Anonymous
2023-11-24 11:53:14
(2 years ago)
Malicious activity detected
Hacking
Brute-Force
๐ฉ๐ช
psauxit
2023-11-23 17:36:15
(2 years ago)
Fail2Ban - NGINX bad requests 400-401-403-404-444, high level vulnerability scanning, commonly xmlrp ...
show more
Fail2Ban - NGINX bad requests 400-401-403-404-444, high level vulnerability scanning, commonly xmlrpc_attack, wp-login brute force, excessive crawling/scraping
show less
Hacking
Web App Attack
๐ฉ๐ช
Richie
2023-11-23 11:51:35
(2 years ago)
[HOST2] Port Scan detected
Port Scan
๐บ๐ธ
TPI-Abuse
2023-11-20 11:55:44
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 88.198.48.98 (static.88-198-48-98.clients.your- ...
show more
(mod_security) mod_security (id:225170) triggered by 88.198.48.98 (static.88-198-48-98.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 20 06:55:38.907560 2023] [security2:error] [pid 21972] [client 88.198.48.98:55890] [client 88.198.48.98] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||shelbysmoak.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "shelbysmoak.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ZVtJOhN-ilzg4osibKdqZQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-20 10:47:11
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 88.198.48.98 (static.88-198-48-98.clients.your- ...
show more
(mod_security) mod_security (id:225170) triggered by 88.198.48.98 (static.88-198-48-98.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 20 05:47:05.882985 2023] [security2:error] [pid 20661] [client 88.198.48.98:35804] [client 88.198.48.98] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pastorjohndunning.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pastorjohndunning.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ZVs5KeiftZJzxJzXstLaBgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-20 09:47:53
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 88.198.48.98 (static.88-198-48-98.clients.your- ...
show more
(mod_security) mod_security (id:225170) triggered by 88.198.48.98 (static.88-198-48-98.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 20 04:47:46.305035 2023] [security2:error] [pid 9414] [client 88.198.48.98:41242] [client 88.198.48.98] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.midwayisland.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.midwayisland.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ZVsrQiBX8niaGdYVGHDybAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-20 08:17:18
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 88.198.48.98 (static.88-198-48-98.clients.your- ...
show more
(mod_security) mod_security (id:225170) triggered by 88.198.48.98 (static.88-198-48-98.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 20 03:17:11.058826 2023] [security2:error] [pid 32059] [client 88.198.48.98:41162] [client 88.198.48.98] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kdgsf.xyz|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kdgsf.xyz"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ZVsWB-QGK9-GnierSxxCmgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-20 08:00:48
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 88.198.48.98 (static.88-198-48-98.clients.your- ...
show more
(mod_security) mod_security (id:225170) triggered by 88.198.48.98 (static.88-198-48-98.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 20 03:00:43.290515 2023] [security2:error] [pid 1400] [client 88.198.48.98:38076] [client 88.198.48.98] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||johncyphers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "johncyphers.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ZVsSKx-SJ6t5BfI9UHMaawAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-20 06:09:14
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 88.198.48.98 (static.88-198-48-98.clients.your- ...
show more
(mod_security) mod_security (id:225170) triggered by 88.198.48.98 (static.88-198-48-98.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 20 01:09:09.880859 2023] [security2:error] [pid 17801] [client 88.198.48.98:36174] [client 88.198.48.98] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||futuresgrowhere.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "futuresgrowhere.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ZVr4BcaiuKl67eJgQGzg5gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-20 05:14:59
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 88.198.48.98 (static.88-198-48-98.clients.your- ...
show more
(mod_security) mod_security (id:225170) triggered by 88.198.48.98 (static.88-198-48-98.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 20 00:14:56.456450 2023] [security2:error] [pid 16084] [client 88.198.48.98:39594] [client 88.198.48.98] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.elpaco.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.elpaco.net"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ZVrrUAOLs-hqJQT1-cLKaQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-20 03:16:26
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 88.198.48.98 (static.88-198-48-98.clients.your- ...
show more
(mod_security) mod_security (id:225170) triggered by 88.198.48.98 (static.88-198-48-98.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 19 22:16:20.742498 2023] [security2:error] [pid 32673] [client 88.198.48.98:44922] [client 88.198.48.98] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.caferutadelaseda.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.caferutadelaseda.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ZVrPhFYW9nSIa29ykcQ8AgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-20 02:29:23
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 88.198.48.98 (static.88-198-48-98.clients.your- ...
show more
(mod_security) mod_security (id:225170) triggered by 88.198.48.98 (static.88-198-48-98.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 19 21:29:16.907780 2023] [security2:error] [pid 17790] [client 88.198.48.98:47982] [client 88.198.48.98] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bamedica.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bamedica.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ZVrEfIJy91RAgw7a_r67JwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2023-11-20 01:35:06
(2 years ago)
Malicious activity detected
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2023-11-20 01:18:35
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 88.198.48.98 (static.88-198-48-98.clients.your- ...
show more
(mod_security) mod_security (id:225170) triggered by 88.198.48.98 (static.88-198-48-98.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 19 20:18:28.966389 2023] [security2:error] [pid 10587] [client 88.198.48.98:50878] [client 88.198.48.98] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.aandbnaturalfoods.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.aandbnaturalfoods.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ZVqz5IE6ugblHTPAhIw90gAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-20 00:26:22
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 88.198.48.98 (static.88-198-48-98.clients.your- ...
show more
(mod_security) mod_security (id:225170) triggered by 88.198.48.98 (static.88-198-48-98.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 19 19:26:18.680296 2023] [security2:error] [pid 19937:tid 48010654447360] [client 88.198.48.98:50128] [client 88.198.48.98] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.visaliacem.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.visaliacem.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ZVqnqv0-GzyfEWzv00ahIQAAAJY"]
show less
Brute-Force
Bad Web Bot
Web App Attack