🇨🇿
lp
2026-09-10 06:21:58
(3 hours ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 157.22.44.96
2026-09-10T07:17:09+02:0 ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 157.22.44.96
2026-09-10T07:17:09+02:00 vpn Access-Reject 'shindo25' station: 157.22.44.96 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-03-26 05:17:10
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 157.22.44.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.44.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 01:17:03.960227 2026] [security2:error] [pid 7009:tid 7009] [client 157.22.44.96:59425] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||idahostem.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "idahostem.org"] [uri "/wp-json/wp/v2/users"] [unique_id "acTBT524dRfuZHzeyF6MAQAAAAw"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-15 02:23:09
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 157.22.44.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.44.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 22:23:04.409906 2026] [security2:error] [pid 13311:tid 13311] [client 157.22.44.96:55867] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||idodat.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "idodat.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abYYCLTTHBjys6puVzei6QAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-01-03 20:51:14
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 157.22.44.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 157.22.44.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 03 15:51:09.218053 2026] [security2:error] [pid 10975:tid 10975] [client 157.22.44.96:56955] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||fiberscribe.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "fiberscribe.com"] [uri "/"] [unique_id "aVmBPdHUXWQ5ghpJr3MtxwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-01-03 18:59:44
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 157.22.44.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 157.22.44.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 03 13:59:41.768274 2026] [security2:error] [pid 21347:tid 21347] [client 157.22.44.96:44273] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||pinman.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "pinman.com"] [uri "/"] [unique_id "aVlnHf1LuX9GAxGcEtEP0gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-17 11:52:53
(8 months ago)
Forum/form spam
Web Spam
🇺🇸
TPI-Abuse
2025-11-27 18:01:57
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 157.22.44.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 157.22.44.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 27 13:01:51.062497 2025] [security2:error] [pid 32016:tid 32016] [client 157.22.44.96:11973] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||primacomm.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "primacomm.com"] [uri "/"] [unique_id "aSiSD9gw6QRTf8lESqLaBQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-27 10:51:48
(9 months ago)
Forum/form spam
Web Spam