๐ซ๐ท
urmarcht
2025-11-25 05:31:15
(10 months ago)
Bot attack detected : webscan vurnerability
Web App Attack
๐ณ๐ฑ
Joop
2025-11-20 07:42:05
(10 months ago)
2025-11-20 08:41:58 +0200 s9 /xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-20 06:29:05
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 39.63.46.79 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 39.63.46.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 20 01:29:00.900818 2025] [security2:error] [pid 24022:tid 24022] [client 39.63.46.79:61846] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||casadelsolmexico.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "casadelsolmexico.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aR61LFEjZ9_-tNioDruY0wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2025-11-20 05:49:46
(10 months ago)
Blocking for trying to access an exploit file: /xmlrpc.php
Hacking
๐ฉ๐ช
bescared
2025-11-19 12:22:41
(10 months ago)
F2B - Malicious activity detected. URL Probing.
Hacking
Bad Web Bot
Web App Attack
๐ซ๐ท
urmarcht
2025-11-19 06:47:27
(10 months ago)
Bot attack detected : webscan vurnerability
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-19 06:35:37
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 39.63.46.79 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 39.63.46.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 19 01:35:29.547674 2025] [security2:error] [pid 18272:tid 18272] [client 39.63.46.79:61187] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||twinls.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "twinls.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aR1lMZxXhQYkwNPSl18RLwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ช
Unwasted
2025-11-19 06:15:35
(10 months ago)
Blocked IP still knocking
Hacking
๐ซ๐ท
COMAITE
2025-11-19 04:52:12
(10 months ago)
Multiple web server 400 error codes from same source ip 39.63.46.79.
Web App Attack
๐ซ๐ฎ
stinpriza
2025-11-19 04:21:03
(10 months ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-19 03:25:49
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 39.63.46.79 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 39.63.46.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 18 22:25:43.903481 2025] [security2:error] [pid 15443:tid 15443] [client 39.63.46.79:62186] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||saadeh.ws|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "saadeh.ws"] [uri "/wp-json/wp/v2/users"] [unique_id "aR04txPLyDXYVIyPSFDmDgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2025-11-19 00:22:45
(10 months ago)
1.384 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-11-18 22:05:30
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 39.63.46.79 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 39.63.46.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 18 17:05:24.960386 2025] [security2:error] [pid 15726:tid 15726] [client 39.63.46.79:60194] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||monogay.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "monogay.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aRztpHk5D0jHgNTD4XlmZwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ช
Unwasted
2025-11-18 20:41:52
(10 months ago)
File scanning
Hacking
Web App Attack
Anonymous
2025-11-18 12:21:24
(10 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH