๐บ๐ธ
TPI-Abuse
2026-02-14 02:18:53
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 154.199.68.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.199.68.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 21:18:48.245648 2026] [security2:error] [pid 31857:tid 31857] [client 154.199.68.181:31846] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.billymitchell.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.billymitchell.com"] [uri "/wordpress/wp-login.php"] [unique_id "aY_biP1DnpzCJ5nIw9jnKgAAAAM"], referer: https://www.billymitchell.com/wordpress/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-06 14:47:08
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 154.199.68.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.199.68.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 06 09:47:04.742875 2026] [security2:error] [pid 2314372:tid 2314372] [client 154.199.68.181:12636] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.kerrywood.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.kerrywood.com"] [uri "/wp-login.php"] [unique_id "aYX-6B8tnGVtKr03cG6U6AAAAA4"], referer: https://kerrywood.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-06 09:35:12
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 154.199.68.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.199.68.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 06 04:35:04.562602 2026] [security2:error] [pid 1541:tid 1541] [client 154.199.68.181:48170] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.whatyouhear.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.whatyouhear.com"] [uri "/wp-login.php"] [unique_id "aYW1yNIODJGh_o0BbeE3HAAAAAw"], referer: https://www.whatyouhear.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-15 14:13:44
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 154.199.68.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 154.199.68.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 15 09:13:40.854572 2026] [security2:error] [pid 14868:tid 14868] [client 154.199.68.181:33570] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dmasoftlab.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dmasoftlab.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aWj2FIJrrLRxnEmUld6vMAAAAAA"], referer: https://dmasoftlab.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-06 02:29:54
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 154.199.68.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 154.199.68.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 05 21:29:48.972769 2026] [security2:error] [pid 11850:tid 11850] [client 154.199.68.181:47024] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||plaisance.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "plaisance.us"] [uri "/wp-json/wp/v2/users"] [unique_id "aVxznPi71sLVujoFM-hCLgAAAA8"], referer: https://plaisance.us
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-31 00:59:17
(9 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-12-29 00:05:42
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 154.199.68.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.199.68.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 19:05:36.301338 2025] [security2:error] [pid 16508:tid 16508] [client 154.199.68.181:36876] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||eye7graphics.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "eye7graphics.com"] [uri "/wp-login.php"] [unique_id "aVHF0BxSuGNhvSCb5OJ6lAAAABc"], referer: http://eye7graphics.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-26 15:37:05
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 154.199.68.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.199.68.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 26 10:36:57.374041 2025] [security2:error] [pid 17316:tid 17316] [client 154.199.68.181:51584] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||primacomm.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "primacomm.com"] [uri "/wp-login.php"] [unique_id "aU6rmdzOfeIqDugSNIwtDAAAAAI"], referer: https://primacomm.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-19 21:07:42
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 154.199.68.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.199.68.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 19 16:07:38.913868 2025] [security2:error] [pid 26014:tid 26014] [client 154.199.68.181:18422] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.vanmeer.info|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.vanmeer.info"] [uri "/wp-login.php"] [unique_id "aUW-mmNu7CaGgabIhulXpAAAABg"], referer: http://www.vanmeer.info/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-18 06:32:11
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 154.199.68.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.199.68.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 18 01:32:06.054731 2025] [security2:error] [pid 7994:tid 7994] [client 154.199.68.181:44360] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.josephshv.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.josephshv.com"] [uri "/wp-login.php"] [unique_id "aUOf5mYp3ZyAszXs23tpagAAAAY"], referer: http://www.josephshv.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Jaime
2025-12-18 05:55:52
(9 months ago)
This day 1 times ... Access forbidden - 403: - ... /wp-login.php
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-12-07 14:06:24
(10 months ago)
(mod_security) mod_security (id:210350) triggered by 154.199.68.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.199.68.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 09:06:15.963096 2025] [security2:error] [pid 28296:tid 28296] [client 154.199.68.181:44218] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.staben.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.staben.com"] [uri "/wp-login.php"] [unique_id "aTWJ13-50W8Zk3f9eMtHOgAAAAk"], referer: https://www.staben.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-29 03:52:26
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 154.199.68.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 154.199.68.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 28 22:52:21.971666 2025] [security2:error] [pid 27716:tid 27716] [client 154.199.68.181:37029] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||persnicketyinc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "persnicketyinc.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aSpt9cOYnQIpCTDz11Vb_gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
london2038.com
2025-11-28 05:28:57
(10 months ago)
Detected by WP fail2ban
2025-11-28T06:28:56.549418+01:00 wordpress: Authentication attempt from 154. ...
show more
Detected by WP fail2ban
2025-11-28T06:28:56.549418+01:00 wordpress: Authentication attempt from 154.199.68.181
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-23 06:53:56
(10 months ago)
(mod_security) mod_security (id:210350) triggered by 154.199.68.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.199.68.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 01:53:52.330966 2025] [security2:error] [pid 2076664:tid 2076664] [client 154.199.68.181:18915] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||grandpont-house.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "grandpont-house.org"] [uri "/wp-login.php"] [unique_id "aSKvgHYWp0rqXCfzVuDQrQAAAA8"], referer: https://grandpont-house.org/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack