๐บ๐ธ
lostswordfish.com
2026-03-20 13:54:04
(5 months ago)
Wordfence waf block on robdarnell
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-02-18 13:26:03
(6 months ago)
Wordfence waf block on robdarnell
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-02-11 12:58:03
(6 months ago)
Wordfence waf block on robdarnell
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 04:45:28
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.199.96 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.199.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 23:45:21.248386 2026] [security2:error] [pid 19401:tid 19401] [client 156.239.199.96:14952] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||advantagesystemsgroup.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "advantagesystemsgroup.com"] [uri "/wp-login.php"] [unique_id "aYq34QfEl_ToYcuM512ffwAAABA"], referer: https://advantagesystemsgroup.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-07 15:21:24
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.199.96 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.199.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 07 10:21:16.572051 2026] [security2:error] [pid 1766087:tid 1766087] [client 156.239.199.96:45132] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||passy.us|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "passy.us"] [uri "/wp-login.php"] [unique_id "aYdYbIZoUQGP4elN6RkAzAAAACE"], referer: http://passy.us/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-01-21 22:24:52
(7 months ago)
wordpress-trap
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-31 00:58:32
(7 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-12-27 11:13:01
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.199.96 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.199.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 06:12:56.891009 2025] [security2:error] [pid 26826:tid 26826] [client 156.239.199.96:21186] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||primacomm.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "primacomm.com"] [uri "/wp-login.php"] [unique_id "aU-_OI4Mg07l8QTKd_d4pAAAAAk"], referer: https://primacomm.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-21 08:58:08
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.199.96 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.199.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 21 03:57:55.401404 2025] [security2:error] [pid 16272:tid 16272] [client 156.239.199.96:30866] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.mcbrearty.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.mcbrearty.org"] [uri "/wp-login.php"] [unique_id "aUe2kwcUcn82E98KAWpPTQAAABQ"], referer: http://www.mcbrearty.org/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-17 13:46:06
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.199.96 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.199.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 17 08:46:01.149626 2025] [security2:error] [pid 29553:tid 29553] [client 156.239.199.96:43323] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||lawrencehale.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "lawrencehale.com"] [uri "/wp-login.php"] [unique_id "aRsnGfDpWNaxAvBQsbFDOAAAACc"], referer: https://lawrencehale.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
advena
2025-08-16 17:16:03
(1 year ago)
156.239.199.96 (AS200373 DREI-K-TECH-GMBH) was intercepted at 2025-08-16T17:10:22Z after violating W ...
show more
156.239.199.96 (AS200373 DREI-K-TECH-GMBH) was intercepted at 2025-08-16T17:10:22Z after violating WAF directive: 874a3e315c344b1281ad4f00046aab6f. Pre-cautionary/corrective action applied: managed_challenge.
show less
Web Spam
Hacking
Brute-Force
Web App Attack
Anonymous
2025-08-01 01:55:38
(1 year ago)
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.08.01 is noted in report tim ...
show more
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.08.01 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-07-31 17:27:03
(1 year ago)
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.07.31 is noted in report tim ...
show more
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.07.31 is noted in report timestamp
show less
Hacking
Brute-Force
๐ฎ๐ณ
wizard1411
2025-06-15 03:20:39
(1 year ago)
DDoS and brute force activity detected
Brute-Force
SSH