๐ซ๐ท
Max la Menace
2024-05-15 06:14:29
(2 years ago)
Wordpress Attack (P)
Web App Attack
๐ง๐ช
cmbplf
2024-04-25 21:24:38
(2 years ago)
100 requests to /wp-json/wp/v2/users
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-04-24 11:07:18
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2400:8904::f03c:93ff:fe5f:3c5f (Unknown): 1 in ...
show more
(mod_security) mod_security (id:210730) triggered by 2400:8904::f03c:93ff:fe5f:3c5f (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 24 07:07:12.343918 2024] [security2:error] [pid 2651036] [client 2400:8904::f03c:93ff:fe5f:3c5f:51604] [client 2400:8904::f03c:93ff:fe5f:3c5f] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.azcrittergetter.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.azcrittergetter.com"] [uri "/csfitz.com"] [unique_id "Zijn4B8CtV7DbMacqn2WgAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2024-04-22 21:37:52
(2 years ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐ณ๐ฑ
maxxsense
2024-04-17 06:09:23
(2 years ago)
(wordpress) Failed wordpress login from 2400:8904::f03c:93ff:fe5f:3c5f (IN/India/-)
Brute-Force
๐ฌ๐ง
Swiptly
2024-04-15 05:37:46
(2 years ago)
WordPress xmlrpc spam or enumeration
...
Web Spam
Bad Web Bot
Web App Attack
๐ฉ๐ช
corthorn
2024-04-13 17:36:43
(2 years ago)
2400:8904::f03c:93ff:fe5f:3c5f - - [13/Apr/2024:19:36:42 +0200] "POST /xmlrpc.php HTTP/1.1" 403 4171 ...
show more
2400:8904::f03c:93ff:fe5f:3c5f - - [13/Apr/2024:19:36:42 +0200] "POST /xmlrpc.php HTTP/1.1" 403 4171 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:84.0) Gecko/20100101 Firefox/84.0"
...
show less
Brute-Force
๐ฉ๐ช
OiledAmoeba
2024-03-24 00:10:13
(2 years ago)
Mar 24 01:10:12 10.23.100.230 wordpress(www.ruhnke.cloud)[37955]: Blocked authentication attempt for ...
show more
Mar 24 01:10:12 10.23.100.230 wordpress(www.ruhnke.cloud)[37955]: Blocked authentication attempt for admin from 2400:8904::f03c:93ff:fe5f:3c5f
...
show less
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
OiledAmoeba
2024-03-22 13:27:15
(2 years ago)
Mar 22 14:27:14 10.23.100.230 wordpress(www.ruhnke.cloud)[48742]: Blocked authentication attempt for ...
show more
Mar 22 14:27:14 10.23.100.230 wordpress(www.ruhnke.cloud)[48742]: Blocked authentication attempt for admin from 2400:8904::f03c:93ff:fe5f:3c5f
...
show less
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
OiledAmoeba
2024-03-10 16:22:39
(2 years ago)
Mar 10 17:21:59 10.23.100.230 wordpress(www.ruhnke.cloud)[39125]: XML-RPC authentication attempt for ...
show more
Mar 10 17:21:59 10.23.100.230 wordpress(www.ruhnke.cloud)[39125]: XML-RPC authentication attempt for unknown user ruhnke from 2400:8904::f03c:93ff:fe5f:3c5f
...
show less
Hacking
Brute-Force
Web App Attack
๐ฆ๐บ
weblite
2024-03-08 11:27:14
(2 years ago)
LONG_RUNNING WP_XMLRPC_ABUSE
Brute-Force
Web App Attack
๐ฉ๐ช
corthorn
2024-03-07 12:02:11
(2 years ago)
2400:8904::f03c:93ff:fe5f:3c5f - - [07/Mar/2024:13:02:10 +0100] "POST /xmlrpc.php HTTP/1.1" 403 4171 ...
show more
2400:8904::f03c:93ff:fe5f:3c5f - - [07/Mar/2024:13:02:10 +0100] "POST /xmlrpc.php HTTP/1.1" 403 4171 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:54.0) Gecko/20100101 Firefox/54.0"
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-03-05 12:39:07
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2400:8904::f03c:93ff:fe5f:3c5f (Unknown): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 2400:8904::f03c:93ff:fe5f:3c5f (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 05 07:39:03.497470 2024] [security2:error] [pid 17712] [client 2400:8904::f03c:93ff:fe5f:3c5f:41640] [client 2400:8904::f03c:93ff:fe5f:3c5f] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mail.abilityengraving.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mail.abilityengraving.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZecSZz3krkd7--GwKHG5TgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-05 12:13:06
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2400:8904::f03c:93ff:fe5f:3c5f (Unknown): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 2400:8904::f03c:93ff:fe5f:3c5f (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 05 07:12:59.577781 2024] [security2:error] [pid 23506] [client 2400:8904::f03c:93ff:fe5f:3c5f:43064] [client 2400:8904::f03c:93ff:fe5f:3c5f] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mail.cienmalos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mail.cienmalos.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZecMSzsAKkO4g20td2PSpQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-04 06:27:59
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2400:8904::f03c:93ff:fe5f:3c5f (Unknown): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 2400:8904::f03c:93ff:fe5f:3c5f (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 04 01:27:55.356437 2024] [security2:error] [pid 13709] [client 2400:8904::f03c:93ff:fe5f:3c5f:56944] [client 2400:8904::f03c:93ff:fe5f:3c5f] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.transcapitalsolutions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.transcapitalsolutions.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZeVp62RBXQn2Ap3zRv3fnwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack