๐ฑ๐ป
garmtech.com
2026-02-13 00:15:53
(6 months ago)
IM360 WAF: Laravel .env file access
Web App Attack
๐ง๐ช
voormedia
2025-11-11 06:52:35
(9 months ago)
Accessed trap at '/xmlrpc.php'
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-11 04:41:16
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 194.61.9.21 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 194.61.9.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 10 23:41:10.446362 2025] [security2:error] [pid 28500:tid 28500] [client 194.61.9.21:38995] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||vffv.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "vffv.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aRK-ZvaTz-GNL50NP9ZbcgAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
kjaerulff
2025-11-11 03:41:34
(9 months ago)
Failed Wordpress login using xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-11 01:17:27
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 194.61.9.21 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 194.61.9.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 10 20:17:19.132647 2025] [security2:error] [pid 18382:tid 18382] [client 194.61.9.21:58707] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gonzalez.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gonzalez.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aRKOnzeLHrro1LMHDuudGQAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-10 22:22:45
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 194.61.9.21 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 194.61.9.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 10 17:22:38.039883 2025] [security2:error] [pid 17711:tid 17711] [client 194.61.9.21:29283] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||waking.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "waking.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aRJlrk-enxg7ptApV_u7JwAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-10 21:48:50
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 194.61.9.21 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 194.61.9.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 10 16:48:45.474019 2025] [security2:error] [pid 31545:tid 31545] [client 194.61.9.21:53365] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||amoriotech.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "amoriotech.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aRJdvdSQun5ZvUTiZuCvmwAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2025-11-10 12:40:03
(9 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-11-10 12:01:56
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 194.61.9.21 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 194.61.9.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 10 07:01:53.025687 2025] [security2:error] [pid 31005:tid 31005] [client 194.61.9.21:46285] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ianpearce.tv|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ianpearce.tv"] [uri "/wp-json/wp/v2/users"] [unique_id "aRHUMU65aP3pLwIY55piEAAAAAM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2025-11-10 12:00:52
(9 months ago)
Unauthorized login attempts [ Hostname-access, wordpress-xmlrpc]
Brute-Force
Web App Attack
Anonymous
2025-08-04 15:23:47
(1 year ago)
Botnet - login attempts with leaked random user/pass lists
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
IT Support
2024-04-09 04:05:39
(2 years ago)
Credential Stuffing
Hacking
Brute-Force
๐บ๐ธ
IT Support
2024-04-06 22:53:19
(2 years ago)
Credential stuffing
Hacking
Brute-Force
๐บ๐ธ
MO webmaster
2024-02-26 14:45:00
(2 years ago)
comment spam
I, [2024-02-26T12:24:35.169752 #1246] INFO -- : Started GET "/comment/add_comment/114 ...
show more
comment spam
I, [2024-02-26T12:24:35.169752 #1246] INFO -- : Started GET "/comment/add_comment/11494/%20U:helenClant%20P:6ouL6x" for 194.61.9.211 at 2024-02-26 12:24:35 +0000
I, [2024-02-26T12:24:39.617335 #1246] INFO -- : Started GET "/comment/add_comment/11494/%20U:helenClant%20P:6ouL6x" for 194.61.9.211 at 2024-02-26 12:24:39 +0000
show less
Blog Spam
๐บ๐ธ
SiliSoftware
2023-11-29 06:29:27
(2 years ago)
/phpBB3/viewtopic.php?t=74
Web App Attack