πΊπΈ
TPI-Abuse
2026-01-23 11:16:53
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.223.235 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.223.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 23 06:16:47.799520 2026] [security2:error] [pid 18482:tid 18482] [client 156.239.223.235:30300] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||primacomm.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "primacomm.com"] [uri "/wp-login.php"] [unique_id "aXNYn6u52VfzyY1LAP0_CQAAAAM"], referer: https://primacomm.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-31 02:10:48
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.223.235 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.223.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 30 21:10:40.957266 2025] [security2:error] [pid 7613:tid 7613] [client 156.239.223.235:18084] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||accommodation-perthairport.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "accommodation-perthairport.com"] [uri "/wp-login.php"] [unique_id "aVSGIJGcB4F9Yb-TG0slzAAAABk"], referer: http://accommodation-perthairport.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Packets-Decreaser.NET
2025-12-31 01:00:51
(7 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
πΊπΈ
TPI-Abuse
2025-12-28 05:44:10
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.223.235 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.223.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 00:44:06.026904 2025] [security2:error] [pid 16776:tid 16776] [client 156.239.223.235:17166] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.passy.us|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.passy.us"] [uri "/wp-login.php"] [unique_id "aVDDplcUngQXobLY40EIPAAAAAk"], referer: http://passy.us/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-27 16:24:11
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.223.235 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.223.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 11:24:07.739573 2025] [security2:error] [pid 22374:tid 22374] [client 156.239.223.235:48464] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||genevaatlantic.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "genevaatlantic.com"] [uri "/wp-login.php"] [unique_id "aVAIJ-MN0-D8HIZJd7Q5zAAAABw"], referer: https://genevaatlantic.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-17 18:58:12
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.223.235 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.223.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 17 13:58:06.665268 2025] [security2:error] [pid 28097:tid 28118] [client 156.239.223.235:28396] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.guitarprimer.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.guitarprimer.com"] [uri "/wp-login.php"] [unique_id "aUL9PmvPEdzMeRHLwa45bQAAAJE"], referer: https://www.guitarprimer.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-11 01:20:20
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.223.235 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.223.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 10 20:20:11.043698 2025] [security2:error] [pid 29408:tid 29408] [client 156.239.223.235:53292] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.saadeh.ws|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.saadeh.ws"] [uri "/wp-login.php"] [unique_id "aTocS_yXm9ROItQc1zjJKgAAABY"], referer: https://www.saadeh.ws/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-18 22:36:48
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 156.239.223.235 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.239.223.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 18 17:36:42.669061 2025] [security2:error] [pid 32429:tid 32429] [client 156.239.223.235:55651] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||bernsteinip.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "bernsteinip.com"] [uri "/wp-login.php"] [unique_id "aRz0-rXKaYYg_i54wNTDOAAAABQ"], referer: https://bernsteinip.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
F242
2025-11-16 05:22:34
(9 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack
πΊπΈ
secmon-bf
2025-08-12 10:13:38
(1 year ago)
Attempt to retrieve sensitive database information.
Exploited Host
Web App Attack
Anonymous
2025-07-31 21:07:40
(1 year ago)
Attempted brute force login to web vpn 4 time(s); last attempt for 2025.07.31 is noted in report tim ...
show more
Attempted brute force login to web vpn 4 time(s); last attempt for 2025.07.31 is noted in report timestamp
show less
Hacking
Brute-Force
π¨π
backslash
2025-05-10 13:15:03
(1 year ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot