๐ซ๐ท
Guardian
2025-05-30 01:44:39
(1 year ago)
Unauthorized connection attempt / Port scanning
82.154.8.249 [30/May/2025:01:44:38] "POST /xmlrpc.ph ...
show more
Unauthorized connection attempt / Port scanning
82.154.8.249 [30/May/2025:01:44:38] "POST /xmlrpc.php HTTP/1.1"
show less
Port Scan
Web App Attack
Anonymous
2025-05-29 08:37:03
(1 year ago)
Malicious activity detected
Hacking
Web App Attack
Anonymous
2025-05-29 01:57:14
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฉ๐ช
Vegascosmetics
2025-05-27 21:51:51
(1 year ago)
Kingcopy(AI-IDS): IP is wandering around the site and acting suspiciously.
Bad Web Bot
Anonymous
2025-05-26 16:30:01
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-05-26 16:03:50
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 82.154.8.249 (bl5-8-249.dsl.telepac.pt): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 82.154.8.249 (bl5-8-249.dsl.telepac.pt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 26 12:03:42.835272 2025] [security2:error] [pid 3530200:tid 3530327] [client 82.154.8.249:37492] [client 82.154.8.249] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||iamfluff.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "iamfluff.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aDSQ3vnbexnvfrEQYTPQowAABBA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-24 11:52:36
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 82.154.8.249 (bl5-8-249.dsl.telepac.pt): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 82.154.8.249 (bl5-8-249.dsl.telepac.pt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 24 07:52:31.813459 2025] [security2:error] [pid 3003226:tid 3003226] [client 82.154.8.249:38669] [client 82.154.8.249] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||adonamusic.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "adonamusic.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aDGy_x4hSAnzouSuGcbGXwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-24 10:50:58
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 82.154.8.249 (bl5-8-249.dsl.telepac.pt): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 82.154.8.249 (bl5-8-249.dsl.telepac.pt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 24 06:50:54.897760 2025] [security2:error] [pid 2028187:tid 2028276] [client 82.154.8.249:37185] [client 82.154.8.249] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||willmanlawfirm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "willmanlawfirm.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aDGkjib7lUt0ANmvMzsXKAAAANY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-24 06:24:53
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 82.154.8.249 (bl5-8-249.dsl.telepac.pt): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 82.154.8.249 (bl5-8-249.dsl.telepac.pt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 24 02:24:49.343770 2025] [security2:error] [pid 1699988:tid 1699988] [client 82.154.8.249:38460] [client 82.154.8.249] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cosplayculture.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cosplayculture.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aDFmMS06hXGfxWZ_q5o7FQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-05-24 04:39:56
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-05-24 03:20:40
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 82.154.8.249 (bl5-8-249.dsl.telepac.pt): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 82.154.8.249 (bl5-8-249.dsl.telepac.pt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 23 23:20:32.562111 2025] [security2:error] [pid 2130601:tid 2130601] [client 82.154.8.249:38359] [client 82.154.8.249] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||honigcpa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "honigcpa.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aDE7AK_YmNmypWp4QwWXUwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Roderic
2025-05-23 18:11:11
(1 year ago)
(apache_scanners-2) Failed apache-scanners trigger with match [redacted])
Port Scan
๐ณ๐ฑ
Roderic
2025-05-23 18:11:11
(1 year ago)
(apache-scanners) Failed apache-scanners trigger with match [redacted])
Port Scan
๐บ๐ธ
TPI-Abuse
2025-05-23 07:35:37
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 82.154.8.249 (bl5-8-249.dsl.telepac.pt): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 82.154.8.249 (bl5-8-249.dsl.telepac.pt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 23 03:35:31.403732 2025] [security2:error] [pid 4049062:tid 4049062] [client 82.154.8.249:38157] [client 82.154.8.249] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||judithcaldwell.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "judithcaldwell.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aDAlQ4hKBnRwkxSlM1VGjAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-23 03:30:09
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 82.154.8.249 (bl5-8-249.dsl.telepac.pt): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 82.154.8.249 (bl5-8-249.dsl.telepac.pt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 22 23:30:00.479680 2025] [security2:error] [pid 1567495:tid 1567595] [client 82.154.8.249:39256] [client 82.154.8.249] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pref-realestate.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pref-realestate.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aC_ruPnBByy-nuI2_Jrs4AAAAM4"]
show less
Brute-Force
Bad Web Bot
Web App Attack