๐ธ๐ฎ
borisperc
2025-08-03 10:45:51
(1 year ago)
Web Spam
Port Scan
Hacking
SQL Injection
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-02 00:42:33
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.119.85.208 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.119.85.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 01 20:42:27.087228 2024] [security2:error] [pid 19435:tid 19435] [client 45.119.85.208:45160] [client 45.119.85.208] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.schlegelcreative.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.schlegelcreative.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZyV1czlOkNxwdyjLP16xjwAAAAo"], referer: http://www.schlegelcreative.com///wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-11-02 00:00:20
(1 year ago)
scanning for sensitive files: /wp-login.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-01 22:52:27
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.119.85.208 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.119.85.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 01 18:52:19.541509 2024] [security2:error] [pid 23570:tid 23610] [client 45.119.85.208:49108] [client 45.119.85.208] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||batonrougegazette.com.aafm.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "batonrougegazette.com.aafm.us"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZyVbo6gS6YqF5DoZAQ_oDgAAAcQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-01 22:26:32
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.119.85.208 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.119.85.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 01 18:26:26.729544 2024] [security2:error] [pid 21287:tid 21287] [client 45.119.85.208:33948] [client 45.119.85.208] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.kandocopies.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.kandocopies.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZyVVkoYJAHVvkoojdyGWEAAAACI"], referer: http://kandoprint.com///wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-01 21:07:54
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.119.85.208 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.119.85.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 01 17:07:48.726127 2024] [security2:error] [pid 13587:tid 13609] [client 45.119.85.208:34626] [client 45.119.85.208] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||chelseyrae.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "chelseyrae.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZyVDJPPqqKn5-rsRNFz_gwAAARQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-01 20:01:12
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.119.85.208 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.119.85.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 01 16:01:08.498755 2024] [security2:error] [pid 10343:tid 10343] [client 45.119.85.208:60864] [client 45.119.85.208] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||customhumanrobots.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "customhumanrobots.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZyUzhMBnfreVlYdOWOt-wwAAADU"], referer: http://www.horushoverbike.com///wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-11-01 19:12:15
(1 year ago)
wordpress-trap
Web App Attack
๐บ๐ธ
myagent.site
2024-11-01 19:07:32
(1 year ago)
Blocked user enumeration attempt
Hacking
๐ง๐ช
sid3windr
2024-11-01 18:27:00
(1 year ago)
GET /wp-login.php (Tarpitted for , wasted 0B)
Web App Attack
๐ฆ๐บ
weblite
2024-11-01 09:59:26
(1 year ago)
WP_XMLRPC_ABUSE
Brute-Force
Web App Attack
๐ง๐ช
taivas.nl
2024-11-01 09:32:12
(1 year ago)
Wordpress_xmlrpc_attack
Bad Web Bot
Anonymous
2024-11-01 07:15:51
(1 year ago)
apache-wordpress-login
Brute-Force
Web App Attack
๐ฌ๐ง
Swiptly
2024-11-01 07:11:14
(1 year ago)
WordPress xmlrpc spam or enumeration
...
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2024-11-01 05:38:56
(1 year ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack