๐บ๐ธ
TPI-Abuse
2026-02-13 13:16:51
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.197.27 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.197.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 08:16:47.201060 2026] [security2:error] [pid 15275:tid 15275] [client 156.239.197.27:26966] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.billymitchell.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.billymitchell.com"] [uri "/wordpress/wp-login.php"] [unique_id "aY8kP9jyI6OaTCCcrwc2JgAAAAI"], referer: https://www.billymitchell.com/wordpress/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ps-center
2026-01-30 14:29:49
(7 months ago)
C2: Web Attack GET /wp-login.php
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-28 08:29:39
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.197.27 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.197.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 03:29:33.926822 2025] [security2:error] [pid 20424:tid 20424] [client 156.239.197.27:34270] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.passy.us|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.passy.us"] [uri "/wp-login.php"] [unique_id "aVDqbX5q8r7BIP5JN_NiwQAAAA8"], referer: http://passy.us/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-27 10:19:23
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 156.239.197.27 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 156.239.197.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 05:19:17.755370 2025] [security2:error] [pid 2871:tid 2871] [client 156.239.197.27:40818] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||insidepublications.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "insidepublications.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aU-ypeuCqTS-vMZWgmvrZwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
F242
2025-12-03 01:05:07
(9 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-23 11:04:00
(9 months ago)
(mod_security) mod_security (id:220150) triggered by 156.239.197.27 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:220150) triggered by 156.239.197.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 06:03:22.130682 2025] [security2:error] [pid 29224:tid 29224] [client 156.239.197.27:17653] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:union(?:\\\\/\\\\*.*\\\\*\\\\/)?select)" at ARGS:order. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5671"] [id "220150"] [rev "4"] [msg "COMODO WAF: SQL injection vulnerability in Ginkgo CMS 5.0 (CVE-2013-5318)||kountz.org|F|2"] [data "mname/**//**/or/**/row(2018,1386)>(select/**/count(*),concat(0x62687a69,(select/**/(elt(2836=2836,1))),0x6b445550,floor(rand(0)*2))x/**/from/**/(select/**/2027/**/union/**/select/**/8505/**/union/**/select/**/7491/**/union/**/select/**/4808)a/**/group/**/by/**/x)"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kountz.org"] [uri "/famsearch.php"] [unique_id "aSLp-mEffinP0qGY9HbNGgAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-22 14:04:40
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.197.27 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.197.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 22 09:04:32.070662 2025] [security2:error] [pid 10263:tid 10263] [client 156.239.197.27:19847] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.digi-estudio.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.digi-estudio.com"] [uri "/wp-login.php"] [unique_id "aSHC8L3hZp91TAoWn4VQ_AAAAB4"], referer: http://www.digi-estudio.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-19 01:32:46
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 156.239.197.27 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 156.239.197.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 18 20:32:43.325122 2025] [security2:error] [pid 29866:tid 29866] [client 156.239.197.27:19575] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||insidepublications.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "insidepublications.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aR0eOyzRGTjo5ZBp665kpQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
hostseries
2025-10-02 17:30:01
(11 months ago)
Trigger: LF_DISTATTACK
Brute-Force
๐ฉ๐ช
Vinyamar
2025-08-08 21:39:39
(1 year ago)
VSecCenter: Generic internal Webserver errors detected. | 1 in 24h
Hacking
Anonymous
2025-07-31 14:53:38
(1 year ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.07.31 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.07.31 is noted in report timestamp
show less
Hacking
Brute-Force
๐ณ๐ฑ
GabrielJST
2025-07-21 07:29:44
(1 year ago)
*Port Scan* detected from 156.239.197.27 (US/United States/-).
Port Scan
๐ฌ๐ง
SilverZippo
2025-07-15 21:30:35
(1 year ago)
Web App Attack
Web App Attack
๐ฎ๐ณ
wizard1411
2025-06-15 03:27:18
(1 year ago)
DDoS and brute force activity detected
Brute-Force
SSH