๐ง๐ท
SOC PR
2026-05-06 07:36:16
(1 month ago)
IPS: WordPress HTTP Brute Force Login Attempt.
Brute-Force
๐ฎ๐ฉ
Burayot
2026-05-04 13:32:40
(1 month ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 167.253.49.190 (US/United States/-) ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 167.253.49.190 (US/United States/-): 2 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-02 10:08:03
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 167.253.49.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 167.253.49.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 02 06:07:58.866686 2026] [security2:error] [pid 18451:tid 18451] [client 167.253.49.190:9361] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||renjunews.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "renjunews.com"] [uri "/wp-json/wp/v2/users"] [unique_id "afXM_qSys3HvKI2oR-MDPQAAACI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2026-04-30 23:35:11
(1 month ago)
WP Login Scan Activities: "2026-05-01T06:35:11.710+07:00" "/wp-login.php" "167.253.49.190" "Mozilla/ ...
show more
WP Login Scan Activities: "2026-05-01T06:35:11.710+07:00" "/wp-login.php" "167.253.49.190" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
show less
Web App Attack
๐ฌ๐ง
Bytemark
2026-04-11 17:27:49
(1 month ago)
167.253.49.190 - - [11/Apr/2026:18:27:42 +0100] "GET /wp-login.php HTTP/1.1" 301 5131 "https://www.g ...
show more
167.253.49.190 - - [11/Apr/2026:18:27:42 +0100] "GET /wp-login.php HTTP/1.1" 301 5131 "https://www.google.com" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
167.253.49.190 - - [11/Apr/2026:18:27:45 +0100] "GET /wp-login.php HTTP/1.1" 404 4928 "https://www.google.com" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
167.253.49.190 - - [11/Apr/2026:18:27:48 +0100] "GET /wp-login.php HTTP/1.1" 301 5131 "https://www.google.com" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
show less
Brute-Force
Web App Attack
๐ช๐ธ
el-brujo
2026-04-03 14:04:14
(2 months ago)
[Fri Apr 03 16:04:12.466916 2026] [proxy_fcgi:error] [pid 3410977:tid 3411545] [remote 167.253.49.19 ...
show more
[Fri Apr 03 16:04:12.466916 2026] [proxy_fcgi:error] [pid 3410977:tid 3411545] [remote 167.253.49.190:0] AH01071: Got error 'Primary script unknown\n', referer: https://www.google.com
[Fri Apr 03 16:04:14.507634 2026] [proxy_fcgi:error] [pid 3410977:tid 3411422] [remote 167.253.49.190:0] AH01071: Got error 'Primary script unknown\n', referer: https://www.google.com
...
show less
Hacking
Web App Attack
๐ฉ๐ช
MusicLibrary
2026-03-24 14:30:43
(2 months ago)
Attempted access to non existent wordpress urls
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-06 15:34:02
(3 months ago)
(mod_security) mod_security (id:210350) triggered by 167.253.49.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 167.253.49.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 06 10:33:56.900250 2026] [security2:error] [pid 6346:tid 6346] [client 167.253.49.190:55613] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||phlippo.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "phlippo.com"] [uri "/"] [unique_id "aarz5IgCq9vztbq-K8kzPAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-18 16:25:32
(3 months ago)
Unauthorized VPN login attempts
Hacking
Brute-Force
๐บ๐ธ
Cyber Crusader
2026-02-12 05:06:40
(3 months ago)
Hundreds of Attempts (at least) to Connect to and Access Firewall Ports
Port Scan
Hacking
Brute-Force
๐ธ๐ฌ
pusathosting.com
2025-09-01 09:21:03
(9 months ago)
2ds22 bruteforce
Brute-Force
Web App Attack
๐จ๐ญ
backslash
2025-05-03 05:55:03
(1 year ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
Anonymous
2025-01-26 16:15:11
(1 year ago)
Automatic report - Vulnerability scan
/RDWeb/Pages/en-US/login.aspx
Web App Attack
Anonymous
2025-01-21 06:30:09
(1 year ago)
Automatic report - Vulnerability scan
/RDWeb/Pages/en-US/login.aspx
Web App Attack
Anonymous
2025-01-20 01:40:14
(1 year ago)
Automatic report - Vulnerability scan
/RDWeb/Pages/en-US/login.aspx
Web App Attack