๐ต๐ฑ
Might Man
2025-03-18 09:36:00
(1 year ago)
h
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
octageeks.com
2025-03-18 04:09:22
(1 year ago)
Wordpress malicious attack:[octawpauthor]
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-17 15:32:57
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 193.176.31.8 (8.31.176.193.baremetal.zare.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 193.176.31.8 (8.31.176.193.baremetal.zare.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 17 11:32:52.527212 2025] [security2:error] [pid 28316:tid 28316] [client 193.176.31.8:15685] [client 193.176.31.8] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||shelbysmoak.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "shelbysmoak.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z9hApMMLNZeiS5tz8WJ8PwAAACo"], referer: https://shelbysmoak.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-17 15:08:48
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 193.176.31.8 (8.31.176.193.baremetal.zare.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 193.176.31.8 (8.31.176.193.baremetal.zare.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 17 11:08:43.874572 2025] [security2:error] [pid 3122:tid 3122] [client 193.176.31.8:12055] [client 193.176.31.8] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.lenorasflowers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.lenorasflowers.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z9g6-z2d57VDOmmCnsKroQAAABU"], referer: http://www.lenorasflowers.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2025-03-17 15:05:49
(1 year ago)
Too many Status 40X (12)
Brute-Force
Web App Attack
๐ฉ๐ช
FeG Deutschland
2025-03-17 14:47:42
(1 year ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 14
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-17 14:37:52
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 193.176.31.8 (8.31.176.193.baremetal.zare.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 193.176.31.8 (8.31.176.193.baremetal.zare.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 17 10:37:47.857490 2025] [security2:error] [pid 2606958:tid 2606958] [client 193.176.31.8:7641] [client 193.176.31.8] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.microkerneltechnologies.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.microkerneltechnologies.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z9gzuwnreTQzmhXTlAQc5QAAABs"], referer: https://www.microkerneltechnologies.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
snappic
2025-03-17 13:55:01
(1 year ago)
Malicious URI path [GET /wp-admin/index.php] [Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KH ...
show more
Malicious URI path [GET /wp-admin/index.php] [Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/38.0.2125.102 Safari/537.36 OPR/25.0.1619.84037]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-17 13:49:45
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 193.176.31.8 (8.31.176.193.baremetal.zare.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 193.176.31.8 (8.31.176.193.baremetal.zare.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 17 09:49:42.730637 2025] [security2:error] [pid 14084:tid 14084] [client 193.176.31.8:15353] [client 193.176.31.8] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.inquisitivequincie.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.inquisitivequincie.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z9godpNZD7YDEjTy_429vAAAABk"], referer: http://www.inquisitivequincie.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
JimArchon72
2025-03-17 13:40:01
(1 year ago)
2025/03/17 13:40:00 "GET /wp-login.php HTTP/1.1"
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-17 13:31:56
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 193.176.31.8 (8.31.176.193.baremetal.zare.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 193.176.31.8 (8.31.176.193.baremetal.zare.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 17 09:31:51.571509 2025] [security2:error] [pid 4535:tid 4535] [client 193.176.31.8:7996] [client 193.176.31.8] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.rootwingcollective.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.rootwingcollective.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z9gkR6bDsaCKTFlC8CRGvQAAAB8"], referer: https://www.rootwingcollective.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ISPLtd
2025-03-17 13:10:51
(1 year ago)
193.176.31.8 - - [17/Mar/2025:10:10:50 -0300] "GET /wp-PII/index.php
193.176.31.8 - - [17/Mar/2025:1 ...
show more
193.176.31.8 - - [17/Mar/2025:10:10:50 -0300] "GET /wp-PII/index.php
193.176.31.8 - - [17/Mar/2025:10:10:50 -0300] "GET /wp-login.php?redirect_to=https%3A%2F%2Fwww.patientrm.com%2Fwp-PII%2Findex.php&reauth=1
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-17 13:02:11
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 193.176.31.8 (8.31.176.193.baremetal.zare.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 193.176.31.8 (8.31.176.193.baremetal.zare.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 17 09:02:04.216658 2025] [security2:error] [pid 30016:tid 30016] [client 193.176.31.8:17942] [client 193.176.31.8] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bernsteinip.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bernsteinip.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z9gdTE3a5ktRHd2-fZitQAAAAAg"], referer: https://bernsteinip.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
mangomad
2023-11-11 10:11:21
(2 years ago)
Repeated Apache mod_security rule triggers
Brute-Force
Web App Attack
๐ฆ๐บ
MAGIC
2023-08-25 15:22:49
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot