๐บ๐ธ
TPI-Abuse
2026-03-04 21:04:05
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 154.199.14.85 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 154.199.14.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 04 16:04:00.812293 2026] [security2:error] [pid 4868:tid 4868] [client 154.199.14.85:41148] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.digi-estudio.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.digi-estudio.com"] [uri "/wp-login.php"] [unique_id "aaieQAG4OqYmQwR_IxlF9gAAAAQ"], referer: http://digi-estudio.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
gnom4ik
2026-02-21 13:47:28
(5 months ago)
ban-reviewer auto report; ip=154.199.14.85; scenario=http:exploit; verdict=valid_ban; confidence=0.9 ...
show more
ban-reviewer auto report; ip=154.199.14.85; scenario=http:exploit; verdict=valid_ban; confidence=0.90; categories=14,15,18; active_decisions=1; lookback_decisions=1; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=IP flagged for HTTP exploit scenario; Active decision count is low but within expected range for new ban; No evidence of legitimate activity in summary data
show less
Port Scan
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-02-10 08:40:09
(5 months ago)
(mod_security) mod_security (id:210350) triggered by 154.199.14.85 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 154.199.14.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 03:40:03.231377 2026] [security2:error] [pid 2555538:tid 2555538] [client 154.199.14.85:36134] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||jolankagroup.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "jolankagroup.com"] [uri "/wp-login.php"] [unique_id "aYru49ISST2soR7ZgP_sLAAAAAA"], referer: http://jolankagroup.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 03:22:29
(5 months ago)
(mod_security) mod_security (id:210350) triggered by 154.199.14.85 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 154.199.14.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 22:22:25.662094 2026] [security2:error] [pid 4617:tid 4617] [client 154.199.14.85:35666] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.schlegelcreative.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.schlegelcreative.com"] [uri "/wp-login.php"] [unique_id "aYqkccqdY4keID4v4D5zpAAAAAw"], referer: https://schlegelcreative.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 00:09:25
(5 months ago)
(mod_security) mod_security (id:210350) triggered by 154.199.14.85 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 154.199.14.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 19:09:18.450092 2026] [security2:error] [pid 554:tid 554] [client 154.199.14.85:11744] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.nekstlevel.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.nekstlevel.com"] [uri "/wp-login.php"] [unique_id "aYp3LtExMq-hc2Wph4nn4AAAAAo"], referer: https://www.nekstlevel.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
i-turnradio.nl
2026-01-30 08:21:25
(5 months ago)
2026-01-30 09:21:25 (CET) ~ Blocked by abusescan risk assessment
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-16 07:51:11
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 154.199.14.85 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 154.199.14.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 02:51:04.648169 2026] [security2:error] [pid 6440:tid 6440] [client 154.199.14.85:51408] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||belintxon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "belintxon.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aWnt6GZXKcalFCrKoaC_qgAAAA4"], referer: https://belintxon.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-13 13:13:28
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 154.199.14.85 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 154.199.14.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 13 08:13:21.833046 2026] [security2:error] [pid 2088494:tid 2088494] [client 154.199.14.85:22352] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.staben.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.staben.com"] [uri "/wp-login.php"] [unique_id "aWZE8bvXzhh6V7yVxy59_AAAAAI"], referer: https://www.staben.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-31 00:59:07
(6 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐ฆ๐บ
weblite
2025-12-29 17:13:38
(6 months ago)
LONG_RUNNING_WP_BRUTE_FORCE
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-28 14:35:55
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 154.199.14.85 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 154.199.14.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 09:35:50.153394 2025] [security2:error] [pid 11082:tid 11082] [client 154.199.14.85:40042] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||activethinkers.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "activethinkers.net"] [uri "/wp-login.php"] [unique_id "aVFARmgFhVLaeFFRTsO4EwAAAAw"], referer: https://activethinkers.net/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-23 21:31:47
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 154.199.14.85 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 154.199.14.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 23 16:31:39.596257 2025] [security2:error] [pid 22916:tid 22920] [client 154.199.14.85:28542] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||pref-realestate.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "pref-realestate.com"] [uri "/wp-login.php"] [unique_id "aUsKO2C_3O1lSjxmdI5YNQAAAEE"], referer: https://pref-realestate.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-23 11:15:56
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 154.199.14.85 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 154.199.14.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 23 06:15:50.669434 2025] [security2:error] [pid 9851:tid 9851] [client 154.199.14.85:24826] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.naominixon.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.naominixon.com"] [uri "/wp-login.php"] [unique_id "aUp55k4zZPoCaP6bP7o7ZwAAAAQ"], referer: http://www.naominixon.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2025-12-13 16:57:07
(7 months ago)
(wordpress) Failed wordpress login from 154.199.14.85 (NL/The Netherlands/North Holland/Amsterdam/-/ ...
show more
(wordpress) Failed wordpress login from 154.199.14.85 (NL/The Netherlands/North Holland/Amsterdam/-/[redacted])
show less
Brute-Force
๐ฉ๐ช
F242
2025-12-03 17:07:20
(7 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack