πΊπΈ
TPI-Abuse
2024-07-04 16:06:37
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 45.40.166.113 (113.166.40.45.host.secureserver. ...
show more
(mod_security) mod_security (id:225170) triggered by 45.40.166.113 (113.166.40.45.host.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 04 12:06:33.880252 2024] [security2:error] [pid 8080] [client 45.40.166.113:56000] [client 45.40.166.113] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.fiasdesigns.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.fiasdesigns.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZobIicric5W-l9kA-EfAkQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-07-04 14:47:09
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 45.40.166.113 (113.166.40.45.host.secureserver. ...
show more
(mod_security) mod_security (id:225170) triggered by 45.40.166.113 (113.166.40.45.host.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 04 10:47:05.321348 2024] [security2:error] [pid 7248] [client 45.40.166.113:60933] [client 45.40.166.113] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.puckerbackbikini.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.puckerbackbikini.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Zoa16ViGWeiHKKrgPNJsqgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-07-04 14:28:41
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 45.40.166.113 (113.166.40.45.host.secureserver. ...
show more
(mod_security) mod_security (id:225170) triggered by 45.40.166.113 (113.166.40.45.host.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 04 10:28:36.009630 2024] [security2:error] [pid 28888] [client 45.40.166.113:58251] [client 45.40.166.113] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||williamfitzsimmons.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "williamfitzsimmons.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZoaxlMrgFExGa8P9wo4EJgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-07-04 13:15:05
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 45.40.166.113 (113.166.40.45.host.secureserver. ...
show more
(mod_security) mod_security (id:225170) triggered by 45.40.166.113 (113.166.40.45.host.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 04 09:14:57.856575 2024] [security2:error] [pid 24154] [client 45.40.166.113:54768] [client 45.40.166.113] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||realdoctorstories.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "realdoctorstories.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZoagUbaPP5VI3esXjOJFcwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-07-04 12:59:38
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 45.40.166.113 (113.166.40.45.host.secureserver. ...
show more
(mod_security) mod_security (id:225170) triggered by 45.40.166.113 (113.166.40.45.host.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 04 08:59:31.721568 2024] [security2:error] [pid 27052:tid 47387074680576] [client 45.40.166.113:49952] [client 45.40.166.113] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sandiegosamband.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sandiegosamband.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Zoacs4-FgMR-aOyK2DI1bgAAAVY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-07-04 11:36:33
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 45.40.166.113 (113.166.40.45.host.secureserver. ...
show more
(mod_security) mod_security (id:225170) triggered by 45.40.166.113 (113.166.40.45.host.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 04 07:36:30.449569 2024] [security2:error] [pid 1894] [client 45.40.166.113:53923] [client 45.40.166.113] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.321q.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.321q.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZoaJPj8wh8gpW2-rmMoR8wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-07-04 06:27:58
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
π²πΎ
Rizzy
2024-07-04 05:35:22
(2 years ago)
Multiple WAF Violations
Brute-Force
Web App Attack
π¦πΊ
MAGIC
2024-07-04 01:00:29
(2 years ago)
VM5 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
π©πͺ
bsoft.de
2024-07-02 15:32:07
(2 years ago)
45.40.166.113 - - [02/Jul/2024:10:58:50 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Mozilla/5.0 ...
show more
45.40.166.113 - - [02/Jul/2024:10:58:50 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36"
45.40.166.113 - - [02/Jul/2024:17:31:43 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.106 Safari/537.36"
45.40.166.113 - - [02/Jul/2024:17:32:05 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36"
show less
Web App Attack
Anonymous
2024-07-02 05:27:29
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
π¬π§
Swiptly
2024-06-30 21:26:05
(2 years ago)
WordPress xmlrpc spam or enumeration
...
Web Spam
Bad Web Bot
Web App Attack
Anonymous
2024-06-30 15:25:30
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
π©πͺ
eminovic.ba
2024-06-30 02:23:51
(2 years ago)
Wordpress attack
...
Hacking
Brute-Force
Web App Attack
π«π·
Kenshin869
2024-06-27 07:56:05
(2 years ago)
Wordpress unauthorized access attempt
Brute-Force