πΊπΈ
TPI-Abuse
2023-12-21 23:46:54
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:403:2d07:: (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:403:2d07:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 21 18:46:51.180785 2023] [security2:error] [pid 3694:tid 47760140867328] [client 2001:41d0:403:2d07:::57680] [client 2001:41d0:403:2d07::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mail.arizonasolutionsgroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mail.arizonasolutionsgroup.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZYTOa3uXWj2MxMfPD7vAoAAAAIc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
WebWizards.NZ
2023-12-21 23:40:18
(2 years ago)
Trolling for resource vulnerabilities
Web App Attack
πΊπΈ
TPI-Abuse
2023-12-21 23:05:12
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:403:2d07:: (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:403:2d07:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 21 18:05:05.965991 2023] [security2:error] [pid 15663] [client 2001:41d0:403:2d07:::44112] [client 2001:41d0:403:2d07::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.greatwesternfirearms.deubellzebub.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.greatwesternfirearms.deubellzebub.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZYTEoTSbeM86nYM5jocfHwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2023-12-21 22:29:15
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:403:2d07:: (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:403:2d07:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 21 17:29:09.337712 2023] [security2:error] [pid 20757] [client 2001:41d0:403:2d07:::55044] [client 2001:41d0:403:2d07::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ipv6.petersonzeyerlaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ipv6.petersonzeyerlaw.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZYS8NVcYfYVB7DTBtWWMowAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2023-12-21 21:47:32
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:403:2d07:: (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:403:2d07:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 21 16:47:29.009210 2023] [security2:error] [pid 18587] [client 2001:41d0:403:2d07:::46630] [client 2001:41d0:403:2d07::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||amsterdamlayovers.thinkingepic.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "amsterdamlayovers.thinkingepic.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZYSycecvmtddvzmeRbSjVwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2023-12-21 20:02:51
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:403:2d07:: (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:403:2d07:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 21 15:02:44.227542 2023] [security2:error] [pid 11601] [client 2001:41d0:403:2d07:::42950] [client 2001:41d0:403:2d07::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||barigby.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "barigby.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZYSZ5BdjWQaM0GgyIZ4UeAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
ph
2023-12-21 19:59:10
(2 years ago)
Bad web bot attempting to run wp-login.php on non-WP site
Hacking
Bad Web Bot
Web App Attack
π©πͺ
Mr-Money
2023-12-21 19:48:09
(2 years ago)
2001:41d0:403:2d07:: - - [21/Dec/2023:20:48:08 +0100] "GET /wp-login.php HTTP/1.1" 404 14692 "http:/ ...
show more
2001:41d0:403:2d07:: - - [21/Dec/2023:20:48:08 +0100] "GET /wp-login.php HTTP/1.1" 404 14692 "http://www.jobs-erz.de/wp-login.php" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:94.0) Gecko/20100101 Firefox/95.0"
...
show less
Hacking
SQL Injection
Bad Web Bot
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2023-12-21 19:03:49
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:403:2d07:: (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:403:2d07:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 21 14:03:43.336284 2023] [security2:error] [pid 21152] [client 2001:41d0:403:2d07:::47080] [client 2001:41d0:403:2d07::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mail.fatcavestudios.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mail.fatcavestudios.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZYSMD46dYZk4m0sRRPM1LQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2023-12-21 18:40:08
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:403:2d07:: (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:403:2d07:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 21 13:39:58.362164 2023] [security2:error] [pid 16399] [client 2001:41d0:403:2d07:::37132] [client 2001:41d0:403:2d07::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||doctoredwinalvarez.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "doctoredwinalvarez.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZYSGfuTX0qOnFEkF91KdBQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
lavnet.net
2023-12-21 17:55:16
(2 years ago)
Dec 21 17:55:15 angela wordpress(thejunkymonkey.com)[1782285]: Blocked user enumeration attempt from ...
show more
Dec 21 17:55:15 angela wordpress(thejunkymonkey.com)[1782285]: Blocked user enumeration attempt from 2001:41d0:403:2d07::
...
show less
Hacking
Web App Attack
π©πͺ
ps-center
2023-12-21 17:55:06
(2 years ago)
MYH: Web Attack GET /wp-login.php
Web Spam
Hacking
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2023-12-21 16:50:47
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:403:2d07:: (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:403:2d07:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 21 11:50:44.056693 2023] [security2:error] [pid 15988] [client 2001:41d0:403:2d07:::45242] [client 2001:41d0:403:2d07::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||computerservicesofflorida.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "computerservicesofflorida.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZYRs5HyXLJQKgdBjUayizgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2023-12-21 16:29:49
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:403:2d07:: (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:403:2d07:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 21 11:29:43.917243 2023] [security2:error] [pid 18027:tid 47284859475712] [client 2001:41d0:403:2d07:::55316] [client 2001:41d0:403:2d07::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ioqm.aafm.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ioqm.aafm.us"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZYRn9ztP5LRQrGb6j0DE_wAAAQ4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2023-12-21 16:08:18
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:403:2d07:: (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:403:2d07:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 21 11:08:10.711563 2023] [security2:error] [pid 25804] [client 2001:41d0:403:2d07:::42744] [client 2001:41d0:403:2d07::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||intelerium.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "intelerium.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZYRi6nlGPG924X4GaTxsKQAAAA0"], referer: http://intelerium.com///wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack