๐บ๐ธ
TPI-Abuse
2026-04-30 05:48:49
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 185.77.223.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 185.77.223.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 01:48:41.478235 2026] [security2:error] [pid 23542:tid 23581] [client 185.77.223.39:34431] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sloveniaflyfishing.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sloveniaflyfishing.com"] [uri "/wp-json/wp/v2/users"] [unique_id "afLtOahQ7rVGkRgKCfZXMAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-26 23:26:22
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 185.77.223.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 185.77.223.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 19:26:15.020648 2026] [security2:error] [pid 6233:tid 6233] [client 185.77.223.39:64843] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||desertautoworks.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "desertautoworks.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ae6fF4HvEzFX5VqMIM6nQAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-10 14:34:58
(5 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
[email protected]
2025-12-01 00:02:12
(6 months ago)
Fail2Ban jail apache-json-scanners detected activity on 2025-12-01T00:02:12Z
Brute-Force
๐ฎ๐ฉ
Burayot
2025-11-07 00:29:02
(6 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 185.77.223.39 (US/United States/-): ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 185.77.223.39 (US/United States/-): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-27 14:38:17
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 185.77.223.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 185.77.223.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 27 10:38:13.936366 2025] [security2:error] [pid 18879:tid 18879] [client 185.77.223.39:47153] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||talkingmess.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "talkingmess.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aP-D1YG5kFStcBUp9XxbAQAAAAU"], referer: https://talkingmess.com/wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2025-10-21 09:50:25
(7 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-09-13 03:47:09
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 185.77.223.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 185.77.223.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 12 23:47:04.207464 2025] [security2:error] [pid 7366:tid 7430] [client 185.77.223.39:51433] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||hotelpuertadelsolcr.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "hotelpuertadelsolcr.com"] [uri "/"] [unique_id "aMTpOJBdTLNpz9XItgfdIgAAAIQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-11 00:19:44
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 185.77.223.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 185.77.223.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 10 20:19:34.625146 2025] [security2:error] [pid 15949:tid 15949] [client 185.77.223.39:26911] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||bluerockdragon.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "bluerockdragon.com"] [uri "/"] [unique_id "aMIVlj1L0n43FfmHyF3NXAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2025-03-16 15:45:05
(1 year ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐ฎ๐ฉ
Burayot
2025-03-14 17:25:00
(1 year ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 185.77.223.39 (US/United States/-): ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 185.77.223.39 (US/United States/-): 1 in the last 3600 secs
show less
Web App Attack
๐จ๐ฆ
wil.com
2024-10-20 17:19:10
(1 year ago)
GlobalProtect login attempts with user auditor.
VPN IP
Brute-Force
๐บ๐ธ
ChamberofCommerce.com
2024-08-13 21:08:47
(1 year ago)
Unauthorized Scraping Attempt - More then 225 Pages Requested in a 24 hour period - Total Requested ...
show more
Unauthorized Scraping Attempt - More then 225 Pages Requested in a 24 hour period - Total Requested Before Block:226
show less
Bad Web Bot
๐ซ๐ท
Jean Valjean
2024-08-01 21:09:44
(1 year ago)
Fail2ban Caboom : wp-login.php Bruteforce
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2022-11-17 19:42:57
(3 years ago)
20 attempts against mh-misbehave-ban on pluto
Brute-Force
Bad Web Bot
Web App Attack