๐บ๐ธ
TPI-Abuse
2023-12-29 02:24:07
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 212.30.36.69 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 212.30.36.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 28 21:24:02.380697 2023] [security2:error] [pid 24929] [client 212.30.36.69:28805] [client 212.30.36.69] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.daisydoesoap.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.daisydoesoap.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZY4twjt7pPOF24qEjciQogAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ps-center
2023-12-28 08:45:20
(2 years ago)
C1: Web Attack GET /manga/kurotama/2019/wp-includes/wlwmanifest.xml
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2023-12-20 06:12:18
(2 years ago)
18 attacks on PHP URLs, Wordpress URLs:
GET /domain.cgi?id=128/xmlrpc.php?rsd HTTP/1.1
GET /domain.c ...
show more
18 attacks on PHP URLs, Wordpress URLs:
GET /domain.cgi?id=128/xmlrpc.php?rsd HTTP/1.1
GET /domain.cgi?id=128/sito/wp-includes/wlwmanifest.xml HTTP/1.1
show less
Web App Attack
๐บ๐ธ
myagent.site
2023-12-19 04:33:50
(2 years ago)
Blocked user enumeration attempt
Hacking
๐บ๐ธ
TPI-Abuse
2023-12-19 02:14:44
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 212.30.36.69 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 212.30.36.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 18 21:14:35.904859 2023] [security2:error] [pid 2444] [client 212.30.36.69:21027] [client 212.30.36.69] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.hallandaleautotag.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.hallandaleautotag.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZYD8i7txf7s6-5z9rpnuqQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2023-12-19 02:08:51
(2 years ago)
Xmlrpc Caught (6)
Brute-Force
Web App Attack
๐ฎ๐ฑ
Dolphi
2023-12-07 02:40:03
(2 years ago)
POST //xmlrpc.php
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-06 19:53:25
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 212.30.36.69 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 212.30.36.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 06 14:53:18.828903 2023] [security2:error] [pid 22294] [client 212.30.36.69:57637] [client 212.30.36.69] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||3beeze.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "3beeze.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZXDRLg4BKZEuHHHBsBllVAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-05 03:03:50
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 212.30.36.69 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 212.30.36.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 04 22:03:43.424323 2023] [security2:error] [pid 28681] [client 212.30.36.69:32811] [client 212.30.36.69] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.surgicaltechnicianprogram.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.surgicaltechnicianprogram.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZW6TD0CSQ07W-e5VRK9WjgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-04 23:38:56
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 212.30.36.69 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 212.30.36.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 04 18:38:49.078868 2023] [security2:error] [pid 32134] [client 212.30.36.69:53759] [client 212.30.36.69] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cdcrtitle15.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cdcrtitle15.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZW5jCcMZb4XQEHM0AxjfHgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Bensay
2023-11-28 17:35:21
(2 years ago)
212.30.36.69 - - [28/Nov/2023:18:35:19 +0100] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 495 "- ...
show more
212.30.36.69 - - [28/Nov/2023:18:35:19 +0100] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 495 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
Tue Nov 28 18:35:20.100432 2023212.30.36.69 - - [28/Nov/2023:18:35:20 +0100] "GET /xmlrpc.php?rsd HTTP/1.1" 404 245 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
Tue Nov 28 18:35:20.100432 2023212.30.36.69 - - [28/Nov/2023:18:35:20 +0100] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 495 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
Tue Nov 28 18:35:20.100432 2023212.30.36.69 - - [28/Nov/2023:18:35:20 +0100] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 495 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
Tue Nov 28 18:35:20.100432 2023
...
show less
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
Ba-Yu
2023-11-03 01:58:47
(2 years ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
Anonymous
2023-09-19 17:10:18
(2 years ago)
Web Spam
Email Spam
Blog Spam
Bad Web Bot
Web App Attack
Anonymous
2023-09-18 14:49:27
(2 years ago)
Web Spam
Email Spam
Blog Spam
Bad Web Bot
Web App Attack
Anonymous
2023-09-16 10:54:39
(2 years ago)
Web Spam
Email Spam
Blog Spam
Bad Web Bot
Web App Attack