π©πͺ
corthorn
2024-06-02 15:52:19
(2 years ago)
2001:1640:5::3:d6 - - [02/Jun/2024:17:52:18 +0200] "POST /xmlrpc.php HTTP/1.1" 403 4174 "-" "Mozilla ...
show more
2001:1640:5::3:d6 - - [02/Jun/2024:17:52:18 +0200] "POST /xmlrpc.php HTTP/1.1" 403 4174 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0"
...
show less
Brute-Force
πΊπΈ
myagent.site
2024-05-23 13:27:36
(2 years ago)
Blocking for trying to access an exploit file: /xmlrpc.php
Hacking
Anonymous
2024-05-22 16:57:07
(2 years ago)
Scenario: crowdsecurity/http-wordpress_user-enum
Hacking
πΊπΈ
TPI-Abuse
2024-05-21 13:12:20
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2001:1640:5::3:d6 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:1640:5::3:d6 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 21 09:12:12.935799 2024] [security2:error] [pid 13070] [client 2001:1640:5::3:d6:29207] [client 2001:1640:5::3:d6] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pastortimsjourney.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pastortimsjourney.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZkydrCBi3bI3gJZCeE4A_AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-05-18 00:35:30
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
π³π±
BlueWire Hosting
2024-05-11 20:10:12
(2 years ago)
Probing for Wordpress vulnerabilities
Bad Web Bot
Web App Attack
π§πͺ
cmbplf
2024-04-29 10:32:33
(2 years ago)
667 requests to /xmlrpc.php
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2024-04-25 20:18:30
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2001:1640:5::3:d6 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:1640:5::3:d6 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 25 16:18:24.048160 2024] [security2:error] [pid 24105] [client 2001:1640:5::3:d6:64272] [client 2001:1640:5::3:d6] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lajoze.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lajoze.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Ziq6kDFX82k0Z7MEMYHlggAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-04-25 20:01:18
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2001:1640:5::3:d6 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:1640:5::3:d6 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 25 16:01:12.301738 2024] [security2:error] [pid 32561] [client 2001:1640:5::3:d6:38597] [client 2001:1640:5::3:d6] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||caribbeancoralinstitute.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "caribbeancoralinstitute.org"] [uri "/wp-json/wp/v2/users"] [unique_id "Ziq2iHu8iI308GcObzZPzAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-04-25 16:22:17
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2001:1640:5::3:d6 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:1640:5::3:d6 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 25 12:22:12.412646 2024] [security2:error] [pid 25318] [client 2001:1640:5::3:d6:52070] [client 2001:1640:5::3:d6] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bbproductionsonline.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bbproductionsonline.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZiqDNJdQ14BzVPaJikvcGQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-04-25 15:07:21
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2001:1640:5::3:d6 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:1640:5::3:d6 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 25 11:07:17.835103 2024] [security2:error] [pid 4825] [client 2001:1640:5::3:d6:62269] [client 2001:1640:5::3:d6] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bonnesfrequences.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bonnesfrequences.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZipxpemGPmchHaoApootDwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
debaba
2024-04-25 11:47:16
(2 years ago)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2024-04-25 11:18:43
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2001:1640:5::3:d6 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:1640:5::3:d6 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 25 07:18:38.057757 2024] [security2:error] [pid 72525] [client 2001:1640:5::3:d6:54833] [client 2001:1640:5::3:d6] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||honigcpa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "honigcpa.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Zio8Dgkw2Rv-wg7Lq4ubNgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-04-25 10:40:09
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2001:1640:5::3:d6 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:1640:5::3:d6 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 25 06:40:04.708021 2024] [security2:error] [pid 19838] [client 2001:1640:5::3:d6:23457] [client 2001:1640:5::3:d6] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.dalessalesandservice.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.dalessalesandservice.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZiozBOKpw7CO-hxB4t8C3AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-04-25 10:09:32
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2001:1640:5::3:d6 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:1640:5::3:d6 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 25 06:09:29.019623 2024] [security2:error] [pid 1585] [client 2001:1640:5::3:d6:61119] [client 2001:1640:5::3:d6] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.songwriterdemo.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.songwriterdemo.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Zior2XPdgsh6lAo35kimmQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack