π¨π
filou812
2025-08-09 22:00:44
(1 year ago)
urls tried are "/backup.zip", "/Archive.zip", "/g6i.zip", "/g6i.ch.zip"
Web App Attack
π©πͺ
LRob
2025-04-10 11:45:15
(1 year ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-12-25 02:58:07
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.40.159.171 (p3plwpweb001.prod.phx3.secureser ...
show more
(mod_security) mod_security (id:225170) triggered by 45.40.159.171 (p3plwpweb001.prod.phx3.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 24 21:58:00.088547 2024] [security2:error] [pid 15222:tid 15222] [client 45.40.159.171:56062] [client 45.40.159.171] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||skinnywheels.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "skinnywheels.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z2t0uBqTR9KqJYTOYKU5xAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-12-24 20:51:46
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.40.159.171 (p3plwpweb001.prod.phx3.secureser ...
show more
(mod_security) mod_security (id:225170) triggered by 45.40.159.171 (p3plwpweb001.prod.phx3.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 24 15:51:40.360401 2024] [security2:error] [pid 3364690:tid 3364690] [client 45.40.159.171:55054] [client 45.40.159.171] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||robertgregorybrowne.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "robertgregorybrowne.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z2se3LVqd4EU9K1aEx9bygAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-12-24 19:03:15
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.40.159.171 (p3plwpweb001.prod.phx3.secureser ...
show more
(mod_security) mod_security (id:225170) triggered by 45.40.159.171 (p3plwpweb001.prod.phx3.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 24 14:03:10.370587 2024] [security2:error] [pid 3046480:tid 3046480] [client 45.40.159.171:57738] [client 45.40.159.171] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||numbulary.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "numbulary.org"] [uri "/wp-json/wp/v2/users"] [unique_id "Z2sFbuxpGVvryiL3KFYBJAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-12-24 09:03:06
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.40.159.171 (p3plwpweb001.prod.phx3.secureser ...
show more
(mod_security) mod_security (id:225170) triggered by 45.40.159.171 (p3plwpweb001.prod.phx3.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 24 04:03:01.165625 2024] [security2:error] [pid 18916:tid 18916] [client 45.40.159.171:53902] [client 45.40.159.171] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||perfectpartnersdogtraining.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "perfectpartnersdogtraining.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z2p4xeBr7J58ZvjGiPpDxQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-10-31 06:41:05
(1 year ago)
Brute Force Login Attempts
Hacking
Brute-Force
π³π±
maxxsense
2024-10-22 18:16:14
(1 year ago)
(wordpress) Failed wordpress login from 45.40.159.171 (US/United States/p3plwpweb001.prod.phx3.secur ...
show more
(wordpress) Failed wordpress login from 45.40.159.171 (US/United States/p3plwpweb001.prod.phx3.secureserver.net)
show less
Brute-Force
π©π°
wnbhosting.dk
2024-10-22 17:20:59
(1 year ago)
WP xmlrpc [2024-10-22T19:20:59+02:00]
Hacking
Web App Attack
Anonymous
2024-10-22 14:36:36
(1 year ago)
xmlrpc attack blocked attempt from fail2ban
...
Web App Attack
π©π°
wnbhosting.dk
2024-10-20 20:17:09
(1 year ago)
WP xmlrpc [2024-10-20T22:17:09+02:00]
Hacking
Web App Attack
π©π°
wnbhosting.dk
2024-10-20 12:21:53
(1 year ago)
WP xmlrpc [2024-10-20T14:21:53+02:00]
Hacking
Web App Attack
π©π°
wnbhosting.dk
2024-10-20 00:08:31
(1 year ago)
WP xmlrpc [2024-10-20T02:08:31+02:00]
Hacking
Web App Attack
π¬π§
Swiptly
2024-10-19 20:22:19
(1 year ago)
WordPress xmlrpc spam or enumeration
...
Web Spam
Bad Web Bot
Web App Attack
π©π°
wnbhosting.dk
2024-10-19 08:03:28
(1 year ago)
WP xmlrpc [2024-10-19T10:03:28+02:00]
Hacking
Web App Attack