๐ช๐ธ
10dencehispahard SL
2024-03-12 08:00:04
(2 years ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-01-23 19:38:40
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 191.101.41.162 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 191.101.41.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 23 14:37:27.865079 2024] [security2:error] [pid 23690] [client 191.101.41.162:51089] [client 191.101.41.162] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.cpectec.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.cpectec.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZbAVd0kBWw0EZ5ZVF2RtUwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-23 18:54:59
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 191.101.41.162 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 191.101.41.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 23 13:54:18.950990 2024] [security2:error] [pid 22126:tid 47130979632896] [client 191.101.41.162:58303] [client 191.101.41.162] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 191.101.41.162 (+1 hits since last alert)|maryschalkdesign.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "maryschalkdesign.com"] [uri "/xmlrpc.php"] [unique_id "ZbALWrgoZD5BE_iqJrkcpAAAAQg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-23 06:29:06
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 191.101.41.162 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 191.101.41.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 23 01:29:01.717462 2024] [security2:error] [pid 7075] [client 191.101.41.162:14997] [client 191.101.41.162] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 191.101.41.162 (+1 hits since last alert)|www.freemanfoundationcle.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.freemanfoundationcle.org"] [uri "/xmlrpc.php"] [unique_id "Za9crQyxqV-S5gYR3_Uu6wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-22 18:47:39
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 191.101.41.162 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 191.101.41.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 22 13:47:31.309700 2024] [security2:error] [pid 3868] [client 191.101.41.162:1211] [client 191.101.41.162] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 191.101.41.162 (+1 hits since last alert)|bikiniadvice.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bikiniadvice.com"] [uri "/xmlrpc.php"] [unique_id "Za64QyG8LBYacMWn8KcX_gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-22 13:04:34
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 191.101.41.162 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 191.101.41.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 22 08:03:28.188226 2024] [security2:error] [pid 10732] [client 191.101.41.162:54025] [client 191.101.41.162] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.darrenj.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.darrenj.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Za5noGKHfbH_-wcB30_tlAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-22 12:40:56
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 191.101.41.162 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 191.101.41.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 22 07:40:48.577874 2024] [security2:error] [pid 4920] [client 191.101.41.162:59951] [client 191.101.41.162] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.boaredraven.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.boaredraven.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Za5iUA81D7kSe1llevy7TgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-22 10:12:26
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 191.101.41.162 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 191.101.41.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 22 05:12:18.713130 2024] [security2:error] [pid 6279] [client 191.101.41.162:49069] [client 191.101.41.162] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.dbfitwell.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.dbfitwell.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Za4_gidRSBM1JbdlewbNuQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-21 19:16:25
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 191.101.41.162 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 191.101.41.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 21 14:16:16.996940 2024] [security2:error] [pid 11836] [client 191.101.41.162:55939] [client 191.101.41.162] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lahamradio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lahamradio.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Za1tgAuRtDShhDzNd5rfbAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2024-01-16 15:47:32
(2 years ago)
[Tue Jan 16 15:47:29.868495 2024] [proxy_fcgi:error] [pid 3339231:tid 140298529273408] [client 191.1 ...
show more
[Tue Jan 16 15:47:29.868495 2024] [proxy_fcgi:error] [pid 3339231:tid 140298529273408] [client 191.101.41.162:34109] AH01071: Got error 'Primary script unknown'
[Tue Jan 16 15:47:30.542783 2024] [proxy_fcgi:error] [pid 3339231:tid 140297723967040] [client 191.101.41.162:34109] AH01071: Got error 'Primary script unknown'
[Tue Jan 16 15:47:31.245905 2024] [proxy_fcgi:error] [pid 3339231:tid 140298478917184] [client 191.101.41.162:34109] AH01071: Got error 'Primary script unknown'
[Tue Jan 16 15:47:31.585997 2024] [proxy_fcgi:error] [pid 3339231:tid 140297807828544] [client 191.101.41.162:34109] AH01071: Got error 'Primary script unknown'
[Tue Jan 16 15:47:32.469990 2024] [proxy_fcgi:error] [pid 3339231:tid 140298512488000] [client 191.101.41.162:34109] AH01071: Got error 'Primary script unknown'
...
show less
Web App Attack
๐บ๐ธ
octageeks.com
2024-01-12 05:11:14
(2 years ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐บ๐ธ
octageeks.com
2024-01-10 05:11:24
(2 years ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐บ๐ธ
mawan
2024-01-10 02:24:18
(2 years ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฌ๐ง
findlab
2024-01-09 16:20:13
(2 years ago)
Backdrop CMS module - scanning for vulnerable files
Bad Web Bot
Web App Attack
๐บ๐ธ
octageeks.com
2024-01-09 05:11:21
(2 years ago)
Wordpress malicious attack:[octaflood]
Web App Attack