๐บ๐ธ
TPI-Abuse
2026-02-18 09:04:49
(5 months ago)
(mod_security) mod_security (id:210350) triggered by 156.249.126.128 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.249.126.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 04:04:41.733443 2026] [security2:error] [pid 23604:tid 23604] [client 156.249.126.128:54432] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||nolaanime.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "nolaanime.com"] [uri "/wp-login.php"] [unique_id "aZWAqZiOUtTAmA9ZUsa8QQAAAAA"], referer: http://nolaanime.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-22 11:12:58
(5 months ago)
(mod_security) mod_security (id:210350) triggered by 156.249.126.128 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.249.126.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 06:12:53.010752 2026] [security2:error] [pid 45690:tid 45690] [client 156.249.126.128:32146] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.cms2020.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.cms2020.com"] [uri "/wp-login.php"] [unique_id "aXIGNIR0tpX_Z5QDNX1PSQAAAAM"], referer: http://cms2020.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-31 00:58:09
(6 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐ฉ๐ช
stinpriza
2025-12-28 18:54:16
(6 months ago)
Web App Attack
Web App Attack
๐ฎ๐ฉ
Burayot
2025-12-23 19:03:03
(6 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 156.249.126.128 (CA/Canada/-): 1 in ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 156.249.126.128 (CA/Canada/-): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-22 23:29:44
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 156.249.126.128 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.249.126.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 22 18:29:36.942173 2025] [security2:error] [pid 28183:tid 28183] [client 156.249.126.128:55804] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||arriagarealestate.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "arriagarealestate.com"] [uri "/wp-login.php"] [unique_id "aUnUYJd-bWOo74nATGDo9gAAAAc"], referer: https://arriagarealestate.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
filthywombat
2025-12-21 23:06:00
(6 months ago)
Likely a proxy, 5 or six others involved at same time using breached uplay credintials (Ubisoft Brea ...
show more
Likely a proxy, 5 or six others involved at same time using breached uplay credintials (Ubisoft Breach).
Windows 10 w/Firefox according to UAS but just as likely forged.
show less
Hacking
Brute-Force
Web App Attack
Anonymous
2025-12-04 06:07:15
(7 months ago)
wordpress-trap
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 19:49:59
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 156.249.126.128 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.249.126.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 14:49:55.940363 2025] [security2:error] [pid 13905:tid 13905] [client 156.249.126.128:46099] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.maffiniandbearce.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.maffiniandbearce.com"] [uri "/wp-login.php"] [unique_id "aS9C4yLfAQaxXrweXNd7YAAAAB4"], referer: https://www.maffiniandbearce.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-23 08:07:50
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 156.249.126.128 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.249.126.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 03:07:47.138288 2025] [security2:error] [pid 2361646:tid 2361709] [client 156.249.126.128:33715] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.nimbll.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.nimbll.com"] [uri "/wp-login.php"] [unique_id "aSLA0yfiZI3xyLMSDDZOjAAAAgs"], referer: https://www.nimbll.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2025-11-22 20:20:04
(7 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-11-22 13:20:10
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 156.249.126.128 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.249.126.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 22 08:20:03.966803 2025] [security2:error] [pid 3822:tid 3822] [client 156.249.126.128:36171] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||genevaatlantic.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "genevaatlantic.com"] [uri "/login/"] [unique_id "aSG4g0j6ewoe8oyvAJCKFgAAABI"], referer: https://genevaatlantic.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-19 06:06:23
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 156.249.126.128 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.249.126.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 19 01:06:19.919059 2025] [security2:error] [pid 28372:tid 28372] [client 156.249.126.128:28113] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.whatyouhear.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.whatyouhear.com"] [uri "/wp-login.php"] [unique_id "aR1eW7t52f9orqCTn7th2QAAABE"], referer: https://www.whatyouhear.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-18 14:44:46
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 156.249.126.128 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.249.126.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 18 09:44:39.066985 2025] [security2:error] [pid 25610:tid 25610] [client 156.249.126.128:27775] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||engineeringarts.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "engineeringarts.com"] [uri "/wp-login.php"] [unique_id "aRyGV5zjUpjXpFl59egmfgAAAB0"], referer: https://engineeringarts.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-17 20:55:09
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 156.249.126.128 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.249.126.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 17 15:55:00.707426 2025] [security2:error] [pid 7590:tid 7590] [client 156.249.126.128:34049] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.centrodentalsindolor.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.centrodentalsindolor.com"] [uri "/wp-login.php"] [unique_id "aRuLpM7pSuUD-8VC2pr-aAAAAB4"], referer: https://www.centrodentalsindolor.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack