π¦πΊ
MAGIC
2024-01-30 07:00:22
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
π¬π§
Swiptly
2024-01-23 08:18:48
(2 years ago)
WordPress xmlrpc spam or enumeration
...
Web Spam
Bad Web Bot
Web App Attack
π©π°
wnbhosting.dk
2024-01-20 07:52:17
(2 years ago)
WP xmlrpc [2024-01-20T08:52:17+01:00]
Hacking
Web App Attack
π©π°
wnbhosting.dk
2024-01-19 10:00:13
(2 years ago)
WP xmlrpc [2024-01-19T11:00:13+01:00]
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2024-01-16 06:36:55
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 85.113.30.187 (85-113-30-187.static.ktnet.kg): ...
show more
(mod_security) mod_security (id:225170) triggered by 85.113.30.187 (85-113-30-187.static.ktnet.kg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 16 01:36:46.018622 2024] [security2:error] [pid 7139] [client 85.113.30.187:43858] [client 85.113.30.187] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||starcrestsales.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "starcrestsales.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZaYj_jh_tMiQZtLyIltpcwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-01-15 23:30:44
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 85.113.30.187 (85-113-30-187.static.ktnet.kg): ...
show more
(mod_security) mod_security (id:225170) triggered by 85.113.30.187 (85-113-30-187.static.ktnet.kg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 15 18:30:39.133817 2024] [security2:error] [pid 29476] [client 85.113.30.187:35664] [client 85.113.30.187] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||okanaganwineclub.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "okanaganwineclub.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZaXAH9PdkpqbgjqpsmN7OQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-01-15 20:49:00
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 85.113.30.187 (85-113-30-187.static.ktnet.kg): ...
show more
(mod_security) mod_security (id:225170) triggered by 85.113.30.187 (85-113-30-187.static.ktnet.kg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 15 15:48:55.789561 2024] [security2:error] [pid 22475] [client 85.113.30.187:33140] [client 85.113.30.187] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mail.paleopathologist.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mail.paleopathologist.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZaWaN_-il-2tA2N952tQkgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-01-15 20:09:10
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 85.113.30.187 (85-113-30-187.static.ktnet.kg): ...
show more
(mod_security) mod_security (id:225170) triggered by 85.113.30.187 (85-113-30-187.static.ktnet.kg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 15 15:09:03.904798 2024] [security2:error] [pid 32061] [client 85.113.30.187:44682] [client 85.113.30.187] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||automaticcreditfinancingontario.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "automaticcreditfinancingontario.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZaWQ3wxPO_96AS_dmHACHgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-01-15 10:12:08
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 85.113.30.187 (85-113-30-187.static.ktnet.kg): ...
show more
(mod_security) mod_security (id:225170) triggered by 85.113.30.187 (85-113-30-187.static.ktnet.kg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 15 05:12:02.875872 2024] [security2:error] [pid 2683:tid 47808042280704] [client 85.113.30.187:57964] [client 85.113.30.187] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cocoonprojects.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cocoonprojects.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZaUE8qkAIXIce65kPz3nPwAAAQw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-01-15 03:44:21
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 85.113.30.187 (85-113-30-187.static.ktnet.kg): ...
show more
(mod_security) mod_security (id:225170) triggered by 85.113.30.187 (85-113-30-187.static.ktnet.kg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 14 22:44:14.553758 2024] [security2:error] [pid 22579] [client 85.113.30.187:45532] [client 85.113.30.187] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||vr-squaredance.xyz|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "vr-squaredance.xyz"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZaSqDoaI1ZNZ-KtriWSdLQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-01-15 03:01:42
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 85.113.30.187 (85-113-30-187.static.ktnet.kg): ...
show more
(mod_security) mod_security (id:225170) triggered by 85.113.30.187 (85-113-30-187.static.ktnet.kg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 14 22:01:37.984596 2024] [security2:error] [pid 29499:tid 47048818689792] [client 85.113.30.187:58184] [client 85.113.30.187] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||teddysdeli.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "teddysdeli.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZaSgEQn5pvICUBnwFOdKdQAAAEg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-01-15 01:22:48
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 85.113.30.187 (85-113-30-187.static.ktnet.kg): ...
show more
(mod_security) mod_security (id:225170) triggered by 85.113.30.187 (85-113-30-187.static.ktnet.kg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 14 20:22:43.680576 2024] [security2:error] [pid 19060] [client 85.113.30.187:48278] [client 85.113.30.187] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||weddingb.trophiesetc.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "weddingb.trophiesetc.us"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZaSI42FkfNavQ0TJeijXjAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-01-15 00:57:59
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 85.113.30.187 (85-113-30-187.static.ktnet.kg): ...
show more
(mod_security) mod_security (id:225170) triggered by 85.113.30.187 (85-113-30-187.static.ktnet.kg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 14 19:57:54.055202 2024] [security2:error] [pid 23974] [client 85.113.30.187:34156] [client 85.113.30.187] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||the-it-man.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "the-it-man.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZaSDEuHSEXWVrfU7VTkQ-gAAABU"], referer: http://the-it-man.com///wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-01-14 22:45:29
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 85.113.30.187 (85-113-30-187.static.ktnet.kg): ...
show more
(mod_security) mod_security (id:225170) triggered by 85.113.30.187 (85-113-30-187.static.ktnet.kg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 14 17:45:22.050075 2024] [security2:error] [pid 29287:tid 47760243959552] [client 85.113.30.187:36344] [client 85.113.30.187] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||davidholls.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "davidholls.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZaRkAmb7dDfpvzWE5AUj_QAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-01-14 22:07:12
(2 years ago)
(wordpress-user-enum) Failed wordpress-user-enum trigger from 85.113.30.187 (KG/Kyrgyzstan/85-113-30 ...
show more
(wordpress-user-enum) Failed wordpress-user-enum trigger from 85.113.30.187 (KG/Kyrgyzstan/85-113-30-187.static.ktnet.kg)
show less
Brute-Force