๐จ๐ฆ
mitsurugi
2025-03-23 17:32:00
(1 year ago)
Xmlrpc attack.
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2025-03-19 11:05:45
(1 year ago)
Too many Status 40X (12)
Brute-Force
Web App Attack
๐ฆ๐บ
MAGIC
2025-03-19 11:00:36
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-03-19 10:50:08
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 34.42.161.186 (186.161.42.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 34.42.161.186 (186.161.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 19 06:50:01.104054 2025] [security2:error] [pid 1412625:tid 1412625] [client 34.42.161.186:56512] [client 34.42.161.186] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||servecon.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "servecon.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "Z9qhWTTCiC_0Y3NXflhRCQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-03-19 10:47:57
(1 year ago)
(wordpress) Failed wordpress login from 34.42.161.186 (US/United States/186.161.42.34.bc.googleuserc ...
show more
(wordpress) Failed wordpress login from 34.42.161.186 (US/United States/186.161.42.34.bc.googleusercontent.com)
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-03-19 10:33:58
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 34.42.161.186 (186.161.42.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 34.42.161.186 (186.161.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 19 06:33:50.916610 2025] [security2:error] [pid 26661:tid 26661] [client 34.42.161.186:65274] [client 34.42.161.186] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.bradleybarefoot.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.bradleybarefoot.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Z9qdjkbO7CFRWQ8Rs1GV_gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2025-03-19 10:22:39
(1 year ago)
73.319 requests to */xmlrpc.php
Brute-Force
Bad Web Bot
๐ธ๐ฌ
pusathosting.com
2025-03-19 10:18:03
(1 year ago)
2ds22 bruteforce
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2025-03-19 10:15:17
(1 year ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-03-19 10:14:24
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 34.42.161.186 (186.161.42.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 34.42.161.186 (186.161.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 19 06:14:19.517553 2025] [security2:error] [pid 8926:tid 8926] [client 34.42.161.186:56770] [client 34.42.161.186] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||hazeltrane.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "hazeltrane.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Z9qY-_CZ45qaPqQREoGn1QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฑ
Dolphi
2025-03-19 10:10:02
(1 year ago)
POST //xmlrpc.php
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-19 09:55:17
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 34.42.161.186 (186.161.42.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 34.42.161.186 (186.161.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 19 05:55:12.603571 2025] [security2:error] [pid 1240684:tid 1240684] [client 34.42.161.186:57056] [client 34.42.161.186] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.takemehomedogrescue.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.takemehomedogrescue.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "Z9qUgP107-8idpgod33WqwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack