๐ญ๐บ
bcsaba
2025-11-04 15:46:31
(11 months ago)
Looking for WP exploit
77.51.52.250 - - [04/Nov/2025:16:46:29 +0100] "GET /wp-content/plugins/WordPr ...
show more
Looking for WP exploit
77.51.52.250 - - [04/Nov/2025:16:46:29 +0100] "GET /wp-content/plugins/WordPressCore/include.php HTTP/1.1" 404 548 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
COMPLEX
2025-11-04 06:31:52
(11 months ago)
Triggered Cloudflare WAF (firewallCustom) from RU.
Action taken: BLOCK
ASN: 12389 (ROSTELECOM-AS PJS ...
show more
Triggered Cloudflare WAF (firewallCustom) from RU.
Action taken: BLOCK
ASN: 12389 (ROSTELECOM-AS PJSC Rostelecom. Technical Team)
Protocol: HTTP/1.1 (GET method)
Endpoint: /tiny.php
show less
Bad Web Bot
๐บ๐ธ
octageeks.com
2025-11-04 05:06:03
(11 months ago)
Wordpress malicious attack:[octascan]
Web App Attack
Anonymous
2025-11-03 21:00:40
(11 months ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐ณ๐ฑ
exxos
2025-10-27 12:03:01
(11 months ago)
HTTP1.x attacks
DDoS Attack
๐ฉ๐ช
David Ferneding
2025-10-26 11:38:08
(11 months ago)
Blocked by UFW (TCP on 80)
Source port: 58906
TTL: 57
Packet length: 60
TOS: 0x00
This report (for ...
show more
Blocked by UFW (TCP on 80)
Source port: 58906
TTL: 57
Packet length: 60
TOS: 0x00
This report (for 77.51.52.250) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack
๐บ๐ธ
natechoe
2025-10-26 08:16:26
(11 months ago)
Connected to HTTP honeypot at /phpinfo.php
Hacking
๐บ๐ธ
TPI-Abuse
2025-10-25 15:21:15
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 77.51.52.250 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 77.51.52.250 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 25 11:21:09.607825 2025] [security2:error] [pid 22948:tid 22948] [client 77.51.52.250:53828] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||babylontravelone.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "babylontravelone.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aPzq5e4PLgvD55_uOZLprQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ฌ
Filipe Dรกvila
2025-10-25 14:49:40
(11 months ago)
[Sat Oct 25 10:49:38.462881 2025] [:error] [pid 351696:tid 140273313056512] [client 77.51.52.250:546 ...
show more
[Sat Oct 25 10:49:38.462881 2025] [:error] [pid 351696:tid 140273313056512] [client 77.51.52.250:54662] [client 77.51.52.250] [redacted]: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "[redacted][redacted]"] [[redacted] "233"] [id "[redacted]"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "[redacted]/4.7.0-dev"] [tag "[redacted]"] [tag "[redacted]"] [hostname "csweb.[redacted]"] [uri "/phpinfo.php"] [unique_id "aPzjgpybRKheVajWkWFhnQAAAEI"]
show less
Web App Attack
Anonymous
2025-10-25 03:34:00
(11 months ago)
WP Probing and/or Hacking
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-24 16:46:50
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 77.51.52.250 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 77.51.52.250 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 24 12:46:46.151533 2025] [security2:error] [pid 1864823:tid 1864823] [client 77.51.52.250:54300] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sharawi-gum.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sharawi-gum.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aPutduxkv9hQ2RfnS5k9LwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-24 08:03:44
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 77.51.52.250 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 77.51.52.250 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 24 04:03:40.762473 2025] [security2:error] [pid 22053:tid 22053] [client 77.51.52.250:50738] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||protection4allsecurity.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "protection4allsecurity.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aPsy3Kmep9ge1P3SW9c2twAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-23 20:52:08
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 77.51.52.250 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 77.51.52.250 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 23 16:52:01.710928 2025] [security2:error] [pid 14256:tid 14256] [client 77.51.52.250:59950] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fusionrep.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fusionrep.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aPqVcSkYOINZoPsFmKPXAAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2025-10-23 11:10:36
(11 months ago)
IM360 WAF: Interaction with fake plugin MV:/wp-content/plugins/WordPressCore/include.php
Web App Attack
๐ซ๐ท
Thaliruth
2025-10-22 05:43:59
(11 months ago)
77.51.52.250 - - [22/Oct/2025:07:43:58 +0200] "GET /manager/assets/modext/core/modx.js HTTP/1.1" 404 ...
show more
77.51.52.250 - - [22/Oct/2025:07:43:58 +0200] "GET /manager/assets/modext/core/modx.js HTTP/1.1" 404 266 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) obsidian/1.8.10 Chrome/132.0.6834.196 Electron/34.2.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack