๐บ๐ธ
TPI-Abuse
2024-03-05 22:06:52
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 45.252.249.224 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.252.249.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 05 17:06:47.374245 2024] [security2:error] [pid 9400] [client 45.252.249.224:50646] [client 45.252.249.224] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mail.zabdisrl.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mail.zabdisrl.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZeeXdz5lTQPWoq0vkDiz8wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-05 20:33:21
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 45.252.249.224 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.252.249.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 05 15:33:15.506714 2024] [security2:error] [pid 686178:tid 47448767981312] [client 45.252.249.224:50618] [client 45.252.249.224] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||talenttourhrservices.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "talenttourhrservices.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZeeBi3OrCq9T6_v6quwRcgAAAIQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-05 17:40:55
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 45.252.249.224 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.252.249.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 05 12:40:51.285527 2024] [security2:error] [pid 3265] [client 45.252.249.224:45662] [client 45.252.249.224] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||soudertonbigred.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "soudertonbigred.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ZedZIwzhLWde3hD9gBTguwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-05 17:01:13
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 45.252.249.224 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.252.249.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 05 12:01:09.797686 2024] [security2:error] [pid 28854] [client 45.252.249.224:49882] [client 45.252.249.224] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||balmedia.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "balmedia.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZedP1UhBzwfEPjLuH0Xw_wAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-05 14:49:23
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 45.252.249.224 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.252.249.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 05 09:49:17.916929 2024] [security2:error] [pid 370] [client 45.252.249.224:58834] [client 45.252.249.224] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mail.kunzteam.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mail.kunzteam.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Zecw7Y5B1qbXJofy1OsoUwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-04 11:08:59
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 45.252.249.224 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.252.249.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 04 06:08:53.307444 2024] [security2:error] [pid 4963] [client 45.252.249.224:38152] [client 45.252.249.224] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.starcrestsales.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.starcrestsales.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZeWrxWIb47vK_lj_XEeNNQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-04 06:30:27
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 45.252.249.224 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.252.249.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 04 01:30:23.613336 2024] [security2:error] [pid 10797] [client 45.252.249.224:34620] [client 45.252.249.224] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||adoniah.co|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "adoniah.co"] [uri "/wp-json/wp/v2/users"] [unique_id "ZeVqf9MQsFb9mMHomiI_OgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
weblite
2024-03-03 13:04:39
(2 years ago)
WP_AUTHOR_SCANNING
Web App Attack
๐บ๐ธ
mnsf
2024-03-03 06:04:04
(2 years ago)
Too many Status 40X (15)
Scanning/Probing (17)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-29 19:26:07
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 45.252.249.224 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.252.249.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 29 14:26:02.270693 2024] [security2:error] [pid 32612] [client 45.252.249.224:49950] [client 45.252.249.224] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.cubbylure.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.cubbylure.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZeDaSj5sE7ySaGsI76YBRwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
taivas.nl
2024-02-28 17:32:14
(2 years ago)
Wordpress_xmlrpc_attack
Bad Web Bot
๐ฉ๐ฐ
wnbhosting.dk
2024-02-27 13:31:38
(2 years ago)
WP xmlrpc [2024-02-27T14:31:38+01:00]
Hacking
Web App Attack
๐ฎ๐ช
Jim Keir
2024-02-26 10:44:32
(2 years ago)
2024-02-26 10:44:32 45.252.249.224 File scanning, blocking 45.252.249.224 for 5 minutes
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-02-25 15:12:38
(2 years ago)
Unauthorized login attempts [ wordpress-xmlrpc]
Brute-Force
Web App Attack
๐ฉ๐ฐ
wnbhosting.dk
2024-02-25 04:53:43
(2 years ago)
WP xmlrpc [2024-02-25T05:53:43+01:00]
Hacking
Web App Attack