Anonymous
2025-12-03 02:09:10
(6 months ago)
wordpress-trap
Web App Attack
π«π·
dynamix
2025-12-03 00:18:13
(6 months ago)
Multiple WAF Violations
Web App Attack
π«π·
dynamix
2025-11-29 11:04:53
(6 months ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-11 08:10:14
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.92.229.189 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.92.229.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 11 03:10:04.697707 2025] [security2:error] [pid 6910:tid 6910] [client 45.92.229.189:55101] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "debbieweibler.com"] [uri "/.env"] [unique_id "aRLvXAULA-ropC6D5vjcXAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-10 16:10:28
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.92.229.189 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.92.229.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 10 11:10:19.715279 2025] [security2:error] [pid 4191:tid 4191] [client 45.92.229.189:59591] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hudready.com"] [uri "/.env"] [unique_id "aRIOa23-NTykzwGdsFQ0SwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
dtorrer
2025-11-09 23:15:01
(6 months ago)
General vulnerability scan.
Port Scan
π©πͺ
conseilgouz
2025-11-09 13:24:51
(6 months ago)
ave-7 : Trying access unauthorized files/dir=>/wp-content/
Hacking
πΊπΈ
TPI-Abuse
2025-11-09 10:12:24
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 45.92.229.189 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.92.229.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 09 05:12:17.382948 2025] [security2:error] [pid 26219:tid 26242] [client 45.92.229.189:40977] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.sloveniaflyfishing.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.sloveniaflyfishing.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aRBpAbhYsd5zz5hSB4GM_gAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-09 06:12:57
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 45.92.229.189 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.92.229.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 09 01:12:52.554527 2025] [security2:error] [pid 18457:tid 18457] [client 45.92.229.189:40793] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.peacecampus.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.peacecampus.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "aRAw5MYAU8i9gzovo0hYjAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Vegascosmetics
2025-11-05 22:52:19
(6 months ago)
Kingcopy(AI-IDS):IP is Probing for Wordpress vulnerabilities WTF:Banned
Hacking
Bad Web Bot
Web App Attack
π«π·
dynamix
2025-11-05 00:04:51
(6 months ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
OceanTreasure
2025-10-03 04:55:07
(8 months ago)
tcp/443; Probing for exposed /.env dotfiles: "GET /.env" @ 2025-10-03T04:45:15Z [azure]
Web App Attack
π³π±
exxos
2025-09-24 15:03:01
(8 months ago)
Attacks with Bad user agents
Hacking
π§πͺ
cmbplf
2025-09-19 03:10:09
(8 months ago)
1.529 POST requests with url.path */wp-login.php
Brute-Force
Bad Web Bot
πΊπΈ
Jason Howell
2025-09-19 02:32:34
(8 months ago)
45.92.229.189 - - [18/Sep/2025:21:18:35 -0500] "POST //xmlrpc.php HTTP/1.1" 200 3017 "-" "Mozilla/5. ...
show more
45.92.229.189 - - [18/Sep/2025:21:18:35 -0500] "POST //xmlrpc.php HTTP/1.1" 200 3017 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 OPR/120.0.0.0"
45.92.229.189 - - [18/Sep/2025:21:32:32 -0500] "POST /wp-login.php HTTP/1.1" 200 6290 "https://www.11thstreetprecinct.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:136.0) Gecko/20100101 Firefox/138.0"
45.92.229.189 - - [18/Sep/2025:21:32:32 -0500] "POST /wp-login.php HTTP/1.1" 200 3892 "https://www.11thstreetprecinct.com/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36 Edg/139.0.3124.85"
45.92.229.189 - - [18/Sep/2025:21:32:33 -0500] "POST /wp-login.php HTTP/1.1" 200 3892 "https://www.11thstreetprecinct.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 OPR/120.0.0.0"
45.92.229.189 - - [18/Sep/
...
show less
Web App Attack