๐ฉ๐ช
FeG Deutschland
2026-10-02 17:16:26
(17 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 16:06:53
(19 hours ago)
(mod_security) mod_security (id:210350) triggered by 102.206.97.44 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 102.206.97.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 12:06:45.011334 2026] [security2:error] [pid 29030:tid 29030] [client 102.206.97.44:55884] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||cvtheory.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "cvtheory.com"] [uri "/"] [unique_id "ar_WlT3-HfKzQxhqPcdUsQAAAAM"], referer: https://generatefreebacklinks.online/dir/results-focused-backlinks-48982
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
ALPHANET
2026-10-02 06:00:12
(1 day ago)
Botnet or web spider not respecting robots.txt
DDoS Attack
Exploited Host
๐น๐ท
ferique
2026-10-01 21:11:00
(1 day ago)
Real-time Intercept: SMTP attack. Reference: 2026-10-02 00:10:49.9953 Login failure: 102.206.97.44 ...
show more
Real-time Intercept: SMTP attack. Reference: 2026-10-02 00:10:49.9953 Login failure: 102.206.97.44 SMTP
show less
Brute-Force
Email Spam
๐ณ๐ฑ
maxxsense
2026-10-01 17:56:09
(1 day ago)
(postfix-unknown) Failed postfix unknown login with username [redacted] from 102.206.97.44 (KE/Kenya ...
show more
(postfix-unknown) Failed postfix unknown login with username [redacted] from 102.206.97.44 (KE/Kenya/-)
show less
Hacking
๐ฉ๐ช
LRob
2026-10-01 15:32:31
(1 day ago)
SMTP AUTH probe | 2026-10-01 15:32 UTC
Port Scan
๐จ๐ฟ
lp
2026-10-01 10:50:27
(2 days ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 102.206.97.44
2026-10-01T11:45:17+02: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 102.206.97.44
2026-10-01T11:45:17+02:00 vpn Access-Reject 'xbuke00' station: 102.206.97.44 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 06:56:58
(5 days ago)
(mod_security) mod_security (id:210350) triggered by 102.206.97.44 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 102.206.97.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 02:56:52.147343 2026] [security2:error] [pid 19200:tid 19200] [client 102.206.97.44:56252] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||saldesica.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "saldesica.com"] [uri "/"] [unique_id "aroPtEEHeE4rEZYpzJFI0QAAAAI"], referer: https://bulkbacklinkchecker.site/dir/editorial-link-building-181460
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
Fredrik_2015
2026-09-26 16:33:05
(6 days ago)
Email login Brute force
Hacking
Brute-Force
๐ฎ๐น
Inartis
2026-09-20 21:36:06
(1 week ago)
2026-09-20T23:36:05.073693mail1.inartis.it postfix/smtpd[3324416]: warning: unknown[102.206.97.44]: ...
show more
2026-09-20T23:36:05.073693mail1.inartis.it postfix/smtpd[3324416]: warning: unknown[102.206.97.44]: SASL PLAIN authentication failed: authentication failure, [email protected]
...
show less
Port Scan
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-18 18:59:08
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 102.206.97.44 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 102.206.97.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 14:59:04.457440 2026] [security2:error] [pid 19063:tid 19063] [client 102.206.97.44:39688] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||kelleysbridge.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "kelleysbridge.com"] [uri "/"] [unique_id "aq2J-OYv6t1-Qs4OLHJ9jwAAAAc"], referer: https://backlinkscheckerbulk.shop/dir/seo-boosting-backlinks-112536
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 12:19:16
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 102.206.97.44 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 102.206.97.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 08:19:07.777978 2026] [security2:error] [pid 17612:tid 17612] [client 102.206.97.44:40972] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||hatfulofrain.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "hatfulofrain.com"] [uri "/"] [unique_id "aqvau5WZXhAx6lybh8bWbwAAABI"], referer: https://bulkdacheckeronline.online/dir/ranking-focused-backlinks-89683
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-16 08:22:56
(2 weeks ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB repu ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB reputation policy (no URL signature). Evidence: Suspicion-Ban (Score 68>=65, Abuse 66, NonEU, first-seen, Change* path)
show less
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 19:18:01
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 102.206.97.44 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 102.206.97.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:17:53.376649 2026] [security2:error] [pid 1478:tid 1478] [client 102.206.97.44:56448] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||theateroobleck.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "theateroobleck.com"] [uri "/"] [unique_id "aqmZ4QCaS938BTz-zaGemwAAAAA"], referer: https://the-at-er.blogspot.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
้ฌผๅฝฑ233
2026-09-15 11:45:12
(2 weeks ago)
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0. ...
show more
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
show less
Bad Web Bot