๐บ๐ธ
TPI-Abuse
2026-02-18 09:01:35
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 156.239.194.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.239.194.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 04:01:27.671005 2026] [security2:error] [pid 9552:tid 9552] [client 156.239.194.193:22924] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||arapi.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "arapi.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "aZV_51X350je8hrGDmKy2AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-16 09:37:36
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 156.239.194.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.239.194.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 16 04:37:31.719855 2026] [security2:error] [pid 2072754:tid 2072754] [client 156.239.194.193:11686] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kerrywood.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kerrywood.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aZLlW71rf_WLEdyOQLq3wwAAAAM"], referer: https://kerrywood.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2026-01-17 21:09:34
(7 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2026-01-11 02:58:32
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.194.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.194.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 10 21:58:25.742848 2026] [security2:error] [pid 1585:tid 1585] [client 156.239.194.193:46314] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||eye7graphics.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "eye7graphics.com"] [uri "/wp-login.php"] [unique_id "aWMR0akJY1QwCOIRU2b4QQAAAAQ"], referer: http://eye7graphics.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-01 22:52:36
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 156.239.194.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.239.194.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 01 17:52:29.154610 2026] [security2:error] [pid 7003:tid 7003] [client 156.239.194.193:10824] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tankservicesinc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tankservicesinc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aVb6rcjeE2K1dq0tNJLH3wAAACA"], referer: https://tankservicesinc.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-31 15:09:55
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 156.239.194.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.239.194.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 31 10:09:49.278230 2025] [security2:error] [pid 26941:tid 26941] [client 156.239.194.193:32472] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||stardancertantra.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "stardancertantra.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aVU8vXX3UieahzmnQgjxDgAAAA8"], referer: https://stardancertantra.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-27 06:56:53
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.194.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.194.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 01:56:49.444327 2025] [security2:error] [pid 21572:tid 21572] [client 156.239.194.193:58736] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.staben.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.staben.com"] [uri "/wp-login.php"] [unique_id "aU-DMaSN6bdmhuJevikNygAAAAM"], referer: https://www.staben.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-19 20:17:54
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.194.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.194.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 19 15:17:48.879690 2025] [security2:error] [pid 11869:tid 11869] [client 156.239.194.193:56556] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.stalbansparish.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.stalbansparish.org"] [uri "/wp-login.php"] [unique_id "aUWy7EpLszqyNMEx_L91JgAAAAM"], referer: https://www.stalbansparish.org/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FutureFm
2025-11-02 09:45:00
(10 months ago)
156.239.194.193 - - [02/Nov/2025:09:46:50 +0100] "POST /wp-login.php
156.239.194.193 - - [02/Nov/20 ...
show more
156.239.194.193 - - [02/Nov/2025:09:46:50 +0100] "POST /wp-login.php
156.239.194.193 - - [02/Nov/2025:09:46:51 +0100] "GET /wp-admin/
show less
Hacking
Brute-Force
Anonymous
2025-07-31 20:25:29
(1 year ago)
Attempted brute force login to web vpn 4 time(s); last attempt for 2025.07.31 is noted in report tim ...
show more
Attempted brute force login to web vpn 4 time(s); last attempt for 2025.07.31 is noted in report timestamp
show less
Hacking
Brute-Force
๐ฎ๐ณ
wizard1411
2025-06-15 03:20:35
(1 year ago)
DDoS and brute force activity detected
Brute-Force
SSH
๐ฉ๐ช
Packets-Decreaser.NET
2025-05-04 16:13:15
(1 year ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
inspectorgdgt
2025-04-12 22:48:38
(1 year ago)
Multiple failed SSL VPN login attempts from 156.239.194.193
Brute-Force