.165.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 05 22:48:05.456516 2024] [security2:error] [pid 6088:tid 6088] [client 165.232.165.58:60004] [client 165.232.165.58] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.blacksheepoffroad.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.blacksheepoffroad.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Zyrm9QrXhVuGyEpNfXruSgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-06 00:28:31
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 165.232.165.58 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 165.232.165.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 05 19:28:26.197344 2024] [security2:error] [pid 30822:tid 30822] [client 165.232.165.58:54165] [client 165.232.165.58] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.elpaco.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.elpaco.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "Zyq4KnmoV6GNtnx-oXTA5gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-11-05 20:36:15
(1 year ago)
(wordpress) Failed wordpress login from 165.232.165.58 (SG/Singapore/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-11-05 19:14:49
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 165.232.165.58 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 165.232.165.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 05 14:14:45.847010 2024] [security2:error] [pid 8975:tid 8975] [client 165.232.165.58:57028] [client 165.232.165.58] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nessmonsters.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nessmonsters.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZypupWjpHBn2VLYSN2SSMAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-05 18:59:09
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 165.232.165.58 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 165.232.165.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 05 13:59:05.824142 2024] [security2:error] [pid 25928:tid 25928] [client 165.232.165.58:62799] [client 165.232.165.58] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.sbeii.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.sbeii.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Zypq-TYeZCU1SMYWDcrfjAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-05 18:38:50
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 165.232.165.58 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 165.232.165.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 05 13:38:43.211169 2024] [security2:error] [pid 15221:tid 15221] [client 165.232.165.58:53189] [client 165.232.165.58] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.creationorevolution.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.creationorevolution.net"] [uri "/mrprentice/index.htm/wp-json/wp/v2/users/"] [unique_id "ZypmM_W9s_o8kBB-81jV_QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-05 18:22:32
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 165.232.165.58 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 165.232.165.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 05 13:22:29.105264 2024] [security2:error] [pid 23848:tid 23848] [client 165.232.165.58:61436] [client 165.232.165.58] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.fritsknuf.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.fritsknuf.com"] [uri "/blog/wp-json/wp/v2/users/"] [unique_id "ZypiZcBALQNNyW8sCGA2GQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kgstokes
2024-11-05 18:09:00
(1 year ago)
xmlrpc.php attack
Brute-Force
Web App Attack