๐บ๐ธ
nationaleventpros.com
2026-09-15 14:59:25
(3 days ago)
WordPress login attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-15 04:55:17
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 185.96.37.106 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 185.96.37.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 00:55:09.458785 2026] [security2:error] [pid 12803:tid 12803] [client 185.96.37.106:55241] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||method-one.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "method-one.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aqjPrenMYsvBqyBDfDPHbgAAAA4"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
โจ
2026-09-15 01:56:11
(3 days ago)
Domain : this-way-up.co.uk
Rule : wp-login
2026-09-15 01:54:36 ***hidden-privacy*** GET /wp-login.ph ...
show more
Domain : this-way-up.co.uk
Rule : wp-login
2026-09-15 01:54:36 ***hidden-privacy*** GET /wp-login.php - 443 - 185.96.37.106 HTTP/1.1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36 https://www.google.com this-way-up.co.uk 404 0 2 1535 258 77 - -
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 23:58:10
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 185.96.37.106 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 185.96.37.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 19:58:02.853807 2026] [security2:error] [pid 3977:tid 3977] [client 185.96.37.106:15169] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rendermatrix.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rendermatrix.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqiKCjArjOpJksaaCgzlpgAAABE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Roderic
2026-05-12 22:43:09
(4 months ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
๐ฉ๐ช
kjaerulff
2025-10-18 08:31:07
(11 months ago)
Failed Wordpress login using wp-login.php
Web App Attack
๐จ๐ญ
backslash
2025-10-13 13:40:27
(11 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
Anonymous
2025-10-04 05:39:26
(11 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฉ๐ช
Packets-Decreaser.NET
2025-09-24 11:16:44
(11 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
Anonymous
2025-04-17 10:00:00
(1 year ago)
โBruteForce attack on SSL VPN. Appears to be addresses coming from US Datacenters. Most all tried us ...
show more
โBruteForce attack on SSL VPN. Appears to be addresses coming from US Datacenters. Most all tried users are invalid and random.Most Tried Users are Guest and Admin. n type=event subtype=vpn level=alert action=ssl-login-fail msg=SSL user failed to logged in logdesc=SSL VPN login fail user=datadevscan02 group=N/A tunnelid=0 tunneltype=ssl-web dst_host=N/A reason=sslvpn_login_unknown_userโ
show less
Hacking
Brute-Force
Web App Attack
Anonymous
2025-04-17 10:00:00
(1 year ago)
โBruteForce attack on SSL VPN. Appears to be addresses coming from US Datacenters. Most all tried us ...
show more
โBruteForce attack on SSL VPN. Appears to be addresses coming from US Datacenters. Most all tried users are invalid and random.Most Tried Users are Guest and Admin. n type=event subtype=vpn level=alert action=ssl-login-fail msg=SSL user failed to logged in logdesc=SSL VPN login fail user=datadevscan02 group=N/A tunnelid=0 tunneltype=ssl-web dst_host=N/A reason=sslvpn_login_unknown_user โ
show less
Hacking
Brute-Force
Web App Attack
๐ท๐บ
sms.ru
2024-09-21 11:00:06
(1 year ago)
SMS pumping attack from foreign country
DDoS Attack
๐บ๐ธ
TPI-Abuse
2024-09-05 05:07:31
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 185.96.37.106 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 185.96.37.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 05 01:07:26.565404 2024] [security2:error] [pid 1335:tid 1335] [client 185.96.37.106:39061] [client 185.96.37.106] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gepteszt.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gepteszt.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Ztk8jqApfiqlmZ0ZpDYizgAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2023-02-04 07:13:53
(3 years ago)
Spam Detected: http://slkjfdf.net/ - Ineizooz <a href="http://slkjfdf.net/">Eneyona</a> ezm.nxfi.toh ...
show more
Spam Detected: http://slkjfdf.net/ - Ineizooz <a href="http://slkjfdf.net/">Eneyona</a> ezm.nxfi.tohnichi.com.yhd.cd http://slkjfdf.net/
show less
Web Spam
๐ฎ๐ฉ
hermawan
2022-09-30 19:15:32
(3 years ago)
[Sat Oct 01 06:15:29.922041 2022] [-:error] [pid 338945:tid 139701379606080] [client 185.96.37.106:2 ...
show more
[Sat Oct 01 06:15:29.922041 2022] [-:error] [pid 338945:tid 139701379606080] [client 185.96.37.106:23163] [client 185.96.37.106] ModSecurity: Access denied with code 403 (phase 1). Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1245"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.0"] [severity "CRITICAL"] [ver "OWASP_CRS/4.0.0-rc1"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/90-klimatologi/analisis-klimatologi/artikel-perubahan-iklim/126-arti"] [unique_id "Yzd4kdVnCXnnOF7o_NNBlAAAAOo"], referer https://karangploso.jatim.bmkg.go.id/index.php/90-klimatologi/analisis-klimatologi/artikel-perubahan-iklim/126-arti [karangplos
...
show less
Hacking
Web App Attack