Anonymous
2026-01-11 16:46:44
(7 months ago)
Failed Wordpress login
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-27 15:31:26
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.199.8 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.199.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 10:31:18.573839 2025] [security2:error] [pid 4419:tid 4518] [client 156.239.199.8:10006] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||pref-realestate.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "pref-realestate.com"] [uri "/wp-login.php"] [unique_id "aU_7xs15vEZHlPu98DPrMAAAAAM"], referer: https://pref-realestate.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-27 14:08:13
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 156.239.199.8 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 156.239.199.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 09:08:09.529829 2025] [security2:error] [pid 28814:tid 28814] [client 156.239.199.8:13216] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kawkacevents.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kawkacevents.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aU_oSTUEwZZxodd6c3UBXAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-23 15:41:44
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.199.8 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.199.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 23 10:41:36.893756 2025] [security2:error] [pid 9669:tid 9669] [client 156.239.199.8:22896] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.texaslawman.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.texaslawman.net"] [uri "/wp-login.php"] [unique_id "aUq4MA5haYc6jH3545kf8wAAAAM"], referer: http://texaslawman.net/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-11 14:00:35
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.199.8 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.199.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 11 09:00:30.045815 2025] [security2:error] [pid 22104:tid 22129] [client 156.239.199.8:46576] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||heworeblack.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "heworeblack.com"] [uri "/wp-login.php"] [unique_id "aTrOflLvBjwnRA56Snd8ngAAAVc"], referer: http://heworeblack.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2025-11-21 02:51:04
(9 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 04-51.156.239.199.8.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 04-51.156.239.199.8.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ฑ๐ป
garmtech.com
2025-11-20 19:21:43
(9 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 21-21.156.239.199.8.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 21-21.156.239.199.8.web-spammers.v2.rbl.imunify.com. succeeded.
show less
Web App Attack
๐ฑ๐ป
garmtech.com
2025-11-20 01:11:36
(9 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 03-11.156.239.199.8.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 03-11.156.239.199.8.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-18 23:44:56
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.199.8 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.199.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 18 18:44:51.304898 2025] [security2:error] [pid 32383:tid 32383] [client 156.239.199.8:48261] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||geckoturner.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "geckoturner.com"] [uri "/wp-login.php"] [unique_id "aR0E82hoY9IZRyAzR-f81wAAAAE"], referer: http://geckoturner.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2025-11-18 19:05:52
(9 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 21-05.156.239.199.8.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 21-05.156.239.199.8.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-16 15:25:55
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 156.239.199.8 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 156.239.199.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 16 10:25:48.961037 2025] [security2:error] [pid 9198:tid 9198] [client 156.239.199.8:24359] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jolankagroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jolankagroup.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aRns_I-ysPPwIi4LffAcQgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
SilverZippo
2025-11-14 05:34:10
(9 months ago)
Web App Attack
Web App Attack
๐ง๐ท
hostseries
2025-10-02 13:37:23
(10 months ago)
Trigger: LF_DISTATTACK
Brute-Force
Anonymous
2025-07-31 16:34:57
(1 year ago)
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.07.31 is noted in report tim ...
show more
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.07.31 is noted in report timestamp
show less
Hacking
Brute-Force
๐ฎ๐ณ
wizard1411
2025-06-14 16:50:59
(1 year ago)
DDoS and brute force activity detected
Brute-Force
SSH