๐บ๐ธ
TPI-Abuse
2023-11-18 07:24:27
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 18 02:24:24.329131 2023] [security2:error] [pid 26438] [client 2a01:4f8:191:80ea::2:35146] [client 2a01:4f8:191:80ea::2] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||engineeringarts.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "engineeringarts.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZVhmqF9THzU0ivnA0dVBkAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-17 15:49:32
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 17 10:49:25.894384 2023] [security2:error] [pid 24021] [client 2a01:4f8:191:80ea::2:41524] [client 2a01:4f8:191:80ea::2] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.globizgate.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.globizgate.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZVeLhayO1ipu6oI4hM0b3QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-17 15:23:26
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 17 10:23:20.106189 2023] [security2:error] [pid 16907] [client 2a01:4f8:191:80ea::2:55188] [client 2a01:4f8:191:80ea::2] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||englishpro.kidswow.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "englishpro.kidswow.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZVeFaBKJwW6e11oAoV_9swAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
iNetWorker
2023-11-16 18:21:38
(2 years ago)
trolling for resource vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-16 18:13:47
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 16 13:13:43.992289 2023] [security2:error] [pid 19570] [client 2a01:4f8:191:80ea::2:55848] [client 2a01:4f8:191:80ea::2] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mjkhan.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mjkhan.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZVZb1xsLZ9K26sx2GPYmKAAAAAY"], referer: http://mjkhan.org///wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-16 17:56:06
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 16 12:56:02.239594 2023] [security2:error] [pid 7556] [client 2a01:4f8:191:80ea::2:60288] [client 2a01:4f8:191:80ea::2] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kairoslogammakmur.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kairoslogammakmur.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZVZXsjiBvtZmU-w6x1ijOAAAAAM"], referer: http://kairoslogammakmur.com///wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2023-11-16 17:49:18
(2 years ago)
(wordpress-user-enum) Failed wordpress-user-enum trigger from 2a01:4f8:191:80ea::2 (DE/Germany/Baden ...
show more
(wordpress-user-enum) Failed wordpress-user-enum trigger from 2a01:4f8:191:80ea::2 (DE/Germany/Baden-Wurttemberg/Klettgau/-/[redacted]): (CF_ENABLE)
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2023-11-16 17:30:27
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 16 12:30:24.255966 2023] [security2:error] [pid 7983] [client 2a01:4f8:191:80ea::2:55798] [client 2a01:4f8:191:80ea::2] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||arsenalfordemocracy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "arsenalfordemocracy.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZVZRsHrMgA4ZiId_Vap78AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-16 12:40:51
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 16 07:40:47.791606 2023] [security2:error] [pid 29571] [client 2a01:4f8:191:80ea::2:56206] [client 2a01:4f8:191:80ea::2] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||riquisimas.club|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "riquisimas.club"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZVYNz2DJcrWA2WkUEo843AAAAAo"], referer: http://riquisimas.club///wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-16 12:06:44
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 16 07:06:36.278609 2023] [security2:error] [pid 16574] [client 2a01:4f8:191:80ea::2:51610] [client 2a01:4f8:191:80ea::2] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||investlocalinc.socialenterprise.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "investlocalinc.socialenterprise.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZVYFzE5RCoK_rtp2uz24ngAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2023-11-07 16:16:34
(2 years ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
mawan
2023-11-06 06:35:59
(2 years ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
mawan
2023-11-04 16:00:08
(2 years ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ณ๐ฑ
ipoac.nl
2023-11-04 14:53:29
(2 years ago)
2023-11-04T15:53:28.720222+01:00 ipoac.nl wordpress(5fm.nu)[36326]: XML-RPC authentication failure f ...
show more
2023-11-04T15:53:28.720222+01:00 ipoac.nl wordpress(5fm.nu)[36326]: XML-RPC authentication failure for admin from 2a01:4f8:191:80ea::2
show less
Web App Attack
๐ฉ๐ช
Sysadmin Peter
2023-11-01 14:13:17
(2 years ago)
2a01:4f8:191:80ea::2 - - [01/Nov/2023:15:13:17 +0100] "POST /wordpress/wp-login.php HTTP/1.1" 200 83 ...
show more
2a01:4f8:191:80ea::2 - - [01/Nov/2023:15:13:17 +0100] "POST /wordpress/wp-login.php HTTP/1.1" 200 8368 "https://pigflag.org/wordpress/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/67.0.3396.99 Safari/537.36"
...
show less
Brute-Force
Web App Attack