|
๐บ๐ธ
threatintelligence_bvc
|
|
|
Brute-Force
|
|
|
Anonymous
|
|
botnet
|
DDoS Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 45.80.187.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 45.80.187.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 22 23:40:42.958451 2025] [security2:error] [pid 1017415:tid 1017415] [client 45.80.187.29:17500] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||campnecon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "campnecon.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aFjMur40zQbRcRdKQGu8lgAAAAA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 45.80.187.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 45.80.187.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 22 23:24:15.991318 2025] [security2:error] [pid 3450507:tid 3450507] [client 45.80.187.29:31492] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||buanamegah.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "buanamegah.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aFjI320acndOwoqHKXQm0AAAABA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
|
Brute-Force
SSH
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 45.80.187.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 45.80.187.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 22 23:06:49.699136 2025] [security2:error] [pid 65418:tid 65418] [client 45.80.187.29:47750] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||meganmurph.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "meganmurph.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aFjEyZb1AqI9pejA20YyEwAAAAg"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
|
Brute-Force
SSH
|
|
|
Anonymous
|
|
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
|
Brute-Force
SSH
|
|
|
๐ต๐ฑ
sefinek.net
|
|
Triggered Cloudflare WAF (firewallCustom) from VN.
Action taken: MANAGED_CHALLENGE
ASN: 136787 (PACK ...
show more
Triggered Cloudflare WAF (firewallCustom) from VN.
Action taken: MANAGED_CHALLENGE
ASN: 136787 (PACKETHUBSA-AS-AP PacketHub S.A.)
Protocol: HTTP/1.1 (GET method)
Zone: sefinek.net
Endpoint: /
Timestamp: 2024-12-03T23:58:48Z
Ray ID: 8ec781c089520440
UA: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Vivaldi/5.3.2679.68
Report generated by Cloudflare-WAF-To-AbuseIPDB:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
|
Bad Web Bot
|
|
|
๐ต๐ฑ
sefinek.net
|
|
Triggered Cloudflare WAF (firewallCustom) from VN.
Action taken: MANAGED_CHALLENGE
ASN: 136787 (PACK ...
show more
Triggered Cloudflare WAF (firewallCustom) from VN.
Action taken: MANAGED_CHALLENGE
ASN: 136787 (PACKETHUBSA-AS-AP PacketHub S.A.)
Protocol: HTTP/1.1 (GET method)
Zone: sefinek.net
Endpoint: /
Timestamp: 2024-12-03T18:13:34Z
Ray ID: 8ec588090b105158
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Edg/114.0.1264.71
Report generated by Cloudflare-WAF-To-AbuseIPDB:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
|
Bad Web Bot
|
|
|
๐ป๐ณ
Xuan Can
|
|
(mod_security) mod_security (id:77350314) triggered by 45.80.187.29 (-): 1 in the last 3600 secs; Po ...
show more
(mod_security) mod_security (id:77350314) triggered by 45.80.187.29 (-): 1 in the last 3600 secs; Ports: 80,443; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 21 15:00:17.944211 2024] [security2:error] [pid 27940:tid 27974] [client 45.80.187.29:48928] [client 45.80.187.29] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/download" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/imunify360-full-apache/001_i360_basic.conf"] [line "8"] [id "77350314"] [msg "IM360 WAF: Path traversal attack||User:kbpavn||Path:/vpn/user/download/client||Arg:ARGS:ostype||Match:../../../../../../../../../etc/passwd||T:APACHE||"] [severity "CRITICAL"] [tag "service_im360"] [hostname "kb.pavietnam.vn"] [uri "/vpn/user/download/client"] [unique_id "ZsWekQuTkTPBl0owfo4BJwAAAAc"]
show less
|
Brute-Force
SSH
|
|