Anonymous
2025-11-04 14:01:23
(8 months ago)
wordpress-trap
Web App Attack
๐ท๐บ
Mga Admin
2025-11-03 20:08:07
(8 months ago)
82.208.107.165 - - [04/Nov/2025:03:08:06 +0700] "GET /goods.php HTTP/1.1" 404 16 "-" "Mozilla/5.0 (W ...
show more
82.208.107.165 - - [04/Nov/2025:03:08:06 +0700] "GET /goods.php HTTP/1.1" 404 16 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36"
82.208.107.165 - - [04/Nov/2025:03:08:06 +0700] "GET /mah.php HTTP/1.1" 404 16 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ฉ๐ช
KiekerJan
2025-11-01 19:22:43
(8 months ago)
82.208.107.165 - - [01/Nov/2025:20:22:43 +0100] "GET /wp-content/plugins/king-addons/freemius/assets ...
show more
82.208.107.165 - - [01/Nov/2025:20:22:43 +0100] "GET /wp-content/plugins/king-addons/freemius/assets/css/customizer.css HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/26.0 Safari/605.1.15"
82.208.107.165 - - [01/Nov/2025:20:22:43 +0100] "GET /wp-content/plugins/king-addons/freemius/assets/css/customizer.css HTTP/1.1" 404 146 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/26.0 Safari/605.1.15"
...
show less
Web App Attack
๐ช๐ช
Unwasted
2025-10-30 01:52:22
(9 months ago)
Abusive content scan (abuse_score:>80)
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
Charlesiv
2025-10-28 16:53:40
(9 months ago)
Triggered Cloudflare WAF (firewallCustom) from RU.
Action taken: BLOCK
ASN: 12389 (ROSTELECOM-AS PJS ...
show more
Triggered Cloudflare WAF (firewallCustom) from RU.
Action taken: BLOCK
ASN: 12389 (ROSTELECOM-AS PJSC Rostelecom. Technical Team)
Protocol: HTTP/1.1 (GET method)
Endpoint: /inputs.php
Timestamp: 2025-10-28T13:59:37Z
Ray ID: 995af46b1a1a8b0c
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
show less
Bad Web Bot
Anonymous
2025-10-28 11:49:03
(9 months ago)
Bot / scanning and/or hacking attempts: GET /p.php HTTP/1.1, GET /i.php HTTP/1.1, GET /phpinfo.php H ...
show more
Bot / scanning and/or hacking attempts: GET /p.php HTTP/1.1, GET /i.php HTTP/1.1, GET /phpinfo.php HTTP/1.1, GET / HTTP/1.1
show less
Hacking
Web App Attack
๐ฉ๐ช
Interceptor_HQ
2025-10-27 21:48:42
(9 months ago)
request_uri: /manager/assets/modext/core/modx.js -- automatic report --
Hacking
Brute-Force
๐จ๐ฟ
ddw
2025-10-27 05:56:10
(9 months ago)
ModSecurity detection - Rules: 933150(PHP Injection Attack: High-Risk PHP Function Name Found)
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-25 12:50:23
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 82.208.107.165 (82-208-107-165.static.mts-nn.ru ...
show more
(mod_security) mod_security (id:225170) triggered by 82.208.107.165 (82-208-107-165.static.mts-nn.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 25 08:50:16.155729 2025] [security2:error] [pid 32045:tid 32045] [client 82.208.107.165:54142] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||babylontravelone.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "babylontravelone.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aPzHiPiWQQ6bH-kukQg4GAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
barbarella
2025-10-24 14:13:42
(9 months ago)
unauthorized access to Wordpress files (GET /wp-content/plugins/WordPressCore/include.php)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-24 09:51:55
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 82.208.107.165 (82-208-107-165.static.mts-nn.ru ...
show more
(mod_security) mod_security (id:225170) triggered by 82.208.107.165 (82-208-107-165.static.mts-nn.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 24 05:51:46.839929 2025] [security2:error] [pid 22419:tid 22419] [client 82.208.107.165:53638] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fattoria-rendena.it|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fattoria-rendena.it"] [uri "/wp-json/wp/v2/users"] [unique_id "aPtMMtahPNkgCMyArvyDtQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-24 07:07:08
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 82.208.107.165 (82-208-107-165.static.mts-nn.ru ...
show more
(mod_security) mod_security (id:225170) triggered by 82.208.107.165 (82-208-107-165.static.mts-nn.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 24 03:07:03.844224 2025] [security2:error] [pid 1226206:tid 1226206] [client 82.208.107.165:53018] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sharawi-gum.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sharawi-gum.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aPsllwyMi__eb-vVoKa9AAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-23 23:21:45
(9 months ago)
wordpress-trap
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-23 23:00:06
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 82.208.107.165 (82-208-107-165.static.mts-nn.ru ...
show more
(mod_security) mod_security (id:225170) triggered by 82.208.107.165 (82-208-107-165.static.mts-nn.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 23 18:59:55.451568 2025] [security2:error] [pid 23814:tid 23814] [client 82.208.107.165:52376] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kenometer.recollected.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kenometer.recollected.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aPqza5lyqsPi_pzoNwHltwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Rosh
2025-10-23 17:37:23
(9 months ago)
[10/23/25 19:37:23] 1 attack: /manager/media/script/mootools/mootools.js (severity 9);
Web App Attack