π©πͺ
ger-stg-sifi1
2024-04-11 23:28:49
(2 years ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
πΊπΈ
TPI-Abuse
2024-04-11 20:05:19
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2607:f298:6:a077::e6:eb42 (propheticvisions.wor ...
show more
(mod_security) mod_security (id:225170) triggered by 2607:f298:6:a077::e6:eb42 (propheticvisions.world): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 11 16:05:15.869078 2024] [security2:error] [pid 13674] [client 2607:f298:6:a077::e6:eb42:55628] [client 2607:f298:6:a077::e6:eb42] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||orcastrong.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "orcastrong.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZhhCe8jCNja4A1mXaVXXlgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
WebWizards.NZ
2024-04-10 16:35:36
(2 years ago)
Trolling for resource vulnerabilities
Web App Attack
πΊπΈ
TPI-Abuse
2024-04-10 16:34:50
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2607:f298:6:a077::e6:eb42 (propheticvisions.wor ...
show more
(mod_security) mod_security (id:225170) triggered by 2607:f298:6:a077::e6:eb42 (propheticvisions.world): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 10 12:34:45.434644 2024] [security2:error] [pid 30985] [client 2607:f298:6:a077::e6:eb42:37706] [client 2607:f298:6:a077::e6:eb42] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.platinummedicalevaluations.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.platinummedicalevaluations.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Zha_pRCXVmR4G3zLs1W0IQAAAAA"], referer: http://www.platinumeval.com///wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-04-10 16:10:36
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2607:f298:6:a077::e6:eb42 (propheticvisions.wor ...
show more
(mod_security) mod_security (id:225170) triggered by 2607:f298:6:a077::e6:eb42 (propheticvisions.world): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 10 12:10:29.328707 2024] [security2:error] [pid 25114] [client 2607:f298:6:a077::e6:eb42:40532] [client 2607:f298:6:a077::e6:eb42] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mail.mlsdirect.xyz|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mail.mlsdirect.xyz"] [uri "/wp-json/wp/v2/users/"] [unique_id "Zha59dyuTOH3Arh3OgxPOwAAAAA"], referer: http://mail.mlsdirect.xyz///wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
cmbplf
2024-04-10 08:25:43
(2 years ago)
3.794 requests to /xmlrpc.php
Brute-Force
Bad Web Bot
πΊπΈ
mawan
2024-04-10 08:14:11
(2 years ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
π³π±
maxxsense
2024-04-10 07:20:19
(2 years ago)
(wordpress) Failed wordpress login from 2607:f298:6:a077::e6:eb42 (US/United States/propheticvisions ...
show more
(wordpress) Failed wordpress login from 2607:f298:6:a077::e6:eb42 (US/United States/propheticvisions.world)
show less
Brute-Force
π¦πΊ
weblite
2024-04-10 06:21:48
(2 years ago)
WP_XMLRPC_ABUSE
Brute-Force
Web App Attack
πΊπΈ
dtorrer
2024-04-10 05:25:59
(2 years ago)
Dictionary attack on login resource.
Brute-Force
π¬π§
Swiptly
2024-04-10 04:14:03
(2 years ago)
WordPress xmlrpc spam or enumeration
...
Web Spam
Bad Web Bot
Web App Attack
π©πͺ
Ba-Yu
2024-04-10 03:48:51
(2 years ago)
WP-xmlrpc exploit
Web Spam
Blog Spam
Hacking
Exploited Host
Web App Attack
π©πͺ
ger-stg-sifi1
2024-04-10 03:22:36
(2 years ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
π©πͺ
jasperedv.de
2024-04-10 03:19:16
(2 years ago)
Apache Login - Brutforcing
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2024-04-09 16:53:02
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2607:f298:6:a077::e6:eb42 (propheticvisions.wor ...
show more
(mod_security) mod_security (id:225170) triggered by 2607:f298:6:a077::e6:eb42 (propheticvisions.world): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 09 12:52:58.806175 2024] [security2:error] [pid 6156] [client 2607:f298:6:a077::e6:eb42:38194] [client 2607:f298:6:a077::e6:eb42] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mail.pixacast.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mail.pixacast.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZhVyalG84IobjTEzWU7GWAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack