๐บ๐ธ
nationaleventpros.com
2024-09-28 05:40:19
(1 year ago)
WordPress login attempt
Brute-Force
๐จ๐ฟ
Milky
2024-09-28 04:50:21
(1 year ago)
1ร attempts to log on to WP. However, we do not use WP. Last visit 2024-09-27 16:49:10
Web Spam
Bad Web Bot
Web App Attack
๐ฉ๐ฐ
wnbhosting.dk
2024-09-28 03:35:38
(1 year ago)
WP xmlrpc [2024-09-28T05:35:38+02:00]
Hacking
Web App Attack
Anonymous
2024-09-28 03:03:18
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2024-09-28 02:23:56
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 54.251.57.14 (ec2-54-251-57-14.ap-southeast-1.c ...
show more
(mod_security) mod_security (id:225170) triggered by 54.251.57.14 (ec2-54-251-57-14.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 27 22:23:50.724844 2024] [security2:error] [pid 2740:tid 2740] [client 54.251.57.14:46412] [client 54.251.57.14] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.iostation.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.iostation.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZvdottY4iSRe6_rdaPVPHAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-27 23:06:43
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 54.251.57.14 (ec2-54-251-57-14.ap-southeast-1.c ...
show more
(mod_security) mod_security (id:225170) triggered by 54.251.57.14 (ec2-54-251-57-14.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 27 19:06:38.642699 2024] [security2:error] [pid 30611:tid 30611] [client 54.251.57.14:34622] [client 54.251.57.14] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.isslv.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.isslv.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "Zvc6fizc33j6TjNjJRTZtwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-27 22:44:30
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 54.251.57.14 (ec2-54-251-57-14.ap-southeast-1.c ...
show more
(mod_security) mod_security (id:225170) triggered by 54.251.57.14 (ec2-54-251-57-14.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 27 18:44:26.197970 2024] [security2:error] [pid 29951:tid 29951] [client 54.251.57.14:39894] [client 54.251.57.14] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sawted.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sawted.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Zvc1SkZv_vsj5twYsSS-hQAAAAI"], referer: http://sawted.com///wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐น
American Jesus
2024-09-27 21:38:00
(1 year ago)
54.251.57.14 - - [27/Sep/2024:21:37:56 +0000] "GET /wp-login.php HTTP/1.1" 301 162 "-" "Mozilla/5.0 ...
show more
54.251.57.14 - - [27/Sep/2024:21:37:56 +0000] "GET /wp-login.php HTTP/1.1" 301 162 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:94.0) Gecko/20100101 Firefox/95.0"
54.251.57.14 - - [27/Sep/2024:21:37:57 +0000] "GET /wp-login.php HTTP/1.1" 301 162 "http://status.generator.duckdns.org/wp-login.php" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:94.0) Gecko/20100101 Firefox/95.0"
54.251.57.14 - - [27/Sep/2024:21:37:59 +0000] "GET /wp-login.php HTTP/1.1" 404 47 "http://status.generator.dedyn.io/wp-login.php" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:94.0) Gecko/20100101 Firefox/95.0"
...
show less
Web App Attack
๐บ๐ธ
snappic
2024-09-27 18:36:43
(1 year ago)
Unsupported user agent typically used for Wordpress exploits [GET /wp-login.php] [Mozilla/5.0 (X11; ...
show more
Unsupported user agent typically used for Wordpress exploits [GET /wp-login.php] [Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:94.0) Gecko/20100101 Firefox/95.0] **Reported from WAF sampled requests**
show less
Bad Web Bot
Web App Attack
Anonymous
2024-09-27 18:00:09
(1 year ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-27 17:27:20
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 54.251.57.14 (ec2-54-251-57-14.ap-southeast-1.c ...
show more
(mod_security) mod_security (id:225170) triggered by 54.251.57.14 (ec2-54-251-57-14.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 27 13:27:12.825967 2024] [security2:error] [pid 22972:tid 22972] [client 54.251.57.14:58866] [client 54.251.57.14] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.caymancline.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.caymancline.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Zvbq8LKCgjTi9Cn8MKxWzgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TheMadBeaker
2024-09-27 17:16:58
(1 year ago)
Fail2Ban Ban Triggered
Wordpress Attack Attempt
Brute-Force
Web App Attack
Anonymous
2024-09-27 16:36:05
(1 year ago)
wordpress-trap
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-27 16:17:31
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 54.251.57.14 (ec2-54-251-57-14.ap-southeast-1.c ...
show more
(mod_security) mod_security (id:225170) triggered by 54.251.57.14 (ec2-54-251-57-14.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 27 12:17:25.405098 2024] [security2:error] [pid 4020480:tid 4021100] [client 54.251.57.14:33080] [client 54.251.57.14] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mail.kennedyfineartphotography.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mail.kennedyfineartphotography.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZvbalZ7JhlesDjQ2NbACtgAAAlQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-09-27 14:25:38
(1 year ago)
wordpress-trap
Web App Attack