๐บ๐ธ
TPI-Abuse
2025-01-02 20:40:41
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:242:1b0c::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:242:1b0c::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 02 15:40:34.694995 2025] [security2:error] [pid 2624:tid 2624] [client 2a01:4f8:242:1b0c::2:50658] [client 2a01:4f8:242:1b0c::2] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.pushingbubbles.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.pushingbubbles.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z3b5wo9RlTPaEiRfSPPqZwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-02 17:57:38
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:242:1b0c::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:242:1b0c::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 02 12:57:30.750475 2025] [security2:error] [pid 3167142:tid 3167142] [client 2a01:4f8:242:1b0c::2:34090] [client 2a01:4f8:242:1b0c::2] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||hawaiivacations.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "hawaiivacations.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z3bTimxxT2sBTpWGxb0P2AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-02 16:40:15
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:242:1b0c::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:242:1b0c::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 02 11:40:07.627057 2025] [security2:error] [pid 8402:tid 8402] [client 2a01:4f8:242:1b0c::2:32918] [client 2a01:4f8:242:1b0c::2] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.jdeloa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.jdeloa.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z3bBZ0_3d_yV5lAF84g3sAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-02 11:31:18
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:242:1b0c::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:242:1b0c::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 02 06:31:13.118151 2025] [security2:error] [pid 4108851:tid 4108851] [client 2a01:4f8:242:1b0c::2:58634] [client 2a01:4f8:242:1b0c::2] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||atmoorehealthcare.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "atmoorehealthcare.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z3Z5AehBBShU0YiZKwsB0gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-02 11:13:38
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:242:1b0c::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:242:1b0c::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 02 06:13:35.178805 2025] [security2:error] [pid 44877:tid 44877] [client 2a01:4f8:242:1b0c::2:46466] [client 2a01:4f8:242:1b0c::2] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||metcomarine.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "metcomarine.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z3Z037MNQ0a4hOq1XsOWKwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-02 08:17:20
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:242:1b0c::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:242:1b0c::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 02 03:17:17.372570 2025] [security2:error] [pid 763977:tid 763993] [client 2a01:4f8:242:1b0c::2:33462] [client 2a01:4f8:242:1b0c::2] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dasperformance.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dasperformance.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z3ZLjfI1SiWYAHhE1p1y7gAAAUw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
F242
2025-01-01 02:48:32
(1 year ago)
Wordpress Login or XMLRPC abuse
Web App Attack
๐ฌ๐ง
BRHosting
2024-12-31 10:25:02
(1 year ago)
Wordpress brute force attack for login credentials (eg xmlrc.php or wp-login.php)
Brute-Force
Web App Attack
๐ฆ๐บ
weblite
2024-12-31 04:12:59
(1 year ago)
WP_XMLRPC_ABUSE
Brute-Force
Web App Attack
๐ณ๐ฑ
ipoac.nl
2024-12-31 03:35:15
(1 year ago)
***:443 2a01:4f8:242:1b0c::2 - - [31/Dec/2024:04:35:15 +0100] *** "POST /xmlrpc.php HTTP/1.1" 403 41 ...
show more
***:443 2a01:4f8:242:1b0c::2 - - [31/Dec/2024:04:35:15 +0100] *** "POST /xmlrpc.php HTTP/1.1" 403 4120 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:24.0) Gecko/20100101 Firefox/24.0"
show less
Bad Web Bot
๐ฆ๐บ
MAGIC
2024-12-19 20:00:56
(1 year ago)
VM5 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ฆ๐บ
weblite
2024-12-17 14:30:12
(1 year ago)
WP_XMLRPC_ABUSE
Brute-Force
Web App Attack
๐ณ๐ฑ
ipoac.nl
2024-12-16 20:50:19
(1 year ago)
***:443 2a01:4f8:242:1b0c::2 - - [16/Dec/2024:21:50:18 +0100] *** "POST /xmlrpc.php HTTP/1.1" 403 41 ...
show more
***:443 2a01:4f8:242:1b0c::2 - - [16/Dec/2024:21:50:18 +0100] *** "POST /xmlrpc.php HTTP/1.1" 403 4119 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.114 Safari/537.36"
show less
Bad Web Bot
๐ฉ๐ช
corthorn
2024-12-13 16:43:29
(1 year ago)
2a01:4f8:242:1b0c::2 - - [13/Dec/2024:17:43:28 +0100] "POST /xmlrpc.php HTTP/1.1" 403 4194 "-" "Mozi ...
show more
2a01:4f8:242:1b0c::2 - - [13/Dec/2024:17:43:28 +0100] "POST /xmlrpc.php HTTP/1.1" 403 4194 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36"
...
show less
Brute-Force
๐ฉ๐ช
Ba-Yu
2024-12-07 23:25:45
(1 year ago)
WP-xmlrpc exploit
Web Spam
Blog Spam
Hacking
Exploited Host
Web App Attack