πΊπΈ
TPI-Abuse
2026-02-07 20:33:37
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 154.193.158.104 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 154.193.158.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 07 15:33:33.456835 2026] [security2:error] [pid 2604945:tid 2604945] [client 154.193.158.104:26398] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.joeordie.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.joeordie.com"] [uri "/wp-login.php"] [unique_id "aYehnY-MxpYYR95g2Z1xJgAAACQ"], referer: http://joeordie.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-05 23:40:35
(7 months ago)
wordpress-trap
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-30 07:07:58
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 154.193.158.104 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 154.193.158.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 30 02:07:53.150265 2026] [security2:error] [pid 13204:tid 13204] [client 154.193.158.104:58964] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||tlc-computing.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "tlc-computing.com"] [uri "/wp-login.php"] [unique_id "aXxYyYbzAiZlx3Z5lt9xHQAAAAE"], referer: http://tlc-computing.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-12 20:54:45
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 154.193.158.104 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 154.193.158.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 12 15:54:39.015583 2026] [security2:error] [pid 27851:tid 27851] [client 154.193.158.104:30552] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.calogerolawfirm.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.calogerolawfirm.com"] [uri "/wp-login.php"] [unique_id "aWVfj6H2pvBaUrMS7UEyHQAAABE"], referer: http://calogerolawfirm.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Jaime
2026-01-11 08:22:01
(8 months ago)
This day 1 times ... Access forbidden - 403: - ... /wp-login.php
Brute-Force
πΊπΈ
TPI-Abuse
2026-01-10 01:19:10
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 154.193.158.104 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 154.193.158.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 09 20:19:00.657337 2026] [security2:error] [pid 23280:tid 23289] [client 154.193.158.104:50822] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||kettlehill.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "kettlehill.com"] [uri "/wp-login.php"] [unique_id "aWGpBARm-ptTZCjdZBUUYgAAAQc"], referer: https://kettlehill.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Packets-Decreaser.NET
2025-12-31 00:57:59
(8 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
πΊπΈ
TPI-Abuse
2025-12-27 00:43:10
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 154.193.158.104 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 154.193.158.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 26 19:43:03.301756 2025] [security2:error] [pid 17571:tid 17571] [client 154.193.158.104:56354] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||waggonerfinancial.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "waggonerfinancial.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aU8rl5qjEF8A9dKjFpluiQAAABw"], referer: https://waggonerfinancial.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
kosada.com
2025-12-26 17:50:02
(8 months ago)
Web password guessing
Brute-Force
πΊπΈ
TPI-Abuse
2025-12-23 14:30:34
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 154.193.158.104 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 154.193.158.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 23 09:30:25.909186 2025] [security2:error] [pid 20109:tid 20109] [client 154.193.158.104:28990] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||iconbizpromo.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "iconbizpromo.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aUqngeiCfbab9IJ4YL2OYgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
technojoe99
2025-12-22 01:59:00
(9 months ago)
Exploit scan from 154.193.158.104. GET /wp-login.php HTTP/1.1.
Web App Attack
π©πͺ
F242
2025-12-02 20:31:32
(9 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-26 14:05:50
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 154.193.158.104 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 154.193.158.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 09:05:43.547525 2025] [security2:error] [pid 25575:tid 25575] [client 154.193.158.104:22723] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||harwoodmechanical.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "harwoodmechanical.com"] [uri "/wp-login.php"] [unique_id "aScJN-14tgnnZV1yMv8o2gAAAAs"], referer: https://harwoodmechanical.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-17 05:31:12
(10 months ago)
(mod_security) mod_security (id:210350) triggered by 154.193.158.104 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 154.193.158.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 17 00:31:07.266245 2025] [security2:error] [pid 29139:tid 29139] [client 154.193.158.104:10799] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.insidepublications.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.insidepublications.com"] [uri "/wp-login.php"] [unique_id "aRqzG3l77lzp1UHn6k7eRQAAABI"], referer: http://www.insidepublications.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-02 12:45:20
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 154.193.158.104 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 154.193.158.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 02 07:45:14.354559 2025] [security2:error] [pid 7482:tid 7492] [client 154.193.158.104:26739] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||flapjacktoys.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "flapjacktoys.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQdSWsquR1uAKW05Dpx75QAAAMg"], referer: https://flapjacktoys.com
show less
Brute-Force
Bad Web Bot
Web App Attack