Anonymous
2025-11-18 20:02:02
(9 months ago)
scanning http requests from known botnet
Web App Attack
๐บ๐ธ
myagent.site
2025-10-27 10:37:19
(10 months ago)
Blocking for trying to access an exploit file: /test.php
Hacking
Anonymous
2025-10-27 09:08:46
(10 months ago)
wordpress-trap
Web App Attack
๐ฉ๐ช
kranem
2025-10-26 12:00:38
(10 months ago)
Triggered Cloudflare WAF from RU.
Action taken: BLOCK
ASN: 34757 (SIBSET-NSK-AS)
Protocol: HTTP/1.1 ...
show more
Triggered Cloudflare WAF from RU.
Action taken: BLOCK
ASN: 34757 (SIBSET-NSK-AS)
Protocol: HTTP/1.1 (GET method)
Endpoint: /xleet.php
Timestamp: 2025-10-26T10:32:43Z
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0
show less
Bad Web Bot
๐บ๐ธ
OceanTreasure
2025-10-26 08:55:06
(10 months ago)
tcp/443; Attempt to enumerate WordPress plugins or detect vulnerable extensions: "GET /wp-content/pl ...
show more
tcp/443; Attempt to enumerate WordPress plugins or detect vulnerable extensions: "GET /wp-content/plugins/WordPressCore/include.php" @ 2025-10-26T08:51:20Z [proxy]
show less
Brute-Force
๐ฆ๐บ
MAGIC
2025-10-26 03:14:05
(10 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ฌ๐ง
CrystalMaker
2025-10-25 21:25:02
(10 months ago)
Vulnerability scan - GET /rest
Hacking
๐บ๐ธ
TPI-Abuse
2025-10-25 17:52:49
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 5.44.168.87 (nat-22-8.nsk.sibset.net): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 5.44.168.87 (nat-22-8.nsk.sibset.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 25 13:52:42.475553 2025] [security2:error] [pid 766044:tid 766044] [client 5.44.168.87:49772] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sharawi-gum.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sharawi-gum.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aP0Oanv9lo7lAv1i4DmRRAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Hazael
2025-10-25 12:28:43
(10 months ago)
SNOOPING - intended to probe for or exploit website vulnerabilities. From: Novosibirsk, Russia - SIB ...
show more
SNOOPING - intended to probe for or exploit website vulnerabilities. From: Novosibirsk, Russia - SIBNETWORKS NSK nats (AS34757 Sibirskie Seti Ltd.) - Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36
show less
Web App Attack
Anonymous
2025-10-25 11:08:39
(10 months ago)
wordpress-trap
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-25 04:48:02
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 5.44.168.87 (nat-22-8.nsk.sibset.net): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 5.44.168.87 (nat-22-8.nsk.sibset.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 25 00:47:56.089592 2025] [security2:error] [pid 28546:tid 28546] [client 5.44.168.87:55730] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fusionrep.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fusionrep.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aPxWfNnRSEaN4EL8luXNJAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
octageeks.com
2025-10-25 04:06:32
(10 months ago)
Wordpress malicious attack:[octascan]
Web App Attack
๐จ๐ญ
YF
2025-10-25 04:05:02
(10 months ago)
Attempted access to sensitive files
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-23 22:03:19
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 5.44.168.87 (nat-22-8.nsk.sibset.net): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 5.44.168.87 (nat-22-8.nsk.sibset.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 23 18:03:12.563749 2025] [security2:error] [pid 5994:tid 5994] [client 5.44.168.87:58280] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||babylontravelone.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "babylontravelone.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aPqmIInpo4o6RBke0xX86QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-23 15:58:55
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 5.44.168.87 (nat-22-8.nsk.sibset.net): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 5.44.168.87 (nat-22-8.nsk.sibset.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 23 11:58:50.940669 2025] [security2:error] [pid 13432:tid 13432] [client 5.44.168.87:58562] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fattoria-rendena.it|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fattoria-rendena.it"] [uri "/wp-json/wp/v2/users"] [unique_id "aPpQutFGypqKbkrp_rvxsQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack