|
๐ฉ๐ช
FeG Deutschland
|
|
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
|
Exploited Host
Web App Attack
|
|
|
๐ซ๐ท
ELYAZ
|
|
(wordpress) Failed wordpress login from 199.96.165.67 (US/United States/-): (CF_ENABLE)
|
Brute-Force
|
|
|
๐ฉ๐ช
FeG Deutschland
|
|
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
|
Exploited Host
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 199.96.165.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 199.96.165.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 00:40:56.851405 2026] [security2:error] [pid 1434798:tid 1434798] [client 199.96.165.67:49329] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||brazilianbottom.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "brazilianbottom.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adXcWFyJyOs0kfJ1raGDmQAAAAM"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 199.96.165.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 199.96.165.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 15:06:54.285032 2026] [security2:error] [pid 1493871:tid 1493871] [client 199.96.165.67:38161] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bfpsamoa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bfpsamoa.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adVVzmoSdFQ6B83DK_5ffwAAAAg"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 199.96.165.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 199.96.165.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 12:25:48.548542 2026] [security2:error] [pid 1121272:tid 1121272] [client 199.96.165.67:63785] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||benchmarkbcs.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "benchmarkbcs.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adUwDKdgitdLI6YAxFCm5gAAABA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฒ๐น
Malta
|
|
199.96.165.67 - - [06/Apr/2026:05:56:50 +0200] "GET /wp-json/wp/v2/users HTTP/1.1" "Go-http-client/1 ...
show more
199.96.165.67 - - [06/Apr/2026:05:56:50 +0200] "GET /wp-json/wp/v2/users HTTP/1.1" "Go-http-client/1.1"
show less
|
Hacking
Web App Attack
VPN IP
|
|
|
๐ฎ๐น
VHosting
|
|
Detected WordPress attack from 4 different servers
|
Brute-Force
Web App Attack
|
|
|
๐บ๐ธ
mind5t0rm
|
|
(XMLRPC) WP XMLPRC Attack 199.96.165.67 (US/United States/-): 3 in the last 3600 secs; Ports: *; Dir ...
show more
(XMLRPC) WP XMLPRC Attack 199.96.165.67 (US/United States/-): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: 199.96.165.67 - - [18/Mar/2026:02:20:39 +0700] "POST /xmlrpc.php HTTP/2.0" 403 154 "-" "curl/8.6.0"
199.96.165.67 - - [18/Mar/2026:02:20:40 +0700] "POST /xmlrpc.php HTTP/2.0" 403 154 "-" "curl/7.88.1"
199.96.165.67 - - [18/Mar/2026:02:20:40 +0700] "POST /xmlrpc.php HTTP/2.0" 403 154 "-" "curl/8.6.0"
show less
|
Port Scan
|
|
|
๐ฎ๐น
alph44
|
|
WordPress attack detected by fail2ban: 3 failed attempts
|
Web App Attack
|
|