πΊπΈ
Dolphi
2025-02-12 14:20:18
(1 year ago)
POST //xmlrpc.php
Brute-Force
Web App Attack
πΊπΈ
octageeks.com
2025-02-12 05:06:41
(1 year ago)
Wordpress malicious attack:[octablocked]
Web App Attack
π¬π§
Apache
2025-02-10 10:24:35
(1 year ago)
(mod_security) mod_security (id:210410) triggered by 212.30.37.16 (NL/The Netherlands/-): 5 in the l ...
show more
(mod_security) mod_security (id:210410) triggered by 212.30.37.16 (NL/The Netherlands/-): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2025-02-09 04:06:44
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 212.30.37.16 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 212.30.37.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 08 23:06:37.998143 2025] [security2:error] [pid 24491:tid 24585] [client 212.30.37.16:47341] [client 212.30.37.16] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||eceinal.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "eceinal.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Z6gpzd2ANAQ6TSOYl_FYMAAAAcI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-02-08 20:47:25
(1 year ago)
apache-wordpress-login
Brute-Force
Web App Attack
Anonymous
2025-02-06 12:33:18
(1 year ago)
wordpress-trap
Web App Attack
π©πͺ
juutis
2025-01-29 06:41:59
(1 year ago)
212.30.37.16 - - [29/Jan/2025:07:41:57 +0100] "POST //wp-login.php HTTP/1.0" 200 11585 "https://taid ...
show more
212.30.37.16 - - [29/Jan/2025:07:41:57 +0100] "POST //wp-login.php HTTP/1.0" 200 11585 "https://taidesuunnistus.net//wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
212.30.37.16 - - [29/Jan/2025:07:41:58 +0100] "POST //wp-login.php HTTP/1.0" 200 11585 "https://taidesuunnistus.net//wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
212.30.37.16 - - [29/Jan/2025:07:41:58 +0100] "POST //wp-login.php HTTP/1.0" 200 11585 "https://taidesuunnistus.net//wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
show less
Web App Attack
π§πͺ
cmbplf
2025-01-29 03:45:24
(1 year ago)
154 requests to */wp-includes/wlwmanifest.xml
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2025-01-28 06:38:15
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 212.30.37.16 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 212.30.37.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 28 01:38:09.564851 2025] [security2:error] [pid 12566:tid 12566] [client 212.30.37.16:5469] [client 212.30.37.16] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.byles.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.byles.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "Z5h7UfZv2NxJpuG_9NVKjgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-01-28 02:44:13
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
π¦πΊ
MAGIC
2025-01-17 03:02:56
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2025-01-11 01:02:03
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-01-07 05:52:07
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
πΊπΈ
TPI-Abuse
2025-01-06 20:53:47
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 212.30.37.16 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 212.30.37.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 06 15:53:43.934652 2025] [security2:error] [pid 13603:tid 13603] [client 212.30.37.16:43763] [client 212.30.37.16] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bernsteinip.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bernsteinip.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Z3xC1x8J2EcNkOdeB11vyQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-12-31 03:17:09
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 212.30.37.16 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 212.30.37.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 30 22:17:05.562250 2024] [security2:error] [pid 4288:tid 4288] [client 212.30.37.16:31187] [client 212.30.37.16] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cvgandhes.investments|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cvgandhes.investments"] [uri "/backups/sql.sql"] [unique_id "Z3NiMdR-NbbNowXsAPvf8gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack