๐บ๐ธ
TPI-Abuse
2026-03-03 18:43:37
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.197.101 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.197.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 03 13:43:31.517947 2026] [security2:error] [pid 9759:tid 9759] [client 156.239.197.101:21574] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.controvac.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.controvac.com"] [uri "/wp-login.php"] [unique_id "aacr0wlDkv-LARN0XbIX2gAAAAM"], referer: https://controvac.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-06 15:47:22
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.197.101 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.197.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 06 10:47:14.195441 2026] [security2:error] [pid 3671:tid 3671] [client 156.239.197.101:38360] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||iconconstructors.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "iconconstructors.com"] [uri "/wp-login.php"] [unique_id "aYYNAgK2bipk1wV92c9yWQAAAAE"], referer: http://iconconstructors.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-22 14:40:26
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 156.239.197.101 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.239.197.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 09:40:20.277740 2026] [security2:error] [pid 2061049:tid 2061049] [client 156.239.197.101:28600] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dalessalesandservice.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dalessalesandservice.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aXI21Pgfmyvh3ODE5MFrZwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-13 14:21:10
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.197.101 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.197.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 13 09:21:00.968266 2026] [security2:error] [pid 17400:tid 17400] [client 156.239.197.101:56644] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.josephshv.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.josephshv.com"] [uri "/wp-login.php"] [unique_id "aWZUzHWMIe8h-R2BuQUXbgAAAAE"], referer: http://josephshv.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-07 12:44:10
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 156.239.197.101 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.239.197.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 07 07:44:06.330565 2026] [security2:error] [pid 20573:tid 20573] [client 156.239.197.101:22598] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.creationorevolution.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.creationorevolution.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "aV5VFrJoDmHaPAO6rRm8xQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-23 12:53:36
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 156.239.197.101 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.239.197.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 23 07:53:31.699528 2025] [security2:error] [pid 31646:tid 31646] [client 156.239.197.101:36662] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rannals.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rannals.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aUqQy71bRZsUiByePPbnZQAAAAE"], referer: https://rannals.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-16 14:46:38
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.197.101 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.197.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 16 09:46:32.915039 2025] [security2:error] [pid 6858:tid 6858] [client 156.239.197.101:28573] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.insidepublications.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.insidepublications.com"] [uri "/wp-login.php"] [unique_id "aRnjyEf_Xup4qEXhuZp-CwAAAAc"], referer: http://www.insidepublications.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-13 23:39:01
(10 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.197.101 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.197.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 18:38:55.652342 2025] [security2:error] [pid 16354:tid 16354] [client 156.239.197.101:29667] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.fundaciondamashcc.org.ec|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.fundaciondamashcc.org.ec"] [uri "/wp-login.php"] [unique_id "aRZsDzKHB9Bw0SJyVLgwjwAAAAg"], referer: http://www.fundaciondamashcc.org.ec/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-07-31 18:50:35
(1 year ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.07.31 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.07.31 is noted in report timestamp
show less
Hacking
Brute-Force
๐ฌ๐ง
D3monite
2025-07-27 06:02:55
(1 year ago)
Attempted Brute Force (cpaneld)
Brute-Force
๐ฎ๐ณ
wizard1411
2025-06-15 03:22:17
(1 year ago)
DDoS and brute force activity detected
Brute-Force
SSH
๐ช๐ธ
el-brujo
2025-06-14 12:48:21
(1 year ago)
06/14/2025-14:48:21.685582 156.239.197.101 Protocol: 6 ET SCAN Potential SSH Scan
Port Scan
Anonymous
2025-06-11 00:21:12
(1 year ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
๐บ๐ธ
TPI-Abuse
2025-04-12 16:54:42
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 156.239.197.101 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.239.197.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 12 12:54:38.504507 2025] [security2:error] [pid 16840:tid 16840] [client 156.239.197.101:60917] [client 156.239.197.101] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||vaezi.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "vaezi.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z_qazsfomRBZifek0dKNfgAAABE"], referer: https://vaezi.com
show less
Brute-Force
Bad Web Bot
Web App Attack