πΊπΈ
TPI-Abuse
2025-10-24 15:11:09
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 176.112.239.182 (176-112-239-182.dynamic.itce.r ...
show more
(mod_security) mod_security (id:225170) triggered by 176.112.239.182 (176-112-239-182.dynamic.itce.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 24 11:11:03.879672 2025] [security2:error] [pid 29952:tid 29952] [client 176.112.239.182:59922] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||protection4allsecurity.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "protection4allsecurity.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aPuXBwzV7gMWNkLIcL-YKQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2025-10-24 11:26:46
(11 months ago)
Excessive multi-domain requests
Brute-Force
πΊπΈ
TPI-Abuse
2025-10-24 10:44:12
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 176.112.239.182 (176-112-239-182.dynamic.itce.r ...
show more
(mod_security) mod_security (id:225170) triggered by 176.112.239.182 (176-112-239-182.dynamic.itce.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 24 06:44:06.094801 2025] [security2:error] [pid 10769:tid 10769] [client 176.112.239.182:58064] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fusionrep.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fusionrep.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aPtYdqxJqlDZau3HQ2CJYgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-24 09:18:56
(11 months ago)
wordpress-trap
Web App Attack
πΊπΈ
TPI-Abuse
2025-10-24 08:55:26
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 176.112.239.182 (176-112-239-182.dynamic.itce.r ...
show more
(mod_security) mod_security (id:225170) triggered by 176.112.239.182 (176-112-239-182.dynamic.itce.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 24 04:55:20.583296 2025] [security2:error] [pid 1371281:tid 1371281] [client 176.112.239.182:56696] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sharawi-gum.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sharawi-gum.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aPs--M34WMttuM6tPheaQwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-10-23 19:53:42
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 176.112.239.182 (176-112-239-182.dynamic.itce.r ...
show more
(mod_security) mod_security (id:225170) triggered by 176.112.239.182 (176-112-239-182.dynamic.itce.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 23 15:53:33.105529 2025] [security2:error] [pid 15935:tid 15935] [client 176.112.239.182:56816] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||babylontravelone.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "babylontravelone.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aPqHvbK6d7af8kDy610b5wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
jfz-abuse
2025-10-23 16:32:30
(11 months ago)
fail2ban: apache-php-recon
...
Web App Attack
π¨π
zynex
2025-10-23 09:08:50
(11 months ago)
URL Probing: /de/xleet-shell.php
Web App Attack
π«π·
Kraften
2025-10-21 13:26:41
(11 months ago)
Web noscript attack
...
Web Spam
Web App Attack
π§π·
leolemos
2025-10-21 08:43:03
(11 months ago)
[Tue Oct 21 05:43:03.373634 2025] [authz_core:error] [pid 1828545:tid 257520223056064] [client 176.1 ...
show more
[Tue Oct 21 05:43:03.373634 2025] [authz_core:error] [pid 1828545:tid 257520223056064] [client 176.112.239.182:0] AH01630: client denied by server configuration: [redacted][redacted]/sites/mah.php
[Tue Oct 21 05:43:03.402548 2025] [authz_core:error] [pid 1828545:tid 257520065048768] [client 176.112.239.182:0] AH01630: client denied by server configuration: [redacted][redacted]/sites/chosen.php
[Tue Oct 21 05:43:03.495741 2025] [authz_core:error] [pid 1619339:tid 257520197693632] [client 176.112.239.182:0] AH01630: client denied by server configuration: [redacted][redacted]/sites/goods.php
show less
Brute-Force
Anonymous
2025-10-20 11:02:14
(11 months ago)
wordpress-trap
Web App Attack
π§π¬
Filipe DΓ‘vila
2025-10-19 22:11:28
(11 months ago)
[Sun Oct 19 18:11:26.435874 2025] [:error] [pid 338993:tid 140273220839168] [client 176.112.239.182: ...
show more
[Sun Oct 19 18:11:26.435874 2025] [:error] [pid 338993:tid 140273220839168] [client 176.112.239.182:49986] [client 176.112.239.182] [redacted]: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "[redacted][redacted]"] [[redacted] "233"] [id "[redacted]"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "[redacted]/4.7.0-dev"] [tag "[redacted]"] [tag "[redacted]"] [hostname "csweb.[redacted]"] [uri "/phpinfo.php"] [unique_id "aPViDmYsngVih2w6jU9t9gAAAMQ"]
show less
Web App Attack
πΊπΈ
TPI-Abuse
2025-10-17 22:36:17
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 176.112.239.182 (176-112-239-182.dynamic.itce.r ...
show more
(mod_security) mod_security (id:210730) triggered by 176.112.239.182 (176-112-239-182.dynamic.itce.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 17 18:36:12.328187 2025] [security2:error] [pid 4707:tid 4707] [client 176.112.239.182:58414] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||criarteste.com|F|2"] [data ".com_jce.ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "criarteste.com"] [uri "/language/en-GB/en-GB.com_jce.ini"] [unique_id "aPLE3CnFaY_mhFrzSt-U8wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
cmbplf
2025-10-17 06:24:34
(11 months ago)
95 requests with url.path */wp-content/plugins/litespeed-cache/readme.txt
Brute-Force
Bad Web Bot
Anonymous
2025-10-16 20:02:38
(11 months ago)
fail2ban apache-modsecurity web [msg "php scripts are not allowed here"] [uri "/tinyfilemanager.php" ...
show more
fail2ban apache-modsecurity web [msg "php scripts are not allowed here"] [uri "/tinyfilemanager.php"]
show less
Web App Attack