๐บ๐ธ
nowyouknow
2024-08-16 19:21:23
(1 year ago)
(From [email protected] ) Hi there,
I ran across your website and thought Iโd reach o ...
show more
(From [email protected] ) Hi there,
I ran across your website and thought Iโd reach out with a cool offer. I work at a PR firm, and weโre offering a no-cost press release for your business! Our publicists will whip up a polished, headline-worthy press release thatโll help get your name out there and catch some extra attention. Our press releases get featured on high authority websites like Bloomberg, NBC, ABC, Fox, Business Insider and over 300 more.
Interested? Just use the chat link below to enter some info, and weโll handle everything. No strings attachedโjust a little boost for your biz!
Hereโs my chat page:
https://hi.switchy.io/press-release-offer
show less
Phishing
Web Spam
๐ณ๐ฑ
applemooz
2024-08-16 15:14:54
(1 year ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-16 15:10:29
(1 year ago)
(mod_security) mod_security (id:240335) triggered by 79.147.43.226 (226.red-79-147-43.dynamicip.rima ...
show more
(mod_security) mod_security (id:240335) triggered by 79.147.43.226 (226.red-79-147-43.dynamicip.rima-tde.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 16 11:10:25.216195 2024] [security2:error] [pid 389:tid 389] [client 79.147.43.226:40589] [client 79.147.43.226] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 79.147.43.226 (+1 hits since last alert)|www.davidquiroa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.davidquiroa.com"] [uri "/xmlrpc.php"] [unique_id "Zr9r4eMLdNsl4L5iOfpnewAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-16 00:27:47
(1 year ago)
(mod_security) mod_security (id:240335) triggered by 79.147.43.226 (226.red-79-147-43.dynamicip.rima ...
show more
(mod_security) mod_security (id:240335) triggered by 79.147.43.226 (226.red-79-147-43.dynamicip.rima-tde.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 15 20:27:41.684129 2024] [security2:error] [pid 23636:tid 23636] [client 79.147.43.226:41652] [client 79.147.43.226] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 79.147.43.226 (+1 hits since last alert)|www.method1.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.method1.net"] [uri "/xmlrpc.php"] [unique_id "Zr6c_Y_xQQQ-Lc_LnKRVgAAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-15 23:15:27
(1 year ago)
(mod_security) mod_security (id:240335) triggered by 79.147.43.226 (226.red-79-147-43.dynamicip.rima ...
show more
(mod_security) mod_security (id:240335) triggered by 79.147.43.226 (226.red-79-147-43.dynamicip.rima-tde.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 15 19:15:22.318444 2024] [security2:error] [pid 3151:tid 3151] [client 79.147.43.226:42110] [client 79.147.43.226] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 79.147.43.226 (+1 hits since last alert)|seahattravel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "seahattravel.com"] [uri "/xmlrpc.php"] [unique_id "Zr6MCo2_Vm7qL2unGFdM4QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-15 04:21:18
(1 year ago)
(mod_security) mod_security (id:240335) triggered by 79.147.43.226 (226.red-79-147-43.dynamicip.rima ...
show more
(mod_security) mod_security (id:240335) triggered by 79.147.43.226 (226.red-79-147-43.dynamicip.rima-tde.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 15 00:21:13.273704 2024] [security2:error] [pid 14441:tid 14454] [client 79.147.43.226:42244] [client 79.147.43.226] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 79.147.43.226 (+1 hits since last alert)|woofnrose.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "woofnrose.com"] [uri "/xmlrpc.php"] [unique_id "Zr2COUgWKYt4o3QzjfMpfQAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐น
Malta
2024-08-15 02:51:37
(1 year ago)
79.147.43.226 - - [15/Aug/2024:04:51:36 +0200] "POST /xmlrpc.php HTTP/1.1" "Mozilla/5.0 (Macintosh; ...
show more
79.147.43.226 - - [15/Aug/2024:04:51:36 +0200] "POST /xmlrpc.php HTTP/1.1" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.6422.60 Safari/537.36"
Brute-force password attempt
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-15 00:14:38
(1 year ago)
(mod_security) mod_security (id:240335) triggered by 79.147.43.226 (226.red-79-147-43.dynamicip.rima ...
show more
(mod_security) mod_security (id:240335) triggered by 79.147.43.226 (226.red-79-147-43.dynamicip.rima-tde.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 14 20:14:31.264078 2024] [security2:error] [pid 9580:tid 9580] [client 79.147.43.226:59800] [client 79.147.43.226] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 79.147.43.226 (+1 hits since last alert)|desertalfas.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "desertalfas.org"] [uri "/xmlrpc.php"] [unique_id "Zr1IZ23RMla_B7eumPuCXgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack