๐น๐ท
rtbh.com.tr
2025-09-26 20:09:01
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐น๐ท
rtbh.com.tr
2025-09-26 00:08:59
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐น๐ท
rtbh.com.tr
2025-09-25 20:09:00
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐บ๐ธ
octageeks.com
2025-09-25 04:06:55
(1 year ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐ฉ๐ช
SpaceHost-Server
2025-09-24 22:31:09
(1 year ago)
Brute-Force
Web App Attack
๐บ๐ธ
Charlesiv
2025-09-24 19:36:08
(1 year ago)
Triggered Cloudflare WAF (botFight) from US.
Action taken: MANAGED_CHALLENGE
ASN: 14618 (AMAZON-AES) ...
show more
Triggered Cloudflare WAF (botFight) from US.
Action taken: MANAGED_CHALLENGE
ASN: 14618 (AMAZON-AES)
Protocol: HTTP/1.1 (GET method)
Endpoint: //site/wp-includes/wlwmanifest.xml
Timestamp: 2025-09-24T19:01:48Z
Ray ID: 9844884f4c703450
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-09-24 19:31:15
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 54.90.93.193 (ec2-54-90-93-193.compute-1.amazon ...
show more
(mod_security) mod_security (id:225170) triggered by 54.90.93.193 (ec2-54-90-93-193.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 24 15:31:08.058166 2025] [security2:error] [pid 13810:tid 13810] [client 54.90.93.193:62308] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.bernsteinip.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.bernsteinip.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aNRG_OPKdC3_0dKz4OpUhwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
applemooz
2025-09-24 19:19:01
(1 year ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-24 17:44:26
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 54.90.93.193 (ec2-54-90-93-193.compute-1.amazon ...
show more
(mod_security) mod_security (id:225170) triggered by 54.90.93.193 (ec2-54-90-93-193.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 24 13:44:19.808176 2025] [security2:error] [pid 2585999:tid 2586024] [client 54.90.93.193:59381] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.ccgparquitectos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.ccgparquitectos.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aNQt866WKTzVDzjQKzjb0QAAAVQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
KitsuneTech
2025-09-24 17:30:17
(1 year ago)
54.90.93.193 - - [24/Sep/2025:12:30:17 -0500] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 301 259 " ...
show more
54.90.93.193 - - [24/Sep/2025:12:30:17 -0500] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 301 259 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-24 17:28:10
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 54.90.93.193 (ec2-54-90-93-193.compute-1.amazon ...
show more
(mod_security) mod_security (id:225170) triggered by 54.90.93.193 (ec2-54-90-93-193.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 24 13:28:05.531217 2025] [security2:error] [pid 3628:tid 3628] [client 54.90.93.193:60856] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cathybermanmft.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cathybermanmft.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aNQqJTQO4f8DCvHFim8qewAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2025-09-24 17:06:15
(1 year ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
iNetWorker
2025-09-24 17:06:14
(1 year ago)
trolling for resource vulnerabilities
Web App Attack
๐จ๐ฆ
polycoda
2025-09-24 16:58:11
(1 year ago)
โจ๏ธ Probes for wlwmanifest.xml everywhere
Hacking
Web App Attack
๐บ๐ธ
myagent.site
2025-09-24 16:48:20
(1 year ago)
Blocked user enumeration attempt
Hacking