๐บ๐ธ
TPI-Abuse
2024-02-01 22:06:02
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 45.92.229.189 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.92.229.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 01 17:05:56.935897 2024] [security2:error] [pid 17689] [client 45.92.229.189:38473] [client 45.92.229.189] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.faithmonger.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.faithmonger.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZbwVxDpTdtm5lLLV86Q2-AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-01 20:52:09
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 45.92.229.189 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.92.229.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 01 15:51:58.163130 2024] [security2:error] [pid 14217] [client 45.92.229.189:28245] [client 45.92.229.189] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lifestyledreamvacation.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lifestyledreamvacation.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZbwEbmPGizzPG8RXEumYegAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-01 20:28:21
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 45.92.229.189 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.92.229.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 01 15:28:16.365897 2024] [security2:error] [pid 28638] [client 45.92.229.189:37017] [client 45.92.229.189] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.eliteelectricalservices.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.eliteelectricalservices.us"] [uri "/wp-json/wp/v2/users/"] [unique_id "Zbv-4ICnHxUbrR0i0xGVfgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-01 19:56:34
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 45.92.229.189 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.92.229.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 01 14:56:31.221994 2024] [security2:error] [pid 19126] [client 45.92.229.189:30967] [client 45.92.229.189] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||utd.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "utd.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "Zbv3b8jLLdg7GDWaoW-2fwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-01 16:42:15
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 45.92.229.189 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.92.229.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 01 11:42:01.527557 2024] [security2:error] [pid 27899] [client 45.92.229.189:54407] [client 45.92.229.189] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.fgrotary.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.fgrotary.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZbvJ2TvRWSaK53dpaOviCgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2024-02-01 08:56:15
(2 years ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฉ๐ช
v1nc
2024-01-18 03:19:39
(2 years ago)
45.92.229.189 - - [18/Jan/2024:03:19:38 +0000] "GET //wp-l0gin.php HTTP/1.1" 404 118 "http://filnk.o ...
show more
45.92.229.189 - - [18/Jan/2024:03:19:38 +0000] "GET //wp-l0gin.php HTTP/1.1" 404 118 "http://filnk.org//wp-l0gin.php" "Go-http-client/1.1"
...
show less
Hacking
๐บ๐ธ
physke
2024-01-17 18:19:59
(2 years ago)
REQUESTED PAGE: //wso.php
Web App Attack
๐ต๐ฑ
jo
2024-01-15 23:24:56
(2 years ago)
[Mon Jan 15 23:24:54.597577 2024] [php:error] [pid 3343217] [client 45.92.229.189:37369] script '/va ...
show more
[Mon Jan 15 23:24:54.597577 2024] [php:error] [pid 3343217] [client 45.92.229.189:37369] script '/var/www/html/doc.php' not found or unable to stat
[Mon Jan 15 23:24:54.873446 2024] [php:error] [pid 3343217] [client 45.92.229.189:37369] script '/var/www/html/shell.php' not found or unable to stat
[Mon Jan 15 23:24:55.150454 2024] [php:error] [pid 3343217] [client 45.92.229.189:37369] script '/var/www/html/fm.php' not found or unable to stat
[Mon Jan 15 23:24:55.701489 2024] [php:error] [pid 3343217] [client 45.92.229.189:37369] script '/var/www/html/repeater.php' not found or unable to stat
[Mon Jan 15 23:24:55.977806 2024] [php:error] [pid 3343217] [client 45.92.229.189:37369] script '/var/www/html/wso.php' not found or unable to stat
...
show less
Port Scan
Hacking
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
๐บ๐ธ
cusezar.com
2024-01-15 03:59:29
(2 years ago)
45.92.229.189 //403.php
Brute-Force
๐ฉ๐ช
FeG Deutschland
2024-01-14 20:04:03
(2 years ago)
Looking for CMS/PHP/SQL vulnerablilities - 13
Exploited Host
Web App Attack
๐บ๐ธ
Secure Gatewayยฎ๏ธ
2024-01-12 22:00:38
(2 years ago)
Report By Secure Gateway Security Team: Unauthorized Connection Attempt
Hacking
๐บ๐ธ
ALSCOยฎ๏ธ
2024-01-12 22:00:38
(2 years ago)
Report By ALSCO Security Team: Unauthorized Connection Attempt
SQL Injection
Anonymous
2024-01-12 00:13:36
(2 years ago)
[Fri Jan 12 01:13:34.596267 2024] [authz_core:error] [pid 2049] [client 45.92.229.189:8445] AH01630: ...
show more
[Fri Jan 12 01:13:34.596267 2024] [authz_core:error] [pid 2049] [client 45.92.229.189:8445] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri Jan 12 01:13:34.801062 2024] [authz_core:error] [pid 2049] [client 45.92.229.189:8445] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri Jan 12 01:13:35.017247 2024] [authz_core:error] [pid 2049] [client 45.92.229.189:8445] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐ซ๐ท
MediaXtend
2024-01-11 12:34:23
(2 years ago)
45.92.229.189 - - [11/Jan/2024:13:34:19 +0100] "GET /wp-admin/wso112233.php HTTP/1.1" 404 4264 "http ...
show more
45.92.229.189 - - [11/Jan/2024:13:34:19 +0100] "GET /wp-admin/wso112233.php HTTP/1.1" 404 4264 "http://[hidden]//wp-admin/wso112233.php" "Go-http-client/1.1"
show less
Web App Attack