๐บ๐ธ
TPI-Abuse
2026-02-08 17:17:31
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.201.182 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.201.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 08 12:17:23.804625 2026] [security2:error] [pid 3876412:tid 3876412] [client 156.239.201.182:36222] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.joeordie.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.joeordie.com"] [uri "/wp-login.php"] [unique_id "aYjFI1DL63DcGbV9mpitogAAABQ"], referer: http://joeordie.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
hostseries
2026-01-13 11:50:03
(7 months ago)
Trigger: LF_DISTATTACK
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-01-10 22:52:44
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.201.182 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.201.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 10 17:52:36.625809 2026] [security2:error] [pid 3540051:tid 3540051] [client 156.239.201.182:31564] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||engineeringarts.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "engineeringarts.com"] [uri "/wp-login.php"] [unique_id "aWLYNK1aRMasc0XBya9bawAAABo"], referer: https://engineeringarts.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-09 22:03:32
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.201.182 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.201.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 09 17:03:25.875453 2026] [security2:error] [pid 23992:tid 23992] [client 156.239.201.182:23866] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||interiorsolutions-stuart.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "interiorsolutions-stuart.com"] [uri "/wp-login.php"] [unique_id "aWF7LWzfE5AFXA4YpbmqhwAAAAM"], referer: https://interiorsolutions-stuart.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2025-12-26 12:22:15
(7 months ago)
Web password guessing
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-12-19 07:58:20
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.201.182 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.201.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 19 02:58:15.270915 2025] [security2:error] [pid 4547:tid 4547] [client 156.239.201.182:39890] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||tedharris.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "tedharris.com"] [uri "/wp-login.php"] [unique_id "aUUFl9XZQOk5dqKElCVtCAAAAAQ"], referer: https://tedharris.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-26 21:48:35
(8 months ago)
wordpress-trap
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-17 12:30:59
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.201.182 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.201.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 17 07:30:52.766802 2025] [security2:error] [pid 6009:tid 6009] [client 156.239.201.182:39867] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||bzbdesigns.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "bzbdesigns.com"] [uri "/wp-login.php"] [unique_id "aRsVfObZ8YEk2JLcRYjvRAAAAAo"], referer: http://bzbdesigns.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-09 03:44:28
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 156.239.201.182 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.239.201.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 08 22:44:25.491201 2025] [security2:error] [pid 18062:tid 18062] [client 156.239.201.182:24825] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||hatfulofrain.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "hatfulofrain.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aRAOGXZ0o1GGLL4TRSsGLAAAAAc"], referer: https://hatfulofrain.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vinyamar
2025-08-09 09:09:50
(1 year ago)
VSecCenter: Generic internal Webserver errors detected. | 1 in 24h
Hacking
Anonymous
2025-07-31 17:28:30
(1 year ago)
Attempted brute force login to web vpn 8 time(s); last attempt for 2025.07.31 is noted in report tim ...
show more
Attempted brute force login to web vpn 8 time(s); last attempt for 2025.07.31 is noted in report timestamp
show less
Hacking
Brute-Force
๐บ๐ธ
mdgudell
2025-06-17 07:04:07
(1 year ago)
156.239.201.182 - - [17/Jun/2025:02:04:06 -0500] "GET /+CSCOE+/logon.html HTTP/1.1" 404 4013 "-" "Mo ...
show more
156.239.201.182 - - [17/Jun/2025:02:04:06 -0500] "GET /+CSCOE+/logon.html HTTP/1.1" 404 4013 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36 Edg/115.0.1901.203"
...
show less
Port Scan
Web App Attack
๐ฎ๐ณ
wizard1411
2025-06-15 03:17:02
(1 year ago)
DDoS and brute force activity detected
Brute-Force
SSH
๐ง๐ท
hostseries
2025-05-08 21:48:44
(1 year ago)
Brute-force cPanel Services
Brute-Force