๐บ๐ธ
TPI-Abuse
2023-12-04 02:56:36
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 47.74.26.120 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 47.74.26.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 03 21:56:31.261202 2023] [security2:error] [pid 9370] [client 47.74.26.120:54678] [client 47.74.26.120] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.lasertherapyoc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.lasertherapyoc.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZW0_37Lujkr16e4dNSNXnAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-27 02:39:33
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 47.74.26.120 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 47.74.26.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 26 21:39:28.275814 2023] [security2:error] [pid 3699] [client 47.74.26.120:64467] [client 47.74.26.120] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thenursingsite.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thenursingsite.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZWQBYMMtMPUasPJx6wZs1wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2023-11-27 02:07:50
(2 years ago)
10 attempts against mh-misc-ban on onion
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-26 21:10:46
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 47.74.26.120 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 47.74.26.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 26 16:10:43.976436 2023] [security2:error] [pid 308531] [client 47.74.26.120:52617] [client 47.74.26.120] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.platinummedicalevaluations.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.platinummedicalevaluations.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZWO0U-ZL6yQ5UOw5kysU6QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2023-11-25 20:03:10
(2 years ago)
47.74.26.120 - - [25/Nov/2023:22:03:09 +0200] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 196 "- ...
show more
47.74.26.120 - - [25/Nov/2023:22:03:09 +0200] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
...
show less
Web App Attack
๐ณ๐ฑ
pa4080
2023-11-25 05:51:29
(2 years ago)
Detected by ModSecurity. Request URI: //xmlrpc.php?rsd
Web App Attack
๐ณ๐ฑ
Savvii
2023-11-23 08:48:53
(2 years ago)
11 attempts against mh_ha-misc-ban on twig
Brute-Force
Web App Attack
๐บ๐ธ
mawan
2023-11-23 08:42:19
(2 years ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ณ๐ฑ
Savvii
2023-11-23 07:18:08
(2 years ago)
11 attempts against mh-misc-ban on twig
Web App Attack
๐ณ๐ฑ
Savvii
2023-11-23 06:02:29
(2 years ago)
10 attempts against mh_ha-misc-ban on twig
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2023-11-23 05:32:17
(2 years ago)
10 attempts against mh-misc-ban on twig
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2023-11-22 04:28:57
(2 years ago)
47.74.26.120 - - [22/Nov/2023:06:28:57 +0200] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 196 "- ...
show more
47.74.26.120 - - [22/Nov/2023:06:28:57 +0200] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
...
show less
Web App Attack
๐ณ๐ฑ
Savvii
2023-11-22 03:41:20
(2 years ago)
10 attempts against mh-misc-ban on chive
Web App Attack
Anonymous
2023-11-21 19:23:32
(2 years ago)
Bot / scanning and/or hacking attempts: POST //xmlrpc.php HTTP/1.1, GET //feed/ HTTP/1.1, GET //?aut ...
show more
Bot / scanning and/or hacking attempts: POST //xmlrpc.php HTTP/1.1, GET //feed/ HTTP/1.1, GET //?author=2 HTTP/1.1, GET //?author=1 HTTP/1.1, done, streams: 0/1/1/0/0 (open/recv/resp/push/rst)
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-21 19:19:32
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 47.74.26.120 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 47.74.26.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 21 14:19:29.009740 2023] [security2:error] [pid 1164] [client 47.74.26.120:55071] [client 47.74.26.120] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||srtalent.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "srtalent.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZV0CwW5Qff675HecMv-EyAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack