๐ฆ๐บ
MAGIC
2025-12-09 03:09:13
(9 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐จ๐ด
ingentar
2025-12-06 03:32:55
(9 months ago)
2025-12-05T22:32:43.912553-05:00 web wordpress(previnm.com)[667881]: Blocked user enumeration attemp ...
show more
2025-12-05T22:32:43.912553-05:00 web wordpress(previnm.com)[667881]: Blocked user enumeration attempt from 35.179.96.11
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2025-12-05 21:44:55
(9 months ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-05 20:28:41
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 35.179.96.11 (ec2-35-179-96-11.eu-west-2.comput ...
show more
(mod_security) mod_security (id:225170) triggered by 35.179.96.11 (ec2-35-179-96-11.eu-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 15:28:34.962903 2025] [security2:error] [pid 21496:tid 21496] [client 35.179.96.11:61269] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lenorasflowers.lahamradio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lenorasflowers.lahamradio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aTNAcndsHpcwWr4T05HNrQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-05 16:34:58
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 35.179.96.11 (ec2-35-179-96-11.eu-west-2.comput ...
show more
(mod_security) mod_security (id:225170) triggered by 35.179.96.11 (ec2-35-179-96-11.eu-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 11:34:52.312737 2025] [security2:error] [pid 9363:tid 9363] [client 35.179.96.11:61154] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||support.leonardodecaprio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "support.leonardodecaprio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aTMJrGJQ1bEJzU142_AEgQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-05 15:01:43
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 35.179.96.11 (ec2-35-179-96-11.eu-west-2.comput ...
show more
(mod_security) mod_security (id:225170) triggered by 35.179.96.11 (ec2-35-179-96-11.eu-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 10:01:37.914510 2025] [security2:error] [pid 13924:tid 13924] [client 35.179.96.11:65378] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||app.wholesalelivelobsters.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "app.wholesalelivelobsters.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aTLz0cA3ODVGEqcJxsocqwAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ด
ingentar
2025-12-05 13:33:58
(9 months ago)
2025-12-05T08:33:47.278656-05:00 web wordpress(previnm.com)[641768]: Blocked user enumeration attemp ...
show more
2025-12-05T08:33:47.278656-05:00 web wordpress(previnm.com)[641768]: Blocked user enumeration attempt from 35.179.96.11
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
FeG Deutschland
2025-12-05 10:48:25
(10 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐ฎ๐น
Giando
2025-12-03 22:51:00
(10 months ago)
CVE-2024-9707 probing
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2025-12-03 22:05:35
(10 months ago)
Too many Status 40X (12)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-03 02:32:12
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 35.179.96.11 (ec2-35-179-96-11.eu-west-2.comput ...
show more
(mod_security) mod_security (id:225170) triggered by 35.179.96.11 (ec2-35-179-96-11.eu-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 21:32:05.761391 2025] [security2:error] [pid 13587:tid 13587] [client 35.179.96.11:64600] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fundaciondamashcc.org.ec|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fundaciondamashcc.org.ec"] [uri "/wp-json/wp/v2/users"] [unique_id "aS-hJR1AnbxbBRU6v7nCjwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-03 01:02:33
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 35.179.96.11 (ec2-35-179-96-11.eu-west-2.comput ...
show more
(mod_security) mod_security (id:225170) triggered by 35.179.96.11 (ec2-35-179-96-11.eu-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 20:02:26.843031 2025] [security2:error] [pid 1588:tid 1588] [client 35.179.96.11:61821] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mail.arriagarealestate.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mail.arriagarealestate.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aS-MIiwUNVi_oQ8BEA1a-QAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-03 00:36:30
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 35.179.96.11 (ec2-35-179-96-11.eu-west-2.comput ...
show more
(mod_security) mod_security (id:225170) triggered by 35.179.96.11 (ec2-35-179-96-11.eu-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 19:36:24.082138 2025] [security2:error] [pid 32643:tid 32643] [client 35.179.96.11:62501] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sharonmauldin.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sharonmauldin.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aS-GCP2mtvTissEecfrT9gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 22:43:51
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 35.179.96.11 (ec2-35-179-96-11.eu-west-2.comput ...
show more
(mod_security) mod_security (id:225170) triggered by 35.179.96.11 (ec2-35-179-96-11.eu-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 17:43:46.061872 2025] [security2:error] [pid 16847:tid 16847] [client 35.179.96.11:58034] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||loneoakhoney.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "loneoakhoney.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aS9roix9jAJ0ACWKogb-aAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 21:02:50
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 35.179.96.11 (ec2-35-179-96-11.eu-west-2.comput ...
show more
(mod_security) mod_security (id:225170) triggered by 35.179.96.11 (ec2-35-179-96-11.eu-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 16:02:43.376889 2025] [security2:error] [pid 21477:tid 21477] [client 35.179.96.11:55574] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||billymitchell.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "billymitchell.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aS9T8_wlS3xrYo-qa1OVUQAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack