๐บ๐ธ
mawan
2023-11-29 19:02:59
(2 years ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
mawan
2023-11-28 10:28:35
(2 years ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐จ๐ญ
Ciamaro Over
2023-11-27 09:23:43
(2 years ago)
wp login attack
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2023-11-26 20:00:06
(2 years ago)
2a01:4f9:c011:f24::1 - - [26/Nov/2023:21:00:04 +0100] "GET /wp-login.php HTTP/1.1" 401 696 "-" "Mozi ...
show more
2a01:4f9:c011:f24::1 - - [26/Nov/2023:21:00:04 +0100] "GET /wp-login.php HTTP/1.1" 401 696 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0"
2a01:4f9:c011:f24::1 - - [26/Nov/2023:21:00:04 +0100] "POST /wp-login.php HTTP/1.1" 401 696 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0"
2a01:4f9:c011:f24::1 - - [26/Nov/2023:21:00:05 +0100] "POST /xmlrpc.php HTTP/1.1" 401 696 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0"
...
show less
Web App Attack
๐ฉ๐ช
corthorn
2023-11-25 09:48:10
(2 years ago)
2a01:4f9:c011:f24::1 - - [25/Nov/2023:10:48:09 +0100] "POST /xmlrpc.php HTTP/1.1" 403 400 "-" "Mozil ...
show more
2a01:4f9:c011:f24::1 - - [25/Nov/2023:10:48:09 +0100] "POST /xmlrpc.php HTTP/1.1" 403 400 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0"
...
show less
Brute-Force
๐ฆ๐บ
weblite
2023-11-25 00:20:55
(2 years ago)
WP_LOGIN_FAIL WP_XMLRPC_ABUSE
Brute-Force
Web App Attack
๐ฉ๐ช
Ba-Yu
2023-11-24 20:06:06
(2 years ago)
WP-xmlrpc exploit
Web Spam
Blog Spam
Hacking
Exploited Host
Web App Attack
๐ฉ๐ช
Ba-Yu
2023-11-24 13:23:27
(2 years ago)
WordPress hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ฉ๐ช
eminovic.ba
2023-11-24 03:31:46
(2 years ago)
Wordpress attack
...
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-17 07:11:29
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:c011:f24::1 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:c011:f24::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 17 02:11:25.340144 2023] [security2:error] [pid 18127] [client 2a01:4f9:c011:f24::1:37824] [client 2a01:4f9:c011:f24::1] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jdgcargo.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jdgcargo.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZVcSHffwGWbAMk8nKSgdyAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-17 06:18:54
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:c011:f24::1 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:c011:f24::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 17 01:18:48.627918 2023] [security2:error] [pid 13515] [client 2a01:4f9:c011:f24::1:43312] [client 2a01:4f9:c011:f24::1] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||moacyrscliar.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "moacyrscliar.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZVcFyCVyvppz1FXNxzYDWgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-16 18:19:46
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:c011:f24::1 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:c011:f24::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 16 13:19:42.776609 2023] [security2:error] [pid 27509] [client 2a01:4f9:c011:f24::1:35552] [client 2a01:4f9:c011:f24::1] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bamedica.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bamedica.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZVZdPoQrLkcavbNB4NuxKAAAABA"], referer: http://testonal.com///wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-16 17:57:59
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:c011:f24::1 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:c011:f24::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 16 12:57:53.702080 2023] [security2:error] [pid 822:tid 47868522764032] [client 2a01:4f9:c011:f24::1:54000] [client 2a01:4f9:c011:f24::1] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||trulyoriginalpurpleoctopus.art|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "trulyoriginalpurpleoctopus.art"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZVZYIVYcmObx-Z2usSw9mgAAAkc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-16 17:32:15
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:c011:f24::1 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:c011:f24::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 16 12:32:11.464077 2023] [security2:error] [pid 23431:tid 47333979719424] [client 2a01:4f9:c011:f24::1:38378] [client 2a01:4f9:c011:f24::1] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mindgardens.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mindgardens.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZVZSGxmSKUX8ttejA2-xAwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-16 13:01:26
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:c011:f24::1 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:c011:f24::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 16 08:01:20.478930 2023] [security2:error] [pid 20881] [client 2a01:4f9:c011:f24::1:42124] [client 2a01:4f9:c011:f24::1] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nextlevelcharge.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nextlevelcharge.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZVYSoFv-v2xla03p6SvQtgAAAAk"], referer: http://evohio.net///wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack