๐บ๐ธ
TPI-Abuse
2026-09-28 21:26:53
(23 hours ago)
(mod_security) mod_security (id:210350) triggered by 103.159.130.152 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 103.159.130.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 17:26:47.686699 2026] [security2:error] [pid 4754:tid 4754] [client 103.159.130.152:52986] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||compassionfatigue.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "compassionfatigue.org"] [uri "/healthycaregiving.com/403.shtml"] [unique_id "arrbl6XHjSKmYyMXIynbjQAAAA4"], referer: https://war-relatedillnessandinjury.blogspot.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 05:27:24
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 103.159.130.152 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 103.159.130.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 01:27:17.940844 2026] [security2:error] [pid 10529:tid 10529] [client 103.159.130.152:55226] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||justicehoward.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "justicehoward.com"] [uri "/"] [unique_id "arIRtRpxDWVz1o1G9fIUMQAAAAY"], referer: https://digitalsophistication.blogspot.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-09-20 23:53:07
(1 week ago)
Repeated requests classified as pathological web bot behavior, for example: /[redacted]?topics%5B0%5 ...
show more
Repeated requests classified as pathological web bot behavior, for example: /[redacted]?topics%5B0%5D=55&topics%5B1%5D=46&topics%5B2%5D=31&topics%5B3%5D=65 (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36")
show less
DDoS Attack
Bad Web Bot
๐ฉ๐ช
jbcrn
2026-09-19 07:19:30
(1 week ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /blog/deflagration.melopoeic/stanchable-anhungered/reprocure/xanthorhamnin-heteroblastic/. User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 02:14:03
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 103.159.130.152 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 103.159.130.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 22:13:55.506853 2026] [security2:error] [pid 2052:tid 2052] [client 103.159.130.152:54243] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||cms2020.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "cms2020.com"] [uri "/"] [unique_id "aqyeY-KErLKF_26imZ9BVQAAAA0"], referer: https://backlinklookup.online/dir/professional-seo-links-41930
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
AvonleaConsulting
2026-09-17 22:58:01
(1 week ago)
Attempts to probe web pages for vulnerable PHP or other applications
Web App Attack
๐ฌ๐ง
AvonleaConsulting
2026-09-17 09:31:49
(1 week ago)
Scanning unused Default website or suspicious access to valid sites from IP marked as abusive
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 16:25:36
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 103.159.130.152 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 103.159.130.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 12:25:30.908395 2026] [security2:error] [pid 17475:tid 17475] [client 103.159.130.152:48494] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||stevenkloepfer.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "stevenkloepfer.com"] [uri "/"] [unique_id "aqrC-gDUiib72fYtyUHyggAAAAY"], referer: https://joncolton.blogspot.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
bigorre.org
2026-09-14 15:13:58
(2 weeks ago)
Unidentified crawling: not a self-announced bot in user-agent
Bad Web Bot
๐ง๐ท
noconex
2026-09-13 07:12:08
(2 weeks ago)
Wazuh Alert | Rule ID: 100199 | Desc: Suricata: (ET SCAN Potential SSH Scan) detectado de 103.159.13 ...
show more
Wazuh Alert | Rule ID: 100199 | Desc: Suricata: (ET SCAN Potential SSH Scan) detectado de 103.159.130.152
show less
Port Scan
Brute-Force
SSH
๐ฉ๐ช
Vegascosmetics
2026-09-12 08:38:28
(2 weeks ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB repu ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB reputation policy (no URL signature). Evidence: Suspicion-Ban (Score 67>=65, Abuse 65, NonEU, first-seen, Change* path)
show less
Hacking
Exploited Host
Web App Attack
๐ซ๐ท
bigorre.org
2026-09-12 06:24:00
(2 weeks ago)
Unidentified crawling: not a self-announced bot in user-agent
Bad Web Bot
๐ซ๐ท
Sklurk
2026-09-12 02:54:01
(2 weeks ago)
Web App Attack
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-11 14:38:45
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
Anonymous
2026-09-08 15:45:45
(3 weeks ago)
Large-scale coordinated botnet (4M+ IPs). Ordered by Alexander Pen'kov (alexander-pen-kov-7b41aa6a/S ...
show more
Large-scale coordinated botnet (4M+ IPs). Ordered by Alexander Pen'kov (alexander-pen-kov-7b41aa6a/Shursky [yordim|LIS|MOW]); Attacker: Mikhail Smirnov (mikhail-smirnov-79830323/Aidan [MOW]) employed by Angara Technologies Group | Catalog Search Fake Parameter Blocked: /catalogsearch/result/?cat=33+&dir=asc&order=relevance&product_vc_mcu=104&q=DVI+104+Tx%2FRx&screensize=22 | UA: Mozilla/5.0 (Windows; U; Windows CE) AppleWebKit/534.40.6 (KHTML, like Gecko) Version/4.1 Safari/534.40.6 | (Magento Site)
show less
Hacking
Bad Web Bot