๐ฎ๐ฉ
rvsdi
2026-08-01 22:24:24
(1 month ago)
[OGWAF] brute_force attack blocked | severity: high | POST /wp-login.php | UA: Mozilla/5.0 (X11; Lin ...
show more
[OGWAF] brute_force attack blocked | severity: high | POST /wp-login.php | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.3
show less
Brute-Force
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-29 20:41:01
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 185.61.216.185 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.61.216.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 16:40:55.273726 2026] [security2:error] [pid 3042914:tid 3042914] [client 185.61.216.185:26847] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||techworksunlimited.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "techworksunlimited.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amplV8N2HORYF-WwqcgzIwAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-07-20 18:30:56
(2 months ago)
Web password guessing
Brute-Force
๐จ๐ฆ
DRI
2026-07-18 22:37:57
(2 months ago)
Web attack/Malicious activity detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 19:43:49
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 185.61.216.185 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.61.216.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 15:43:43.152575 2026] [security2:error] [pid 32133:tid 32133] [client 185.61.216.185:43211] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gotdt.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gotdt.com"] [uri "/wp-json/wp/v2/users"] [unique_id "alqF70ghAlflfR5q8v6_VAAAAA8"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-26 04:24:22
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 185.61.216.185 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.61.216.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 00:24:17.129508 2026] [security2:error] [pid 20665:tid 20665] [client 185.61.216.185:47631] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dvdmasters.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dvdmasters.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acS08f6heHpsfg_eSoQzWwAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-22 23:37:48
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 185.61.216.185 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.61.216.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 22 19:37:39.575129 2026] [security2:error] [pid 11459:tid 11464] [client 185.61.216.185:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mindgardens.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mindgardens.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acB9Q0EsklxjK70vBjHpDwAAAMA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-03-22 14:44:44
(5 months ago)
Web password guessing
Brute-Force
๐บ๐ธ
xmission.com
2026-03-03 23:47:00
(6 months ago)
185.61.216.185 - - [03/Mar/2026:16:46:59 -0700] "POST /wp-login.php HTTP/1.1" 200 2333 "https://dooc ...
show more
185.61.216.185 - - [03/Mar/2026:16:46:59 -0700] "POST /wp-login.php HTTP/1.1" 200 2333 "https://dooce.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-03-01 14:58:45
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 185.61.216.185 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.61.216.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 01 09:58:40.194782 2026] [security2:error] [pid 4075:tid 4075] [client 185.61.216.185:49841] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||berklie.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "berklie.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aaRUIO_9MGCBy_3lXdTcpQAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-09-24 11:16:59
(11 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
Anonymous
2025-05-30 14:24:57
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ญ๐ฐ
www.winos.me
2025-05-30 08:37:06
(1 year ago)
xmlrpc does not allow access
Web App Attack
๐ฉ๐ช
LRob
2025-05-28 07:30:07
(1 year ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ญ๐ฐ
www.winos.me
2025-05-28 02:20:04
(1 year ago)
xmlrpc does not allow access
Web App Attack