|
π³π±
BlueWire Hosting
|
|
Probing for application vulnerabilities
|
Brute-Force
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 45.77.240.26 (45.77.240.26.vultrusercontent.com ...
show more
(mod_security) mod_security (id:225170) triggered by 45.77.240.26 (45.77.240.26.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 15 04:08:25.587584 2025] [security2:error] [pid 3498938:tid 3498938] [client 45.77.240.26:51611] [client 45.77.240.26] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.prostar.industries|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.prostar.industries"] [uri "/wp-json/wp/v2/users/"] [unique_id "aCWg-b-q9_KbCuBD1CrmSgAAAAg"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
π«π·
GEDAL
|
|
$f2bV_matches
|
Brute-Force
SSH
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 45.77.240.26 (45.77.240.26.vultrusercontent.com ...
show more
(mod_security) mod_security (id:225170) triggered by 45.77.240.26 (45.77.240.26.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 15 02:58:21.196480 2025] [security2:error] [pid 1240806:tid 1240823] [client 45.77.240.26:55595] [client 45.77.240.26] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rockabyecotons.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rockabyecotons.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aCWQjR7KERdyqvSFAy9JAgAAAQ8"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
Charlesiv
|
|
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 20473 (AS-VULTR)
Protoco ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 20473 (AS-VULTR)
Protocol: HTTP/1.1 (GET method)
Endpoint: /web/wp-includes/wlwmanifest.xml
Timestamp: 2025-05-15T05:22:16Z
Ray ID: 94003252deedfe05
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
show less
|
Bad Web Bot
|
|
|
π«π·
COMAITE
|
|
Multiple web server 400 error codes from same source ip 45.77.240.26.
|
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 45.77.240.26 (45.77.240.26.vultrusercontent.com ...
show more
(mod_security) mod_security (id:225170) triggered by 45.77.240.26 (45.77.240.26.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 15 01:46:15.715204 2025] [security2:error] [pid 737439:tid 737439] [client 45.77.240.26:52762] [client 45.77.240.26] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gamerah.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gamerah.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "aCV_p8Y4BWirPpLJASvL6gAAAAI"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
π―π΅
Valhalla
|
|
/xmlrpc.php?rsd
|
Hacking
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 45.77.240.26 (45.77.240.26.vultrusercontent.com ...
show more
(mod_security) mod_security (id:225170) triggered by 45.77.240.26 (45.77.240.26.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 15 01:07:15.131878 2025] [security2:error] [pid 3846081:tid 3846081] [client 45.77.240.26:56601] [client 45.77.240.26] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||karenbernsteinlaw.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "karenbernsteinlaw.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "aCV2gwCk1Ofz7_-O6YMWsAAAAAg"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
ipblock.com
|
|
IPBlock protected site ID [2815-wdn][s=02].
Exploit request, vulnerability scanner.
|
Hacking
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
masterguru
|
|
WordPress: User enumeration. Pattern match "(author\\\\= (88030-147)
|
Hacking
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 45.77.240.26 (45.77.240.26.vultrusercontent.com ...
show more
(mod_security) mod_security (id:225170) triggered by 45.77.240.26 (45.77.240.26.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 15 00:40:15.464132 2025] [security2:error] [pid 2542170:tid 2542170] [client 45.77.240.26:49360] [client 45.77.240.26] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.elpaco.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.elpaco.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "aCVwLyA2Hb-afP532LIzogAAACA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 45.77.240.26 (45.77.240.26.vultrusercontent.com ...
show more
(mod_security) mod_security (id:225170) triggered by 45.77.240.26 (45.77.240.26.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 15 00:09:25.361753 2025] [security2:error] [pid 1871078:tid 1871078] [client 45.77.240.26:63155] [client 45.77.240.26] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.naturephotographyadventures.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.naturephotographyadventures.com"] [uri "/blog/wp-json/wp/v2/users/"] [unique_id "aCVo9btD64Ne6fBr6fQ56QAAABM"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
π«π·
ecodehost.com
|
|
Domain : 3blazertarama.net
Rule : env
2025-05-15 03:28:23 10.100.1.20 GET /wp-includes/wlwmanifest.x ...
show more
Domain : 3blazertarama.net
Rule : env
2025-05-15 03:28:23 10.100.1.20 GET /wp-includes/wlwmanifest.xml - 443 - 45.77.240.26 HTTP/1.1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 - 3blazertarama.net 404 0 0 1747 418 2962 - -
show less
|
Hacking
SQL Injection
|
|
|
πΊπΈ
bigwavedave
|
|
Wordpress Attack
|
Web App Attack
|
|