πΊπΈ
TPI-Abuse
2026-02-14 07:33:34
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 154.193.158.150 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 154.193.158.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 02:33:31.011194 2026] [security2:error] [pid 26907:tid 26907] [client 154.193.158.150:15570] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ardath.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ardath.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "aZAlS_obqLWNlPkqnU9_fgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-13 21:05:28
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 154.193.158.150 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 154.193.158.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 16:05:23.269657 2026] [security2:error] [pid 3427467:tid 3427467] [client 154.193.158.150:22282] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.joeordie.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.joeordie.com"] [uri "/wp-login.php"] [unique_id "aY-SE70fHil0ZoAOfVZh1QAAABY"], referer: http://joeordie.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Tilellit.PRO
2026-02-05 15:24:17
(8 months ago)
Fail2Ban banned 154.193.158.150 for security violations in jail wp-armour. Log: 2026/02/05 15:24:17 ...
show more
Fail2Ban banned 154.193.158.150 for security violations in jail wp-armour. Log: 2026/02/05 15:24:17 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 154.193.158.150 | Target: wplogin" , client: 154.193.158.150, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
πΊπΈ
TPI-Abuse
2026-01-23 08:48:42
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 154.193.158.150 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 154.193.158.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 23 03:48:34.772171 2026] [security2:error] [pid 30520:tid 30520] [client 154.193.158.150:40006] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.maffiniandbearce.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.maffiniandbearce.com"] [uri "/wp-login.php"] [unique_id "aXM14nNlVONMDEtx8D-uTQAAABw"], referer: https://www.maffiniandbearce.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-13 01:50:10
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 154.193.158.150 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 154.193.158.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 12 20:50:04.898250 2026] [security2:error] [pid 3496:tid 3496] [client 154.193.158.150:32448] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.wave94.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.wave94.com"] [uri "/wp-login.php"] [unique_id "aWWkzKGGPmVCw6PfzSXj_gAAABo"], referer: https://wave94.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-11 14:18:50
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 154.193.158.150 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 154.193.158.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 11 09:18:44.350799 2026] [security2:error] [pid 5983:tid 5983] [client 154.193.158.150:43094] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||grandpont-house.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "grandpont-house.org"] [uri "/wp-login.php"] [unique_id "aWOxRLeF85hSJ38zw_3__gAAABw"], referer: https://grandpont-house.org/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-04 13:31:14
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 154.193.158.150 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 154.193.158.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 04 08:31:09.016385 2026] [security2:error] [pid 30859:tid 30883] [client 154.193.158.150:24822] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||kettlehill.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "kettlehill.com"] [uri "/wp-login.php"] [unique_id "aVprndrqwybmdRtICp1ykQAAABM"], referer: https://kettlehill.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Packets-Decreaser.NET
2025-12-31 00:58:57
(9 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
πΊπΈ
TPI-Abuse
2025-12-28 06:46:12
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 154.193.158.150 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 154.193.158.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 01:46:06.409990 2025] [security2:error] [pid 24250:tid 24250] [client 154.193.158.150:12454] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.mavikalem.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.mavikalem.org"] [uri "/wp-login.php"] [unique_id "aVDSLkKOCByvMzwHp8_KigAAAAc"], referer: https://www.mavikalem.org/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Jaime
2025-12-24 19:36:02
(9 months ago)
This day 1 times ... Access forbidden - 403: - ... /wp-login.php
Brute-Force
πΊπΈ
TPI-Abuse
2025-12-23 07:47:30
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 154.193.158.150 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 154.193.158.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 23 02:47:22.960804 2025] [security2:error] [pid 14952:tid 14952] [client 154.193.158.150:23276] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||casadelsolmexico.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "casadelsolmexico.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "aUpJCh4AOKVHLL9oQBj3TgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-23 00:01:44
(9 months ago)
Failed Wordpress login
Hacking
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-23 03:18:13
(10 months ago)
(mod_security) mod_security (id:210350) triggered by 154.193.158.150 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 154.193.158.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 22 22:18:07.026433 2025] [security2:error] [pid 24870:tid 24870] [client 154.193.158.150:42573] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.whatyouhear.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.whatyouhear.com"] [uri "/wp-login.php"] [unique_id "aSJ879ssbS89gFLdpl97OwAAAAg"], referer: https://www.whatyouhear.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-22 05:44:38
(10 months ago)
(mod_security) mod_security (id:210350) triggered by 154.193.158.150 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 154.193.158.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 22 00:44:33.786330 2025] [security2:error] [pid 32231:tid 32231] [client 154.193.158.150:30033] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.livingminimal.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.livingminimal.com"] [uri "/wp-login.php"] [unique_id "aSFNwa8inlblfP5AZgh2kgAAAB8"], referer: http://www.livingminimal.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-16 13:50:33
(10 months ago)
(mod_security) mod_security (id:210350) triggered by 154.193.158.150 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 154.193.158.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 16 08:50:26.191858 2025] [security2:error] [pid 20940:tid 20940] [client 154.193.158.150:18365] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||kawkacevents.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "kawkacevents.com"] [uri "/wp-login.php"] [unique_id "aRnWolRxi0TkklHttjgiggAAACc"], referer: http://kawkacevents.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack