๐บ๐ธ
octageeks.com
2025-12-14 05:06:06
(8 months ago)
Wordpress malicious attack:[octawp]
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-13 06:06:00
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 192.169.148.61 (61.148.169.192.host.secureserve ...
show more
(mod_security) mod_security (id:225170) triggered by 192.169.148.61 (61.148.169.192.host.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 13 01:05:56.225180 2025] [security2:error] [pid 14220:tid 14220] [client 192.169.148.61:45406] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ussthresher.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ussthresher.com"] [uri "/index.php/wp-json/wp/v2/users"] [unique_id "aT0CRAh_EC-lX5IhZCH5vAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-12 05:41:52
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 192.169.148.61 (61.148.169.192.host.secureserve ...
show more
(mod_security) mod_security (id:225170) triggered by 192.169.148.61 (61.148.169.192.host.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 12 00:41:45.927822 2025] [security2:error] [pid 5192:tid 5192] [client 192.169.148.61:62172] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||arellasoc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "arellasoc.com"] [uri "/wp-json/Wp/v2/users"] [unique_id "aTurGYQHlTd-Oj36CP4PKQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-06-24 14:02:59
(2 years ago)
Unauthorized login attempts [ bot_accesslogs]
Brute-Force
๐ง๐ช
taivas.nl
2024-06-22 04:32:42
(2 years ago)
Many_bad_calls
Web App Attack
๐ง๐ช
taivas.nl
2024-06-21 23:32:12
(2 years ago)
Bad_requests
Bad Web Bot
๐จ๐ญ
teamsecure
2024-06-16 08:43:34
(2 years ago)
Banned for trying to access wp-login
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-15 13:53:03
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 192.169.148.61 (61.148.169.192.host.secureserve ...
show more
(mod_security) mod_security (id:210730) triggered by 192.169.148.61 (61.148.169.192.host.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 15 09:53:00.323627 2024] [security2:error] [pid 24394] [client 192.169.148.61:57636] [client 192.169.148.61] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||brentsagnotti.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brentsagnotti.com"] [uri "/httpdocs.bak"] [unique_id "Zm2cvNUAN5w8RqNZppHSQwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-06-09 05:24:46
(2 years ago)
Ports: *; Direction: 0; Trigger: CT_LIMIT
Brute-Force
SSH
Anonymous
2024-06-09 04:14:15
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_MODSEC
Brute-Force
SSH
๐ฉ๐ช
Mario Silber
2024-06-02 12:12:38
(2 years ago)
(mod_security) mod_security triggered on hostname [redacted] 192.169.148.61 (US/United States/61.148 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 192.169.148.61 (US/United States/61.148.169.192.host.secureserver.net)
show less
SQL Injection
๐ฌ๐ง
preissler.co.uk
2024-06-02 12:03:48
(2 years ago)
Web scanning
Web App Attack
Anonymous
2024-05-31 01:26:31
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2024-05-29 01:05:46
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2024-05-27 13:55:56
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 192.169.148.61 (61.148.169.192.host.secureserve ...
show more
(mod_security) mod_security (id:210492) triggered by 192.169.148.61 (61.148.169.192.host.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 27 09:55:51.096866 2024] [security2:error] [pid 1669] [client 192.169.148.61:57688] [client 192.169.148.61] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fishing-links.com"] [uri "/.env.bak"] [unique_id "ZlSQ55ChWVl9WiYrOek64wAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack