๐บ๐ธ
TPI-Abuse
2026-02-21 03:10:50
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 156.239.222.188 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.239.222.188 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 22:10:47.624386 2026] [security2:error] [pid 22150:tid 22150] [client 156.239.222.188:55076] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||arthuryeung.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "arthuryeung.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "aZkiNxwplg9vqX-rGOZI_AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 04:07:30
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.222.188 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.222.188 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 17 23:06:57.957883 2026] [security2:error] [pid 32063:tid 32063] [client 156.239.222.188:19338] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||arapi.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "arapi.org"] [uri "/wp-login.php"] [unique_id "aZU64cXkq-er7Ostg-TixgAAAAs"], referer: https://arapi.org/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2026-02-10 00:34:03
(7 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-01-13 06:51:06
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.222.188 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.222.188 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 13 01:51:01.983884 2026] [security2:error] [pid 10131:tid 10131] [client 156.239.222.188:18502] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||wealthsec.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "wealthsec.com"] [uri "/wp-login.php"] [unique_id "aWXrVTdZCL9gQLlfVuq-2QAAAAE"], referer: https://wealthsec.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-31 00:58:17
(8 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-12-20 08:17:57
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.222.188 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.222.188 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 20 03:17:51.452820 2025] [security2:error] [pid 12492:tid 12608] [client 156.239.222.188:49262] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||woofnrose.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "woofnrose.com"] [uri "/wp-login.php"] [unique_id "aUZbr63wTF7BXv_ttSlaowAAAdY"], referer: https://woofnrose.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 21:29:19
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 156.239.222.188 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.239.222.188 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 16:29:13.948004 2025] [security2:error] [pid 32756:tid 32756] [client 156.239.222.188:37829] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||passy.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "passy.us"] [uri "/wp-json/wp/v2/users/"] [unique_id "aS9aKcBHif7TwrJCPDGoZwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-22 00:52:35
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.222.188 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.222.188 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 21 19:52:31.723704 2025] [security2:error] [pid 20028:tid 20028] [client 156.239.222.188:13021] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||jolankagroup.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "jolankagroup.com"] [uri "/wp-login.php"] [unique_id "aSEJTxeUnqTLKKRrxkEwdgAAAAo"], referer: http://jolankagroup.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2025-11-21 12:10:07
(9 months ago)
IM360 WAF: Old style account creation and modification in Joomla! MV:registration
Web App Attack
๐ฑ๐ป
garmtech.com
2025-11-21 02:50:57
(9 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 04-50.156.239.222.188.web-spam ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 04-50.156.239.222.188.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ฑ๐ป
garmtech.com
2025-11-21 01:48:19
(9 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 03-48.156.239.222.188.web-spam ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 03-48.156.239.222.188.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ฑ๐ป
garmtech.com
2025-11-20 20:05:11
(9 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 22-05.156.239.222.188.web-spam ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 22-05.156.239.222.188.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ฑ๐ป
garmtech.com
2025-11-20 06:49:54
(9 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 08-49.156.239.222.188.web-spam ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 08-49.156.239.222.188.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-18 22:32:26
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.222.188 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.222.188 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 18 17:32:20.305859 2025] [security2:error] [pid 12547:tid 12547] [client 156.239.222.188:55447] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.texaslawman.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.texaslawman.net"] [uri "/wp-login.php"] [unique_id "aRzz9EXny_RnrXqjMEvQ8AAAAAo"], referer: http://www.texaslawman.net/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2025-11-18 17:31:28
(9 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 19-31.156.239.222.188.web-spam ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 19-31.156.239.222.188.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack