๐บ๐ธ
TPI-Abuse
2026-01-25 12:18:07
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 156.239.199.209 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.239.199.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 25 07:18:01.316454 2026] [security2:error] [pid 22617:tid 22617] [client 156.239.199.209:50892] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||assheton.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "assheton.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aXYJ-bPBk6ggrWUFwKhkMAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-14 19:53:26
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 156.239.199.209 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.239.199.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 14 14:53:18.510614 2026] [security2:error] [pid 28060:tid 28060] [client 156.239.199.209:54732] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||accommodation-perthairport.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "accommodation-perthairport.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aWf0Lim__MGekBLQhL8fRwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-11 06:39:49
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.199.209 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.199.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 11 01:39:44.063340 2026] [security2:error] [pid 30009:tid 30009] [client 156.239.199.209:29092] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.whatyouhear.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.whatyouhear.com"] [uri "/wp-login.php"] [unique_id "aWNFsI48_tNWY8SpkWvFWAAAAA4"], referer: https://www.whatyouhear.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-28 09:22:05
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.199.209 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.199.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 04:22:00.550848 2025] [security2:error] [pid 28437:tid 28437] [client 156.239.199.209:47760] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||kawkacevents.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "kawkacevents.com"] [uri "/wp-login.php"] [unique_id "aVD2uKIcoLFQXg_Pn7wovwAAAAc"], referer: http://kawkacevents.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-24 19:14:47
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.199.209 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.199.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 24 14:14:42.363590 2025] [security2:error] [pid 1739:tid 1739] [client 156.239.199.209:21708] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.the-it-man.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.the-it-man.com"] [uri "/wp-login.php"] [unique_id "aUw7ohxwVXsnnO_qqk-WGQAAAAM"], referer: https://www.the-it-man.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-20 00:51:28
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.199.209 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.199.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 19 19:51:21.006695 2025] [security2:error] [pid 1241:tid 1241] [client 156.239.199.209:60788] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||drdot.xyz|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "drdot.xyz"] [uri "/wp-login.php"] [unique_id "aUXzCaLGySfkkh3Udl0IwQAAAAQ"], referer: http://drdot.xyz/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-18 03:51:18
(8 months ago)
wordpress-trap
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 09:30:15
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.199.209 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.199.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:30:07.915531 2025] [security2:error] [pid 11991:tid 11991] [client 156.239.199.209:35299] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||barigby.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "barigby.com"] [uri "/wp-login.php"] [unique_id "aSQln2x6T_kP8irMY47jkgAAAAk"], referer: https://barigby.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-19 01:05:45
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.199.209 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.199.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 18 20:05:38.535987 2025] [security2:error] [pid 10984:tid 10984] [client 156.239.199.209:9673] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.insidepublications.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.insidepublications.com"] [uri "/wp-login.php"] [unique_id "aR0X4rfmwGEQRGcpDNyQJAAAAAc"], referer: http://insidepublications.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-18 06:54:04
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.199.209 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.199.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 18 01:53:56.605303 2025] [security2:error] [pid 9170:tid 9170] [client 156.239.199.209:19335] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||cms2020.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "cms2020.com"] [uri "/wp-login.php"] [unique_id "aRwYBIs5m_cBopubNjOyrwAAABE"], referer: http://cms2020.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
hostseries
2025-10-01 22:36:09
(11 months ago)
Trigger: LF_DISTATTACK
Brute-Force
๐ณ๐ฑ
GabrielJST
2025-08-15 07:13:48
(1 year ago)
*Port Scan* detected from 156.239.199.209 (US/United States/-).
Port Scan
Anonymous
2025-07-31 21:02:45
(1 year ago)
Attempted brute force login to web vpn 4 time(s); last attempt for 2025.07.31 is noted in report tim ...
show more
Attempted brute force login to web vpn 4 time(s); last attempt for 2025.07.31 is noted in report timestamp
show less
Hacking
Brute-Force
๐ฎ๐ณ
wizard1411
2025-06-14 16:52:38
(1 year ago)
DDoS and brute force activity detected
Brute-Force
SSH