๐บ๐ธ
TPI-Abuse
2026-02-11 23:35:42
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 154.86.113.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.86.113.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 18:35:38.442108 2026] [security2:error] [pid 1036649:tid 1036649] [client 154.86.113.217:21546] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||jolankagroup.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "jolankagroup.com"] [uri "/wp-login.php"] [unique_id "aY0SSmB79ToL11mNnLXngAAAAAc"], referer: http://jolankagroup.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-11 22:26:01
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 154.86.113.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 154.86.113.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 17:25:57.227410 2026] [security2:error] [pid 26169:tid 26169] [client 154.86.113.217:27096] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.allotrope.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.allotrope.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aY0B9VedpQjQvNlLJ7kqLAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 00:30:39
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 154.86.113.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.86.113.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 08 19:30:31.893132 2026] [security2:error] [pid 1692:tid 1692] [client 154.86.113.217:15040] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.hodlmoser.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.hodlmoser.com"] [uri "/wp-login.php"] [unique_id "aYkqp8kzEvOpkVTAtvVpWgAAABQ"], referer: http://hodlmoser.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-05 12:09:11
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 154.86.113.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.86.113.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 05 07:09:03.715746 2026] [security2:error] [pid 20122:tid 20122] [client 154.86.113.217:25430] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.schlegelcreative.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.schlegelcreative.com"] [uri "/wp-login.php"] [unique_id "aYSIXw713blzZEFrcnPSFwAAABQ"], referer: https://schlegelcreative.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2026-01-17 21:08:29
(8 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2026-01-16 11:14:17
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 154.86.113.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 154.86.113.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 06:14:11.331936 2026] [security2:error] [pid 23432:tid 23432] [client 154.86.113.217:43688] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||method1.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "method1.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "aWodg5cZFSmcBhQkXKKqcwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-01-15 19:25:04
(8 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐ธ๐ฌ
ANTI SCANNER
2026-01-08 15:58:56
(8 months ago)
Scanner : /xmlrpc.php
Web Spam
๐บ๐ธ
TPI-Abuse
2025-12-28 08:19:02
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 154.86.113.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.86.113.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 03:18:55.108945 2025] [security2:error] [pid 24448:tid 24448] [client 154.86.113.217:57402] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.insidepublications.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.insidepublications.com"] [uri "/wp-login.php"] [unique_id "aVDn715WivFzxuA4gSwH_gAAAAk"], referer: http://www.insidepublications.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-28 07:10:57
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 154.86.113.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.86.113.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 02:10:54.125792 2025] [security2:error] [pid 28858:tid 28858] [client 154.86.113.217:57940] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||schmitzcomm.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "schmitzcomm.net"] [uri "/wp-login.php"] [unique_id "aVDX_t0IYxstYsD8Wx0vKAAAABk"], referer: http://schmitzcomm.net/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-22 22:12:22
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 154.86.113.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.86.113.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 22 17:12:19.391938 2025] [security2:error] [pid 8179:tid 8179] [client 154.86.113.217:13268] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.kawkacevents.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.kawkacevents.com"] [uri "/wp-login.php"] [unique_id "aUnCQ6aQjvnYJPlZLzTvAwAAABA"], referer: http://www.kawkacevents.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2025-12-20 06:07:21
(9 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 154.86.113.217 (NL/The Netherlands/ ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 154.86.113.217 (NL/The Netherlands/-): 1 in the last 3600 secs
show less
Web App Attack
๐ฉ๐ช
Jaime
2025-12-18 13:41:44
(9 months ago)
This day 1 times ... Access forbidden - 403: - ... /wp-login.php
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-12-02 19:44:57
(10 months ago)
(mod_security) mod_security (id:210350) triggered by 154.86.113.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.86.113.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 14:44:49.406258 2025] [security2:error] [pid 31442:tid 31442] [client 154.86.113.217:33675] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.humbliaslaw.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.humbliaslaw.com"] [uri "/wp-login.php"] [unique_id "aS9BscfbL0OaTqr6Cl-KnAAAAAs"], referer: http://www.humbliaslaw.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
F242
2025-12-02 16:44:29
(10 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack