Anonymous
2025-07-06 15:46:45
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-06-01 08:53:15
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ง๐ท
hostseries
2025-01-09 14:00:51
(1 year ago)
Trigger: LF_IMAPD
Brute-Force
๐ฉ๐ช
Vegascosmetics
2024-12-28 22:50:35
(1 year ago)
Kingcopy(AI-IDS):IP is Probing for Wordpress vulnerabilities WTF:Banned
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-28 05:45:16
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 92.223.85.70 (vpn-gw-prod-009.sin0-gcl.ff.avast ...
show more
(mod_security) mod_security (id:225170) triggered by 92.223.85.70 (vpn-gw-prod-009.sin0-gcl.ff.avast.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 28 00:45:09.180783 2024] [security2:error] [pid 27286:tid 27286] [client 92.223.85.70:6943] [client 92.223.85.70] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||aisoftwaretools.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "aisoftwaretools.com"] [uri "/blog/wp-json/wp/v2/users/"] [unique_id "Z2-QZXCzWCT9RcViLvxhWwAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-28 05:30:07
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 92.223.85.70 (vpn-gw-prod-009.sin0-gcl.ff.avast ...
show more
(mod_security) mod_security (id:225170) triggered by 92.223.85.70 (vpn-gw-prod-009.sin0-gcl.ff.avast.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 28 00:30:03.020912 2024] [security2:error] [pid 5784:tid 5784] [client 92.223.85.70:6907] [client 92.223.85.70] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||symbarenewables.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "symbarenewables.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Z2-M26dWUfpo6wSn-AspTgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2024-12-28 00:23:28
(1 year ago)
โจ๏ธ Probes for wlwmanifest.xml everywhere
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-28 00:14:08
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 92.223.85.70 (vpn-gw-prod-009.sin0-gcl.ff.avast ...
show more
(mod_security) mod_security (id:225170) triggered by 92.223.85.70 (vpn-gw-prod-009.sin0-gcl.ff.avast.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 27 19:14:03.045216 2024] [security2:error] [pid 21084:tid 21084] [client 92.223.85.70:6846] [client 92.223.85.70] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.fatcavestudios.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.fatcavestudios.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Z29Cy0JHWUQBnYyWd5JXJQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2024-12-27 23:58:47
(1 year ago)
10 attempts against mh_ha-misc-ban on ec102967
Brute-Force
Web App Attack
๐ฌ๐ง
Apache
2024-12-21 12:47:37
(1 year ago)
(mod_security) mod_security (id:210410) triggered by 92.223.85.70 (SG/Singapore/vpn-gw-prod-009.sin0 ...
show more
(mod_security) mod_security (id:210410) triggered by 92.223.85.70 (SG/Singapore/vpn-gw-prod-009.sin0-gcl.ff.avast.com): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-21 12:41:11
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 92.223.85.70 (vpn-gw-prod-009.sin0-gcl.ff.avast ...
show more
(mod_security) mod_security (id:225170) triggered by 92.223.85.70 (vpn-gw-prod-009.sin0-gcl.ff.avast.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 21 07:41:07.659786 2024] [security2:error] [pid 23105:tid 23105] [client 92.223.85.70:10052] [client 92.223.85.70] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dynamic-therapy-mn.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dynamic-therapy-mn.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Z2a3Y-dBUj9-9LIDvbjhKAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
COMAITE
2024-12-21 12:38:52
(1 year ago)
Multiple web server 400 error codes from same source ip 92.223.85.70.
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-21 12:04:33
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 92.223.85.70 (vpn-gw-prod-009.sin0-gcl.ff.avast ...
show more
(mod_security) mod_security (id:225170) triggered by 92.223.85.70 (vpn-gw-prod-009.sin0-gcl.ff.avast.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 21 07:04:26.409127 2024] [security2:error] [pid 3307:tid 3307] [client 92.223.85.70:10064] [client 92.223.85.70] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.kvaziri.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.kvaziri.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Z2auyszsxlv01xHlD_24FwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-12-21 11:20:50
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐น๐ท
rtbh.com.tr
2024-12-09 20:52:52
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force