πΊπΈ
TPI-Abuse
2026-02-25 23:04:52
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 154.193.155.93 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 154.193.155.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 25 18:04:46.329701 2026] [security2:error] [pid 29132:tid 29132] [client 154.193.155.93:38788] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||directcch.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "directcch.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aZ-ADsdcz4yxKq4Ca61vuwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
backslash
2026-02-25 08:18:00
(7 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-02-13 19:20:54
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 154.193.155.93 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 154.193.155.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 14:20:47.319393 2026] [security2:error] [pid 27884:tid 27884] [client 154.193.155.93:46096] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||passy.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "passy.us"] [uri "/wp-json/wp/v2/users/"] [unique_id "aY95jwJcHWmiVi05YYcrgQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-07 07:08:03
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 154.193.155.93 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 154.193.155.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 07 02:07:56.194376 2026] [security2:error] [pid 14966:tid 14966] [client 154.193.155.93:43498] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wave94.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wave94.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aYbkzG_Cm0WacK8bTRnuLwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-20 15:38:42
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 154.193.155.93 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.193.155.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 20 10:38:33.965629 2026] [security2:error] [pid 2297:tid 2297] [client 154.193.155.93:24862] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||persnicketyinc.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "persnicketyinc.com"] [uri "/wp-login.php"] [unique_id "aW-hefW3V5_KSyW5BscbAwAAAAI"], referer: http://persnicketyinc.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-01-11 16:46:44
(8 months ago)
Failed Wordpress login
Hacking
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-31 04:41:09
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 154.193.155.93 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.193.155.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 30 23:41:02.529971 2025] [security2:error] [pid 7234:tid 7234] [client 154.193.155.93:60600] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||wealthsec.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "wealthsec.com"] [uri "/wp-login.php"] [unique_id "aVSpXn9b_jZvcm6rjp_JqwAAAAU"], referer: https://wealthsec.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-31 04:13:04
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 154.193.155.93 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.193.155.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 30 23:12:53.200767 2025] [security2:error] [pid 22141:tid 22141] [client 154.193.155.93:52502] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.calogerolawfirm.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.calogerolawfirm.com"] [uri "/wp-login.php"] [unique_id "aVSixUIwYiZKarqP62lNzQAAAAM"], referer: http://www.calogerolawfirm.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Packets-Decreaser.NET
2025-12-31 00:59:02
(9 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
π«π·
mrcrassi
2025-12-27 12:30:08
(9 months ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST meth ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /wp-login.php
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:138.0) Gecko/20100101 Firefox/138.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2025-12-24 12:03:46
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 154.193.155.93 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.193.155.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 24 07:03:41.462344 2025] [security2:error] [pid 29702:tid 29702] [client 154.193.155.93:21926] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.mcbrearty.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.mcbrearty.org"] [uri "/wp-login.php"] [unique_id "aUvWnU4j6EtKdSrnkzhkrwAAABE"], referer: http://mcbrearty.org/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-19 21:08:07
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 154.193.155.93 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.193.155.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 19 16:08:00.622435 2025] [security2:error] [pid 25962:tid 25962] [client 154.193.155.93:47242] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.vanmeer.info|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.vanmeer.info"] [uri "/wp-login.php"] [unique_id "aUW-sIsmS8Cv-DuyMzWBWwAAAAU"], referer: http://www.vanmeer.info/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
F242
2025-12-17 23:47:03
(9 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-30 03:17:21
(10 months ago)
(mod_security) mod_security (id:210350) triggered by 154.193.155.93 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.193.155.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 29 22:17:15.646063 2025] [security2:error] [pid 20532:tid 20532] [client 154.193.155.93:18305] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||braintechsoftwaresolutions.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "braintechsoftwaresolutions.com"] [uri "/wp-login.php"] [unique_id "aSu3O07KHqMzbt9JcjUYhAAAAAE"], referer: http://braintechsoftwaresolutions.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-18 12:18:26
(10 months ago)
(mod_security) mod_security (id:210350) triggered by 154.193.155.93 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.193.155.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 18 07:18:20.493362 2025] [security2:error] [pid 32146:tid 32146] [client 154.193.155.93:48513] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||drdot.xyz|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "drdot.xyz"] [uri "/wp-login.php"] [unique_id "aRxkDCOrL1xfUENEJADZqgAAAAQ"], referer: http://drdot.xyz/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack