๐ซ๐ท
Tilellit.PRO
2026-02-19 09:39:45
(6 months ago)
Fail2Ban banned 156.239.210.92 for security violations in jail wp-armour. Log: 2026/02/19 09:39:45 [ ...
show more
Fail2Ban banned 156.239.210.92 for security violations in jail wp-armour. Log: 2026/02/19 09:39:45 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 156.239.210.92 | Target: wplogin" , client: 156.239.210.92, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ฉ๐ช
F242
2026-02-08 22:51:41
(7 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack
Anonymous
2026-01-18 03:55:38
(7 months ago)
wordpress-trap
Web App Attack
๐ง๐ท
hostseries
2026-01-13 13:04:28
(7 months ago)
Trigger: LF_DISTATTACK
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-01-04 16:12:08
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.210.92 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.210.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 04 11:12:03.589201 2026] [security2:error] [pid 3550096:tid 3550096] [client 156.239.210.92:27884] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||dynamic-therapy-mn.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "dynamic-therapy-mn.com"] [uri "/wp-login.php"] [unique_id "aVqRU_IjNk_3wkuSS52q9AAAAAM"], referer: https://dynamic-therapy-mn.com//wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-31 00:58:02
(8 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐ฆ๐บ
MAGIC
2025-12-24 02:14:03
(8 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ฉ๐ช
F242
2025-12-17 13:34:42
(8 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-04 07:27:27
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.210.92 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.210.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 04 02:27:22.638520 2025] [security2:error] [pid 11399:tid 11399] [client 156.239.210.92:13803] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.josephshv.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.josephshv.com"] [uri "/wp-login.php"] [unique_id "aTE32p1rGZPQ6tzOW4FwpAAAAAY"], referer: http://www.josephshv.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
F242
2025-12-03 00:24:55
(9 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack
Anonymous
2025-12-02 20:24:26
(9 months ago)
botnet
DDoS Attack
๐บ๐ธ
TPI-Abuse
2025-11-28 09:56:06
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.210.92 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.210.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 28 04:55:58.370119 2025] [security2:error] [pid 12768:tid 12768] [client 156.239.210.92:16057] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||mfleetservice.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "mfleetservice.com"] [uri "/wp-login.php"] [unique_id "aSlxrvsFzMEmNdWc_vB8sAAAACA"], referer: http://mfleetservice.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-17 01:36:53
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.210.92 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.210.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 16 20:36:43.979415 2025] [security2:error] [pid 8025:tid 8025] [client 156.239.210.92:18241] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||interiorsolutions-stuart.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "interiorsolutions-stuart.com"] [uri "/wp-login.php"] [unique_id "aRp8K7TQ6HCMvQq2KfLmDgAAABE"], referer: https://interiorsolutions-stuart.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-16 03:43:43
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.210.92 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.210.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 15 22:43:37.767949 2025] [security2:error] [pid 11469:tid 11469] [client 156.239.210.92:20109] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.kawkacevents.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.kawkacevents.com"] [uri "/wp-login.php"] [unique_id "aRlIaflifcAwI7XsSM13KQAAABE"], referer: http://www.kawkacevents.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
cloudmax
2025-08-06 23:05:50
(1 year ago)
Cloudmax IPS Block - Suspicious activity. Possible port scanning, service reconnaissance, or vulnera ...
show more
Cloudmax IPS Block - Suspicious activity. Possible port scanning, service reconnaissance, or vulnerability probing
show less
Port Scan