๐ฌ๐ง
rakkor
2025-03-23 02:56:38
(1 year ago)
2025/03/23 02:53:14 [error] 15629#15629: *3316948 open() "/var/services/web/wp-content/plugins/wp-jo ...
show more
2025/03/23 02:53:14 [error] 15629#15629: *3316948 open() "/var/services/web/wp-content/plugins/wp-job-portal/readme.txt" failed (2: No such file or directory), client: 45.131.195.74, server: , request: "GET /wp-content/plugins/wp-job-portal/readme.txt HTTP/1.1", host: "rakkor.uk"
2025/03/23 02:56:37 [error] 15629#15629: *3317076 open() "/var/services/web/wp-content/plugins/miniorange-2-factor-authentication/readme.txt" failed (2: No such file or directory), client: 45.131.195.74, server: , request: "GET /wp-content/plugins/miniorange-2-factor-authentication/readme.txt HTTP/1.1", host: "rakkor.uk"
...
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-22 12:30:34
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 45.131.195.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.195.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 22 08:30:29.180899 2025] [security2:error] [pid 25327:tid 25327] [client 45.131.195.74:30413] [client 45.131.195.74] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "inquisitivequincie.com"] [uri "/wp-content/plugins/cherry-plugin/admin/import-export/download-content.php"] [unique_id "Z96tZbCwnp0-fyXsDS45IAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2025-03-22 10:05:15
(1 year ago)
Scanning/Probing (28)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-22 05:11:37
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 45.131.195.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.195.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 22 01:11:34.126643 2025] [security2:error] [pid 3463:tid 3463] [client 45.131.195.74:6007] [client 45.131.195.74] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bikinitweets.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "Z95GhnFCzvhMxkI1ZUNG0gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
octageeks.com
2025-03-22 04:07:04
(1 year ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
mnsf
2025-03-21 09:06:06
(1 year ago)
Scanning/Probing (14)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-18 23:02:32
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 45.131.195.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.195.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 18 19:02:25.098715 2025] [security2:error] [pid 4873:tid 4873] [client 45.131.195.74:1521] [client 45.131.195.74] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ironsightsarmory.com"] [uri "/wp-content/plugins/mapsvg/gm_download.php"] [unique_id "Z9n7gYG2pSxlqu0FOcLXuAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-18 20:18:45
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 45.131.195.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.195.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 18 16:18:40.460720 2025] [security2:error] [pid 21123:tid 21123] [client 45.131.195.74:5903] [client 45.131.195.74] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "save1vet.org"] [uri "/wp-content/plugins/post-pdf-export/dompdf/dompdf.php"] [unique_id "Z9nVIGq0j9j4mKzHXvWJjAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Mendip_Defender
2025-03-18 14:49:09
(1 year ago)
45.131.195.74 - - [18/Mar/2025:14:49:03 +0000] "GET /wp-content/themes/directorybox/style.css HTTP/1 ...
show more
45.131.195.74 - - [18/Mar/2025:14:49:03 +0000] "GET /wp-content/themes/directorybox/style.css HTTP/1.0" 404 31676 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2 Mobile/15E148 Safari/604.1"
45.131.195.74 - - [18/Mar/2025:14:49:04 +0000] "GET /wp-content/plugins/indeed-wp-superbackup/admin/assets/css/style.css HTTP/1.0" 404 31676 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2 Mobile/15E148 Safari/604.1"
...
show less
Hacking
Web App Attack
๐บ๐ธ
mnsf
2025-03-18 11:05:45
(1 year ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐บ๐ธ
antlac1
2025-03-17 07:10:52
(1 year ago)
crowdsecurity/http-wordpress-scan
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2025-03-16 18:05:18
(1 year ago)
Scanning/Probing (15)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2025-03-15 17:05:11
(1 year ago)
Scanning/Probing (18)
Brute-Force
Web App Attack
๐ฌ๐ง
Mendip_Defender
2025-03-15 15:29:22
(1 year ago)
45.131.195.74 - - [15/Mar/2025:15:29:17 +0000] "GET /wp-content/plugins/instawp-connect/readme.txt H ...
show more
45.131.195.74 - - [15/Mar/2025:15:29:17 +0000] "GET /wp-content/plugins/instawp-connect/readme.txt HTTP/1.1" 403 146 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2 Mobile/15E148 Safari/604.1"
45.131.195.74 - - [15/Mar/2025:15:29:18 +0000] "GET /wp-content/plugins/instawp-connect/readme.txt HTTP/1.1" 403 146 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2 Mobile/15E148 Safari/604.1"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-15 03:33:33
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 45.131.195.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.195.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 14 23:33:26.081435 2025] [security2:error] [pid 16329:tid 16329] [client 45.131.195.74:38873] [client 45.131.195.74] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "acoastcleaning.com"] [uri "/wp-content/plugins/usc-e-shop/functions/content-log.php"] [unique_id "Z9T1Bm6n8ix_P2-s2uZ79wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack