๐บ๐ธ
TPI-Abuse
2026-02-26 14:22:53
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 154.199.69.111 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 154.199.69.111 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 26 09:22:47.730801 2026] [security2:error] [pid 26249:tid 26249] [client 154.199.69.111:53122] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thehandyfamily.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thehandyfamily.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aaBXN_Uu8c-QkIUBP4aK0wAAAAg"], referer: https://thehandyfamily.net
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-02-08 14:21:12
(7 months ago)
Fail2Ban banned 154.199.69.111 for security violations in jail wp-armour. Log: 2026/02/08 14:21:11 [ ...
show more
Fail2Ban banned 154.199.69.111 for security violations in jail wp-armour. Log: 2026/02/08 14:21:11 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 154.199.69.111 | Target: wplogin" , client: 154.199.69.111, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐บ๐ธ
TPI-Abuse
2026-02-05 22:34:49
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 154.199.69.111 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.199.69.111 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 05 17:34:41.991958 2026] [security2:error] [pid 14130:tid 14130] [client 154.199.69.111:45210] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||primacomm.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "primacomm.com"] [uri "/wp-login.php"] [unique_id "aYUbAUihzcq0gE1NwHUmlQAAAAg"], referer: https://primacomm.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-01-19 22:02:17
(8 months ago)
wordpress-trap
Web App Attack
Anonymous
2026-01-13 13:31:44
(8 months ago)
Failed Wordpress login
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-05 03:14:59
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 154.199.69.111 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.199.69.111 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 04 22:14:55.779579 2026] [security2:error] [pid 6769:tid 6769] [client 154.199.69.111:16128] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||lawrencehale.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "lawrencehale.com"] [uri "/wp-login.php"] [unique_id "aVssrwr0jySVf-qu9p2t2wAAAAw"], referer: https://lawrencehale.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-31 00:58:37
(8 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐ซ๐ท
COMAITE
2025-12-23 08:01:43
(8 months ago)
SQL injection attempt from 154.199.69.111.
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-21 23:01:36
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 154.199.69.111 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.199.69.111 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 21 18:01:28.821801 2025] [security2:error] [pid 18405:tid 18405] [client 154.199.69.111:29768] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||drdot.xyz|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "drdot.xyz"] [uri "/wp-login.php"] [unique_id "aUh8SOEpXgvQFySeZkjq0wAAAAU"], referer: http://drdot.xyz/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-15 19:30:10
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 154.199.69.111 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 154.199.69.111 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 15 14:30:07.107527 2025] [security2:error] [pid 30815:tid 30815] [client 154.199.69.111:12812] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||iconconstructors.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "iconconstructors.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aUBhv0kllQIhFsdsON8rWgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-20 18:44:16
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 154.199.69.111 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 154.199.69.111 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 20 13:44:10.996970 2025] [security2:error] [pid 4584:tid 4584] [client 154.199.69.111:38429] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fnavarro.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fnavarro.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aR9hekRA3qxrGUHi9vo0ZwAAAAE"], referer: https://fnavarro.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-15 22:09:00
(10 months ago)
(mod_security) mod_security (id:210350) triggered by 154.199.69.111 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.199.69.111 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 15 17:08:48.083123 2025] [security2:error] [pid 25787:tid 25810] [client 154.199.69.111:31139] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.asetiadi.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.asetiadi.net"] [uri "/wp-login.php"] [unique_id "aRj58C1fdNXYN8Jc_nSKsgAAAFQ"], referer: http://www.asetiadi.net/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-13 18:24:00
(10 months ago)
(mod_security) mod_security (id:210350) triggered by 154.199.69.111 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.199.69.111 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 13:23:54.298803 2025] [security2:error] [pid 17455:tid 17455] [client 154.199.69.111:24379] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||jolankagroup.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "jolankagroup.com"] [uri "/wp-login.php"] [unique_id "aRYiOnIgAWidMxLrr4IeowAAABc"], referer: http://jolankagroup.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2025-11-09 21:40:03
(10 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
secmon-bf
2025-08-12 05:03:54
(1 year ago)
Attempted to exploit a web server vulnerability.
Web App Attack