Anonymous
2026-01-05 15:28:32
(9 months ago)
Failed Wordpress Logins
Web App Attack
πΊπΈ
TPI-Abuse
2024-09-05 16:24:47
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2001:1810:4141:138:0:4:42af:3878 (web120c38.car ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:1810:4141:138:0:4:42af:3878 (web120c38.carrierzone.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 05 12:24:43.430679 2024] [security2:error] [pid 5982:tid 5982] [client 2001:1810:4141:138:0:4:42af:3878:34936] [client 2001:1810:4141:138:0:4:42af:3878] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mail.modalguitarist.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mail.modalguitarist.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZtnbS19RAyaYhMb-DfBWGAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
cmbplf
2024-04-17 15:17:18
(2 years ago)
1.440 requests to /xmlrpc.php
Brute-Force
Bad Web Bot
π¬π§
Swiptly
2024-04-17 14:20:07
(2 years ago)
WordPress xmlrpc spam or enumeration
...
Web Spam
Bad Web Bot
Web App Attack
π©πͺ
Ba-Yu
2024-03-08 14:00:45
(2 years ago)
WP-xmlrpc exploit
Web Spam
Blog Spam
Hacking
Exploited Host
Web App Attack
π©πͺ
SCHAPPY
2024-03-03 12:38:41
(2 years ago)
Mutliple attempts to access web resources unauthorized, HTTP code 403.
Web App Attack
πΊπΈ
mawan
2023-11-25 13:14:25
(2 years ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
πΊπΈ
mawan
2023-11-24 05:11:08
(2 years ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
π¦πΊ
weblite
2023-11-22 12:05:50
(2 years ago)
WP_XMLRPC_ABUSE
Brute-Force
Web App Attack
π©πͺ
Ba-Yu
2023-11-21 03:27:46
(2 years ago)
WP-xmlrpc exploit
Web Spam
Blog Spam
Hacking
Exploited Host
Web App Attack
πΊπΈ
mawan
2023-11-20 22:28:55
(2 years ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
πΊπΈ
TPI-Abuse
2023-11-17 20:03:34
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2001:1810:4141:138:0:4:42af:3878 (web120c38.car ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:1810:4141:138:0:4:42af:3878 (web120c38.carrierzone.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 17 15:03:31.275701 2023] [security2:error] [pid 21639] [client 2001:1810:4141:138:0:4:42af:3878:59544] [client 2001:1810:4141:138:0:4:42af:3878] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||artichokedesign.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "artichokedesign.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ZVfHE77RPNqO0720ZxXFZAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2023-11-17 19:11:41
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2001:1810:4141:138:0:4:42af:3878 (web120c38.car ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:1810:4141:138:0:4:42af:3878 (web120c38.carrierzone.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 17 14:11:36.701958 2023] [security2:error] [pid 9126] [client 2001:1810:4141:138:0:4:42af:3878:48646] [client 2001:1810:4141:138:0:4:42af:3878] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||4115thewestford.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "4115thewestford.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZVe66HQnOeV3elA3dg0DmgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2023-11-17 18:40:07
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2001:1810:4141:138:0:4:42af:3878 (web120c38.car ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:1810:4141:138:0:4:42af:3878 (web120c38.carrierzone.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 17 13:40:02.565092 2023] [security2:error] [pid 4325] [client 2001:1810:4141:138:0:4:42af:3878:54170] [client 2001:1810:4141:138:0:4:42af:3878] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||randyshelly.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "randyshelly.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZVezgtcuZyTl5YQTbqEmmQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2023-11-17 17:27:37
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2001:1810:4141:138:0:4:42af:3878 (web120c38.car ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:1810:4141:138:0:4:42af:3878 (web120c38.carrierzone.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 17 12:27:33.413203 2023] [security2:error] [pid 8883] [client 2001:1810:4141:138:0:4:42af:3878:57882] [client 2001:1810:4141:138:0:4:42af:3878] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||greatwesternfirearms.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "greatwesternfirearms.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZVeihQlOStHRx-CQCnkZPAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack