๐ฉ๐ช
neckaralb-admin.de
2025-12-08 13:07:39
(9 months ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฎ๐น
Progetto1
2025-12-07 22:25:02
(9 months ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-07 04:13:54
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 3.25.164.51 (ec2-3-25-164-51.ap-southeast-2.com ...
show more
(mod_security) mod_security (id:225170) triggered by 3.25.164.51 (ec2-3-25-164-51.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 06 23:13:47.739648 2025] [security2:error] [pid 2712:tid 2726] [client 3.25.164.51:60900] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ainavelas.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ainavelas.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aTT--wKNP51U3TMztlyH_QAAAMw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-07 01:06:20
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 3.25.164.51 (ec2-3-25-164-51.ap-southeast-2.com ...
show more
(mod_security) mod_security (id:225170) triggered by 3.25.164.51 (ec2-3-25-164-51.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 06 20:06:16.181156 2025] [security2:error] [pid 6282:tid 6282] [client 3.25.164.51:51592] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dandksupply.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dandksupply.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aTTTCGNbJRXyJG_E187U8AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2025-12-06 19:10:45
(9 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-06 17:04:19
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 3.25.164.51 (ec2-3-25-164-51.ap-southeast-2.com ...
show more
(mod_security) mod_security (id:225170) triggered by 3.25.164.51 (ec2-3-25-164-51.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 06 12:04:16.697428 2025] [security2:error] [pid 30084:tid 30084] [client 3.25.164.51:61105] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||anus.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "anus.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aTRiEKk_p6DNpWlZwNdX7wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-06 13:32:22
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 3.25.164.51 (ec2-3-25-164-51.ap-southeast-2.com ...
show more
(mod_security) mod_security (id:225170) triggered by 3.25.164.51 (ec2-3-25-164-51.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 06 08:32:16.617683 2025] [security2:error] [pid 22728:tid 22728] [client 3.25.164.51:54007] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bergenoaks.com.velvetculture.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bergenoaks.com.velvetculture.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aTQwYHHBEgeeyc-AOQxsfQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-06 03:57:33
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 3.25.164.51 (ec2-3-25-164-51.ap-southeast-2.com ...
show more
(mod_security) mod_security (id:225170) triggered by 3.25.164.51 (ec2-3-25-164-51.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 22:57:27.203464 2025] [security2:error] [pid 4857:tid 4857] [client 3.25.164.51:52058] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kicking2achieve.org.kimbrothersusa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kicking2achieve.org.kimbrothersusa.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aTOpp4P8hdO-qgCsJKceMwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2025-12-06 01:46:41
(10 months ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-05 16:40:21
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 3.25.164.51 (ec2-3-25-164-51.ap-southeast-2.com ...
show more
(mod_security) mod_security (id:225170) triggered by 3.25.164.51 (ec2-3-25-164-51.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 11:40:16.050606 2025] [security2:error] [pid 17311:tid 17311] [client 3.25.164.51:52357] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nolaanime.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nolaanime.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aTMK8KITA1Vx3LNm4ClKHwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2025-12-05 07:31:35
(10 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐บ๐ธ
octageeks.com
2025-12-05 05:06:10
(10 months ago)
Wordpress malicious attack:[octa404]
Web App Attack
๐ฉ๐ช
Phenix Info
2025-12-04 00:22:48
(10 months ago)
SmallGuard.fr - HoneyPot
Web App Attack
๐ต๐ฑ
IROK
2025-11-29 12:27:01
(10 months ago)
Firewall Blocked - Unauthorized Port Scanning
...
Port Scan
๐บ๐ธ
TPI-Abuse
2025-11-29 06:16:25
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 3.25.164.51 (ec2-3-25-164-51.ap-southeast-2.com ...
show more
(mod_security) mod_security (id:225170) triggered by 3.25.164.51 (ec2-3-25-164-51.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 29 01:16:18.541731 2025] [security2:error] [pid 11114:tid 11114] [client 3.25.164.51:59903] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||citrineartstudio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "citrineartstudio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aSqPsmJoSCcyvLD_0Rt9BQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack