πΉπ·
rtbh.com.tr
2025-12-15 20:10:28
(8 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
πΊπΈ
TPI-Abuse
2025-12-14 14:20:26
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 45.118.133.179 (45-118-133-179.ip.linodeusercon ...
show more
(mod_security) mod_security (id:225170) triggered by 45.118.133.179 (45-118-133-179.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 14 09:20:21.684486 2025] [security2:error] [pid 19000:tid 19000] [client 45.118.133.179:59553] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.bostonlog.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.bostonlog.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aT7HpXTz1MnNrWsuqXiKswAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³πΏ
Antinson
2025-12-14 12:32:46
(9 months ago)
Scraping with a high error ratio and request rate
Bad Web Bot
πΊπΈ
TPI-Abuse
2025-12-13 17:32:07
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 45.118.133.179 (45-118-133-179.ip.linodeusercon ...
show more
(mod_security) mod_security (id:225170) triggered by 45.118.133.179 (45-118-133-179.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 13 12:32:02.186352 2025] [security2:error] [pid 18941:tid 18941] [client 45.118.133.179:56937] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bosdkbook.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bosdkbook.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aT2jEoXh62C4t_bDIItqiAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
cmbplf
2025-12-12 23:59:40
(9 months ago)
9.468 POST requests in 1 hour (1yr10mos3w)
Brute-Force
Bad Web Bot
Anonymous
2025-12-12 22:14:33
(9 months ago)
Bot / scanning and/or hacking attempts: POST //xmlrpc.php HTTP/1.1
Hacking
Web App Attack
πΉπ·
rtbh.com.tr
2025-12-10 20:10:23
(9 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
π³π±
Site.eu
2025-12-09 02:09:57
(9 months ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
πΊπΈ
TPI-Abuse
2025-12-08 21:29:39
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 45.118.133.179 (45-118-133-179.ip.linodeusercon ...
show more
(mod_security) mod_security (id:225170) triggered by 45.118.133.179 (45-118-133-179.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 08 16:29:32.187999 2025] [security2:error] [pid 4248:tid 4248] [client 45.118.133.179:64670] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bonesband.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bonesband.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aTdDPI-EUnYAgAiqXD1OfQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-08 21:00:37
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 45.118.133.179 (45-118-133-179.ip.linodeusercon ...
show more
(mod_security) mod_security (id:225170) triggered by 45.118.133.179 (45-118-133-179.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 08 16:00:30.219929 2025] [security2:error] [pid 13249:tid 13249] [client 45.118.133.179:56054] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bonegym.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bonegym.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aTc8btiitEd9-P7fr_jGtAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΉπ·
rtbh.com.tr
2025-12-08 20:10:20
(9 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
π©πͺ
neckaralb-admin.de
2025-12-08 05:31:29
(9 months ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
π©πͺ
bsoft.de
2025-12-08 01:01:16
(9 months ago)
45.118.133.179 - - [08/Dec/2025:02:01:08 +0100] "GET //xmlrpc.php?rsd HTTP/1.1" 200 786 "-" "Mozilla ...
show more
45.118.133.179 - - [08/Dec/2025:02:01:08 +0100] "GET //xmlrpc.php?rsd HTTP/1.1" 200 786 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
45.118.133.179 - - [08/Dec/2025:02:01:13 +0100] "GET //wp-json/wp/v2/users/ HTTP/1.1" 404 144 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
45.118.133.179 - - [08/Dec/2025:02:01:14 +0100] "POST //xmlrpc.php HTTP/1.1" 200 426 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
show less
Web App Attack
πΉπ·
rtbh.com.tr
2025-12-07 20:10:19
(9 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
π·πΊ
DZBOT
2025-12-07 00:05:44
(9 months ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack