๐ฎ๐ณ
Mr.Singh
2026-03-06 21:30:19
(6 months ago)
NFT blocked 156.239.218.40 after 3 rejections on 07-Mar-2026.
Port Scan
Brute-Force
๐ฉ๐ช
bescared
2026-02-25 18:37:20
(6 months ago)
F2B - Malicious activity detected. URL Probing.
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-20 22:49:45
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.218.40 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.218.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 20 17:49:39.695358 2026] [security2:error] [pid 16638:tid 16638] [client 156.239.218.40:18326] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.lyldevelopers.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.lyldevelopers.com"] [uri "/wp-login.php"] [unique_id "aXAGg3q71grPg4jtpBX9_AAAAAE"], referer: http://lyldevelopers.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-11 16:09:48
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.218.40 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.218.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 11 11:09:44.722089 2026] [security2:error] [pid 993545:tid 993545] [client 156.239.218.40:21640] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||engineeringarts.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "engineeringarts.com"] [uri "/wp-login.php"] [unique_id "aWPLSPWMT7Uv3Chi6liXRwAAAA4"], referer: https://engineeringarts.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-31 02:26:39
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 156.239.218.40 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 156.239.218.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 30 21:26:36.414399 2025] [security2:error] [pid 8511:tid 8511] [client 156.239.218.40:21262] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wave94.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wave94.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aVSJ3EyEoKFMkFt_NhDfXwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-31 01:00:57
(8 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-11-26 06:17:21
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 156.239.218.40 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 156.239.218.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 01:17:17.181555 2025] [security2:error] [pid 5709:tid 5709] [client 156.239.218.40:29053] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kawkacevents.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kawkacevents.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aSabbdKTNmbNLZALpzzoqwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-21 15:47:46
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.218.40 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.218.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 21 10:47:42.409385 2025] [security2:error] [pid 475:tid 475] [client 156.239.218.40:41267] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||wealthsec.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "wealthsec.com"] [uri "/wp-login.php"] [unique_id "aSCJnrytliyWFWCp8vZNCgAAAAE"], referer: https://wealthsec.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
hostseries
2025-10-01 19:27:39
(11 months ago)
Trigger: LF_DISTATTACK
Brute-Force
Anonymous
2025-08-05 20:07:19
(1 year ago)
Attempted brute force login to web vpn 68 time(s); last attempt for 2025.08.05 is noted in report ti ...
show more
Attempted brute force login to web vpn 68 time(s); last attempt for 2025.08.05 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-08-01 00:58:57
(1 year ago)
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.08.01 is noted in report tim ...
show more
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.08.01 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-07-31 06:00:06
(1 year ago)
Attempted brute force login to web vpn 4 time(s); last attempt for 2025.07.31 is noted in report tim ...
show more
Attempted brute force login to web vpn 4 time(s); last attempt for 2025.07.31 is noted in report timestamp
show less
Hacking
Brute-Force
๐ฌ๐ง
D3monite
2025-07-23 15:27:59
(1 year ago)
Attempted Brute Force (cpaneld)
Brute-Force
๐ฎ๐ณ
wizard1411
2025-06-14 16:55:23
(1 year ago)
DDoS and brute force activity detected
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-05-12 10:12:49
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 156.239.218.40 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 156.239.218.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 12 06:12:44.797023 2025] [security2:error] [pid 2281956:tid 2281956] [client 156.239.218.40:41045] [client 156.239.218.40] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||diuana.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "diuana.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aCHJnEbX4jZ8x-7SNViqugAAAAU"], referer: https://diuana.com
show less
Brute-Force
Bad Web Bot
Web App Attack