๐บ๐ธ
octageeks.com
2025-11-04 05:06:10
(8 months ago)
Wordpress malicious attack:[octascan]
Web App Attack
Anonymous
2025-11-04 01:41:46
(8 months ago)
[Tue Nov 04 02:41:44.903450 2025] [authz_core:error] [pid 2107563:tid 2107563] [client 5.188.97.19:5 ...
show more
[Tue Nov 04 02:41:44.903450 2025] [authz_core:error] [pid 2107563:tid 2107563] [client 5.188.97.19:58950] AH01630: client denied by server configuration: /home/berlinersc-badminton/public_html/wso.php
[Tue Nov 04 02:41:44.904943 2025] [authz_core:error] [pid 2112090:tid 2112090] [client 5.188.97.19:58964] AH01630: client denied by server configuration: /home/berlinersc-badminton/public_html/shell.php
[Tue Nov 04 02:41:45.125870 2025] [authz_core:error] [pid 2107565:tid 2107565] [client 5.188.97.19:58968] AH01630: client denied by server configuration: /home/berlinersc-badminton/public_html/xleet.php
[Tue Nov 04 02:41:45.129648 2025] [authz_core:error] [pid 2102912:tid 2102912] [client 5.188.97.19:58974] AH01630: client denied by server configuration: /home/berlinersc-badminton/public_html/xleet-shell.php
[Tue Nov 04 02:41:45.292733 2025] [authz_core:error] [pid 2102882:tid 2102882] [client 5.188.97.19:58982] AH01630: client denied by server configuration: /home/berlinersc-badminton/pub
...
show less
Brute-Force
Anonymous
2025-11-03 08:43:19
(8 months ago)
fail2ban apache-modsecurity web [msg "php scripts are not allowed here"] [uri "/tiny.php"]
Web App Attack
๐ฉ๐ช
bescared
2025-11-01 23:55:14
(9 months ago)
F2B - Malicious activity detected. URL Probing.
Hacking
Web App Attack
๐ณ๐ฑ
i-turnradio.nl
2025-11-01 15:02:35
(9 months ago)
2025-11-01 @ 16:02:35 (CET) ~ Blocked for trying to access: /wp-content/plugins/king-addons/freemius ...
show more
2025-11-01 @ 16:02:35 (CET) ~ Blocked for trying to access: /wp-content/plugins/king-addons/freemius/assets/css/customizer.css
show less
Web App Attack
๐บ๐ธ
ne1for23
2025-10-30 06:06:32
(9 months ago)
Probing for CVE-2006-5730 target to exploit (Modx CMS 0.9.2.1 and earlier/FCKeditor).
5.188.97.19 - ...
show more
Probing for CVE-2006-5730 target to exploit (Modx CMS 0.9.2.1 and earlier/FCKeditor).
5.188.97.19 - - [30/Oct/2025:06:06:32 +0000] "GET /manager/media/script/mootools/mootools.js HTTP/1.1" 403 555 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-25 09:35:54
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 5.188.97.19 (5-188-97-19.umnyeseti.ru): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 5.188.97.19 (5-188-97-19.umnyeseti.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 25 05:35:48.055027 2025] [security2:error] [pid 10148:tid 10148] [client 5.188.97.19:60852] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kenometer.recollected.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kenometer.recollected.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aPyZ9FI1HVDp0lgJ4HzxSQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-24 20:15:58
(9 months ago)
fail2ban apache-modsecurity web [msg "php scripts are not allowed here"] [uri "/mah.php"]
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-24 07:45:22
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 5.188.97.19 (5-188-97-19.umnyeseti.ru): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 5.188.97.19 (5-188-97-19.umnyeseti.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 24 03:45:16.399175 2025] [security2:error] [pid 1313109:tid 1313109] [client 5.188.97.19:50690] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sharawi-gum.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sharawi-gum.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aPsujPCUH-g34Gbmm2ugpgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-24 07:15:45
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 5.188.97.19 (5-188-97-19.umnyeseti.ru): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 5.188.97.19 (5-188-97-19.umnyeseti.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 24 03:15:42.284617 2025] [security2:error] [pid 32527:tid 32527] [client 5.188.97.19:55684] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fusionrep.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fusionrep.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aPsnnm2vogNRU5ec7F9XOAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-24 05:49:22
(9 months ago)
wordpress-trap
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-23 13:25:28
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 5.188.97.19 (5-188-97-19.umnyeseti.ru): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 5.188.97.19 (5-188-97-19.umnyeseti.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 23 09:25:24.215424 2025] [security2:error] [pid 7104:tid 7104] [client 5.188.97.19:60612] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fattoria-rendena.it|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fattoria-rendena.it"] [uri "/wp-json/wp/v2/users"] [unique_id "aPosxLjOI1gEjrpBg4yplQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
kjaerulff
2025-10-20 14:17:21
(9 months ago)
Probing for PHP files (admin.php)
Web App Attack
๐ง๐ช
cmbplf
2025-10-19 01:31:42
(9 months ago)
111 requests with url.path */wp-content/plugins/litespeed-cache/readme.txt
Brute-Force
Bad Web Bot
๐ฉ๐ช
on-com
2025-10-18 09:59:10
(9 months ago)
URL scan
Brute-Force
Web App Attack