๐บ๐ธ
TPI-Abuse
2026-03-03 11:33:08
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 156.239.219.237 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.239.219.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 03 06:33:00.244713 2026] [security2:error] [pid 18182:tid 18182] [client 156.239.219.237:60492] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||daos.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "daos.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "aabG7EIxXSjNl9_BKcS-wgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-28 13:49:29
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 156.239.219.237 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.239.219.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 28 08:49:27.392389 2026] [security2:error] [pid 3412:tid 3412] [client 156.239.219.237:31072] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||paladinmicro.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "paladinmicro.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aaLyZ_N-NiVcTh7ofUeJ_QAAAAs"], referer: https://paladinmicro.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 03:04:50
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.219.237 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.219.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 22:04:44.949689 2026] [security2:error] [pid 21945:tid 21969] [client 156.239.219.237:41134] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||orthopedica.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "orthopedica.org"] [uri "/wp-login.php"] [unique_id "aY6UzBtceAHuS2V-cx0sxAAAAI0"], referer: https://orthopedica.org/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-12 08:46:07
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.219.237 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.219.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 12 03:46:00.845141 2026] [security2:error] [pid 3394:tid 3394] [client 156.239.219.237:22990] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||fiasdesigns.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "fiasdesigns.com"] [uri "/wp-login.php"] [unique_id "aWS0yKC_dCoRY3eUjfwDEwAAABE"], referer: http://fiasdesigns.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
hostseries
2026-01-08 00:39:48
(8 months ago)
Trigger: LF_DISTATTACK
Brute-Force
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-31 00:57:23
(8 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-12-02 21:30:57
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.219.237 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.219.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 16:30:50.201565 2025] [security2:error] [pid 12191:tid 12191] [client 156.239.219.237:46591] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.humbliaslaw.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.humbliaslaw.com"] [uri "/wp-login.php"] [unique_id "aS9aioZi3Q-PGTRCHr5tFQAAAAM"], referer: http://www.humbliaslaw.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-23 04:32:51
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.219.237 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.219.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 22 23:32:45.071599 2025] [security2:error] [pid 6270:tid 6270] [client 156.239.219.237:9665] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.whatyouhear.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.whatyouhear.com"] [uri "/wp-login.php"] [unique_id "aSKOba9DshFXzH74eikC1AAAAAw"], referer: https://www.whatyouhear.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-18 15:14:21
(10 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.219.237 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.219.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 18 10:14:15.817329 2025] [security2:error] [pid 9118:tid 9118] [client 156.239.219.237:50105] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||salernospizza.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "salernospizza.com"] [uri "/wp-login.php"] [unique_id "aRyNR-d12FwDcL3nGiKWowAAAAw"], referer: https://salernospizza.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-17 13:12:41
(10 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.219.237 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.219.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 17 08:12:34.807518 2025] [security2:error] [pid 9214:tid 9214] [client 156.239.219.237:60467] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||eye7graphics.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "eye7graphics.com"] [uri "/wp-login.php"] [unique_id "aRsfQj1pnKx9zzVp6ZJ0cQAAAA0"], referer: http://eye7graphics.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-14 13:32:06
(10 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.219.237 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.219.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 14 08:31:59.240112 2025] [security2:error] [pid 29341:tid 29341] [client 156.239.219.237:55409] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||jolankagroup.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "jolankagroup.com"] [uri "/wp-login.php"] [unique_id "aRcvT7icSFHbw5qzs0UdTgAAAAQ"], referer: http://jolankagroup.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
Yashgarg@123
2025-10-21 05:51:36
(11 months ago)
DDoS and brute force activity detected
Brute-Force
SSH
๐ฌ๐ง
threewalls.co.uk
2025-10-03 18:26:30
(11 months ago)
Triggered bot honeypot on gclproducts.co.uk
Fraud Orders
FTP Brute-Force
Brute-Force
Exploited Host
Anonymous
2025-07-31 19:37:55
(1 year ago)
Attempted brute force login to web vpn 3 time(s); last attempt for 2025.07.31 is noted in report tim ...
show more
Attempted brute force login to web vpn 3 time(s); last attempt for 2025.07.31 is noted in report timestamp
show less
Hacking
Brute-Force
๐ฎ๐ณ
wizard1411
2025-06-15 16:28:44
(1 year ago)
DDoS and brute force activity detected
Brute-Force
SSH