๐บ๐ธ
TPI-Abuse
2026-02-11 15:10:44
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 154.193.159.14 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.193.159.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 10:10:37.921881 2026] [security2:error] [pid 3791:tid 3791] [client 154.193.159.14:48702] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||arthuryeung.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "arthuryeung.net"] [uri "/wp-login.php"] [unique_id "aYyb7TIdWm4S5us6OOS2qgAAAAw"], referer: http://arthuryeung.net/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-26 16:33:41
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 154.193.159.14 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.193.159.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 26 11:33:34.272489 2026] [security2:error] [pid 23252:tid 23259] [client 154.193.159.14:12876] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||victorchiarizia.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "victorchiarizia.com"] [uri "/wp-login.php"] [unique_id "aXeXXtQMRqmEZfsJeYE3RgAAAQU"], referer: http://www.victorchiarizia.com//wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-16 10:21:22
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 154.193.159.14 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 154.193.159.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 05:21:16.171596 2026] [security2:error] [pid 5195:tid 5195] [client 154.193.159.14:31640] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mp3tracks.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mp3tracks.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aWoRHGLOUEeWlawdTOKpegAAABM"], referer: https://mp3tracks.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-12 21:48:32
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 154.193.159.14 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.193.159.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 12 16:48:25.184102 2026] [security2:error] [pid 30963:tid 30963] [client 154.193.159.14:35820] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||lawrencehale.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "lawrencehale.com"] [uri "/wp-login.php"] [unique_id "aWVsKa1TVCWhgdoZC5Jf0wAAABQ"], referer: https://lawrencehale.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-12 10:30:19
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 154.193.159.14 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 154.193.159.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 12 05:30:13.615951 2026] [security2:error] [pid 23140:tid 23140] [client 154.193.159.14:55038] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||insidepublications.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "insidepublications.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aWTNNYxlAbYSiunTyby5JwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
smithclass.net
2026-01-08 07:06:20
(8 months ago)
Jan 8 07:06:20 gravy wordpress(lallygag.net)[731375]: Blocked authentication attempt for admin from ...
show more
Jan 8 07:06:20 gravy wordpress(lallygag.net)[731375]: Blocked authentication attempt for admin from 154.193.159.14
...
show less
Hacking
Brute-Force
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-31 00:58:47
(9 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-12-23 21:44:32
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 154.193.159.14 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.193.159.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 23 16:44:25.474548 2025] [security2:error] [pid 1132:tid 1132] [client 154.193.159.14:34650] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||jolankagroup.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "jolankagroup.com"] [uri "/wp-login.php"] [unique_id "aUsNOaaL5xDAA7u5ULqrVQAAAAs"], referer: http://jolankagroup.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Jaime
2025-12-21 21:53:06
(9 months ago)
This day 1 times ... Access forbidden - 403: - ... /wp-login.php
Brute-Force
Anonymous
2025-11-25 17:33:41
(10 months ago)
wordpress-trap
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-21 18:45:37
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 154.193.159.14 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 154.193.159.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 21 13:45:33.405040 2025] [security2:error] [pid 3977:tid 3977] [client 154.193.159.14:22247] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||blindshine.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "blindshine.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aSCzTSsap4C-Uztl4Usy1QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
stinpriza
2025-11-16 04:31:26
(10 months ago)
Web App Attack
Web App Attack
๐จ๐ญ
backslash
2025-09-30 18:40:23
(1 year ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
๐ท๐ด
clauss
2025-09-22 21:22:35
(1 year ago)
IP reached maximum auth failures for a one day block
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-06-24 06:20:11
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 154.193.159.14 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 154.193.159.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 24 02:20:04.499644 2025] [security2:error] [pid 1946889:tid 1946889] [client 154.193.159.14:28771] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||flamberge.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "flamberge.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aFpDlGqsDWO-hduBQhwX6AAAAAg"], referer: https://flamberge.com
show less
Brute-Force
Bad Web Bot
Web App Attack