๐ซ๐ฎ
YF
2025-05-30 18:00:20
(1 year ago)
xmlrpc.php (Potential DDoS or brute force)
Brute-Force
Web App Attack
๐ฉ๐ช
mondor.ro
2025-05-30 17:16:18
(1 year ago)
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 3.85.110.24, Reason:[( ...
show more
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 3.85.110.24, Reason:[(manifest) WordPress wlwmanifest.xml Attack 3.85.110.24 (US/United States/ec2-3-85-110-24.compute-1.amazonaws.com): 10 in the last 3600 secs]; Ports: *; Direction: inout; Trigger: LF_CLUSTER; Logs:
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2025-05-30 15:36:22
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 3.85.110.24 (ec2-3-85-110-24.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:225170) triggered by 3.85.110.24 (ec2-3-85-110-24.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 30 11:36:15.363579 2025] [security2:error] [pid 366379:tid 366379] [client 3.85.110.24:53215] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||flybits.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "flybits.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "aDnQbw9jZFw7TwldRNh8AAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-30 13:50:55
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 3.85.110.24 (ec2-3-85-110-24.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:225170) triggered by 3.85.110.24 (ec2-3-85-110-24.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 30 09:50:48.495065 2025] [security2:error] [pid 209296:tid 209296] [client 3.85.110.24:64976] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.fatcaverecords.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.fatcaverecords.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aDm3uFioPprJofO5Ec6dewAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
ingroscart.it
2025-05-30 13:37:50
(1 year ago)
(mod_security) mod_security triggered on hostname [redacted] 3.85.110.24 (US/United States/ec2-3-85- ...
show more
(mod_security) mod_security triggered on hostname [redacted] 3.85.110.24 (US/United States/ec2-3-85-110-24.compute-1.amazonaws.com)
show less
SQL Injection
Anonymous
2025-05-30 13:33:50
(1 year ago)
(wordpress) Failed wordpress login from 3.85.110.24 (US/United States/ec2-3-85-110-24.compute-1.amaz ...
show more
(wordpress) Failed wordpress login from 3.85.110.24 (US/United States/ec2-3-85-110-24.compute-1.amazonaws.com)
show less
Brute-Force
Anonymous
2025-05-30 13:04:48
(1 year ago)
Bad Web Bot
Web App Attack
Anonymous
2025-05-30 12:35:02
(1 year ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Progetto1
2025-05-30 12:32:03
(1 year ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-30 12:27:27
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 3.85.110.24 (ec2-3-85-110-24.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:225170) triggered by 3.85.110.24 (ec2-3-85-110-24.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 30 08:27:23.526219 2025] [security2:error] [pid 335688:tid 335688] [client 3.85.110.24:53606] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.taekwondoit.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.taekwondoit.com"] [uri "/about-us/wp-json/wp/v2/users/"] [unique_id "aDmkKycYkkEIsIjtca0IIwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-30 11:04:13
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 3.85.110.24 (ec2-3-85-110-24.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:225170) triggered by 3.85.110.24 (ec2-3-85-110-24.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 30 07:04:10.313533 2025] [security2:error] [pid 292013:tid 292013] [client 3.85.110.24:64244] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||emailaegis.axiomemail.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "emailaegis.axiomemail.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "aDmQqnMA4wn1x1x1CMduvAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐น
Evag Touf
2025-05-30 10:54:40
(1 year ago)
(wordpress) Failed wordpress login from 3.85.110.24 (US/United States/-): (CF_ENABLE)
Brute-Force
Anonymous
2025-05-30 10:12:07
(1 year ago)
(wordpress) Failed wordpress login from 3.85.110.24 (US/United States/ec2-3-85-110-24.compute-1.amaz ...
show more
(wordpress) Failed wordpress login from 3.85.110.24 (US/United States/ec2-3-85-110-24.compute-1.amazonaws.com)
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-05-30 10:09:09
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 3.85.110.24 (ec2-3-85-110-24.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:225170) triggered by 3.85.110.24 (ec2-3-85-110-24.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 30 06:09:03.774137 2025] [security2:error] [pid 173169:tid 173169] [client 3.85.110.24:51491] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||edgecomix.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "edgecomix.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aDmDv7dbDCDORhk5Oh7CaQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-30 09:42:52
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 3.85.110.24 (ec2-3-85-110-24.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:225170) triggered by 3.85.110.24 (ec2-3-85-110-24.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 30 05:42:47.871406 2025] [security2:error] [pid 261587:tid 261587] [client 3.85.110.24:51413] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.earthtwoworkshop.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.earthtwoworkshop.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aDl9l_MgGK9-9RpI2PURAAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack