๐ณ๐ฑ
BlueWire Hosting
2023-12-17 21:10:16
(2 years ago)
Probing for Wordpress vulnerabilities
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-17 20:53:41
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:1a:a095::2 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:1a:a095::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 17 15:53:35.654215 2023] [security2:error] [pid 4048] [client 2a01:4f9:1a:a095::2:45390] [client 2a01:4f9:1a:a095::2] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.waterspell.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.waterspell.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZX9fz4gbQ7oX5cEZWONoFgAAAAY"], referer: http://sevenriverspublishing.com///wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-17 20:11:47
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:1a:a095::2 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:1a:a095::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 17 15:11:41.184400 2023] [security2:error] [pid 18055] [client 2a01:4f9:1a:a095::2:46314] [client 2a01:4f9:1a:a095::2] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bickleton.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bickleton.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZX9V_Y3c-Rl7z_l8e9HcWgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Max la Menace
2023-12-17 19:31:35
(2 years ago)
Wordpress attack (F)
Blog Spam
Web App Attack
๐ฉ๐ช
SCHAPPY
2023-12-17 18:55:30
(2 years ago)
Mutliple attempts to access web resources unauthorized, HTTP code 403.
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-17 18:24:34
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:1a:a095::2 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:1a:a095::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 17 13:24:26.837272 2023] [security2:error] [pid 23048] [client 2a01:4f9:1a:a095::2:60894] [client 2a01:4f9:1a:a095::2] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||theaccents.mainstreetofficesuites.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "theaccents.mainstreetofficesuites.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZX882jh4mVAT5mChGuYT7wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-17 17:23:16
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:1a:a095::2 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:1a:a095::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 17 12:23:14.162964 2023] [security2:error] [pid 472] [client 2a01:4f9:1a:a095::2:44438] [client 2a01:4f9:1a:a095::2] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||illumoonatedtarot.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "illumoonatedtarot.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZX8ugmV2Hm35EmIWcPq8QQAAAAc"], referer: http://illumoonatedtarot.com///wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-17 17:06:55
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:1a:a095::2 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:1a:a095::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 17 12:06:52.157530 2023] [security2:error] [pid 28538] [client 2a01:4f9:1a:a095::2:59746] [client 2a01:4f9:1a:a095::2] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||trekandpaddle.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "trekandpaddle.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZX8qrOhiXBAtTzQEL_FYhwAAAAQ"], referer: http://trekandpaddle.com///wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
OiledAmoeba
2023-12-17 16:40:21
(2 years ago)
Dec 17 17:40:20 10.23.100.230 wordpress(www.ruhnke.cloud)[79901]: Blocked user enumeration attempt f ...
show more
Dec 17 17:40:20 10.23.100.230 wordpress(www.ruhnke.cloud)[79901]: Blocked user enumeration attempt from 2a01:4f9:1a:a095::2
...
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-17 16:15:50
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:1a:a095::2 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:1a:a095::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 17 11:15:46.586548 2023] [security2:error] [pid 17052] [client 2a01:4f9:1a:a095::2:38822] [client 2a01:4f9:1a:a095::2] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||truthsabouthealthcare.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "truthsabouthealthcare.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZX8esttTjxB_nV4VqdlbwAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
iNetWorker
2023-12-17 15:45:56
(2 years ago)
trolling for resource vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-17 15:42:10
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:1a:a095::2 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:1a:a095::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 17 10:42:06.082643 2023] [security2:error] [pid 17671] [client 2a01:4f9:1a:a095::2:37322] [client 2a01:4f9:1a:a095::2] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||energycapitalinvestments.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "energycapitalinvestments.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZX8Wzmstnclw-1D5GOm-0AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Mr-Money
2023-12-17 14:29:19
(2 years ago)
2a01:4f9:1a:a095::2 - - [17/Dec/2023:15:29:19 +0100] "GET /wp-login.php HTTP/1.1" 404 4540 "http://b ...
show more
2a01:4f9:1a:a095::2 - - [17/Dec/2023:15:29:19 +0100] "GET /wp-login.php HTTP/1.1" 404 4540 "http://bipro-box.de/wp-login.php" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0"
...
show less
Hacking
SQL Injection
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-17 14:16:41
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:1a:a095::2 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:1a:a095::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 17 09:16:34.310092 2023] [security2:error] [pid 28398] [client 2a01:4f9:1a:a095::2:58894] [client 2a01:4f9:1a:a095::2] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||americasdairylandgolf.landoflincolngolf.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "americasdairylandgolf.landoflincolngolf.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZX8CwgAmuXxwa0Avatf-gAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-17 13:59:43
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:1a:a095::2 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:1a:a095::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 17 08:59:36.638184 2023] [security2:error] [pid 11823] [client 2a01:4f9:1a:a095::2:53910] [client 2a01:4f9:1a:a095::2] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bosdkbook.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bosdkbook.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZX7-yBoPOBKmixwxX6j94AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack