๐ฌ๐ง
adnscom.net
2025-08-13 14:29:34
(1 year ago)
IPS trigger: Brute force WebApp/CMS scanning/attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-07 22:40:23
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 195.12.190.59 (liepa.bsd.lt): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 195.12.190.59 (liepa.bsd.lt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 07 18:40:17.775929 2025] [security2:error] [pid 11782:tid 11782] [client 195.12.190.59:51516] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||daos.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "daos.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aJUrUZxieflit0wbdjO_1wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2025-08-07 12:54:34
(1 year ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 195.12.190.59 (LT/Lithuania/liepa.b ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 195.12.190.59 (LT/Lithuania/liepa.bsd.lt): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-04 04:12:21
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 195.12.190.59 (liepa.bsd.lt): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 195.12.190.59 (liepa.bsd.lt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 04 00:12:17.383790 2025] [security2:error] [pid 6793:tid 6793] [client 195.12.190.59:36278] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.northfortworthalliance.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.northfortworthalliance.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aJAzIQ13B5_5lchex2pNAwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-04 03:11:42
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 195.12.190.59 (liepa.bsd.lt): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 195.12.190.59 (liepa.bsd.lt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 03 23:11:35.600973 2025] [security2:error] [pid 30209:tid 30209] [client 195.12.190.59:57870] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.levijoneslegal.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.levijoneslegal.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aJAk54OGwSRioMgvItfGJgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2025-08-04 00:23:21
(1 year ago)
Blocking for trying to access an exploit file: /xmlrpc.php
Hacking
Anonymous
2025-08-02 09:55:04
(1 year ago)
xmlrpc attack blocked attempt from fail2ban
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-30 22:25:07
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 195.12.190.59 (liepa.bsd.lt): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 195.12.190.59 (liepa.bsd.lt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 30 18:24:59.131961 2025] [security2:error] [pid 6722:tid 6722] [client 195.12.190.59:32842] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.bostonlog.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.bostonlog.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aIqbu_urJFhCuliznzP3dgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
SOC [GOLINE SA]
2025-07-30 20:01:31
(1 year ago)
FortiGate detected IPS attack from IPv4 address 195.12.190.59
Hacking
๐บ๐ธ
TPI-Abuse
2025-07-23 02:26:26
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 195.12.190.59 (liepa.bsd.lt): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 195.12.190.59 (liepa.bsd.lt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 22 22:26:18.480259 2025] [security2:error] [pid 15768:tid 15768] [client 195.12.190.59:50990] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.starcrestsales.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.starcrestsales.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aIBISmJTJTfYrxtC_p77UgAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-23 01:20:05
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 195.12.190.59 (liepa.bsd.lt): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 195.12.190.59 (liepa.bsd.lt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 22 21:19:56.217050 2025] [security2:error] [pid 4799:tid 4799] [client 195.12.190.59:40954] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.ohiohca.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.ohiohca.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aIA4vMWY0GXq9mQrrHHiOAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2025-07-22 22:44:46
(1 year ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
myagent.site
2025-07-22 20:48:16
(1 year ago)
Blocking for trying to access an exploit file: /xmlrpc.php
Hacking
๐ฎ๐น
VHosting
2025-07-22 19:10:02
(1 year ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ฉ๐ช
Hazzard
2025-06-11 04:58:16
(1 year ago)
(wordpress) Failed wordpress login from 195.12.190.59 (LT/Lithuania/Vilnius City Municipality/Vilniu ...
show more
(wordpress) Failed wordpress login from 195.12.190.59 (LT/Lithuania/Vilnius City Municipality/Vilnius/liepa.insec.lt/[redacted])
show less
Brute-Force