๐ณ๐ฑ
e.fierstra
2026-09-01 10:35:18
(1 hour ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-31 18:27:34
(18 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 15:34:03
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 104.28.160.175 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 104.28.160.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 11:33:56.273528 2026] [security2:error] [pid 24981:tid 24981] [client 104.28.160.175:60867] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||rivercityacct.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "rivercityacct.com"] [uri "/"] [unique_id "apL75Fh2b06Z38dpxW7lygAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 14:08:26
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 104.28.160.175 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 104.28.160.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 10:08:20.746912 2026] [security2:error] [pid 28574:tid 28574] [client 104.28.160.175:61033] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||intolifeproductions.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "intolifeproductions.com"] [uri "/"] [unique_id "apLn1ImEBnMHediSP2hGGAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
neron
2026-08-25 21:21:50
(6 days ago)
CrowdSec blocked: tcp:scan detected via OPNsense firewall
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 21:35:00
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 104.28.160.175 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 104.28.160.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 17:34:56.555598 2026] [security2:error] [pid 30860:tid 30860] [client 104.28.160.175:33071] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||countylockup.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "countylockup.org"] [uri "/"] [unique_id "aotngInY51yY7yZkNi06rAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 19:48:41
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 104.28.160.175 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 104.28.160.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 15:48:35.382129 2026] [security2:error] [pid 8789:tid 8789] [client 104.28.160.175:34489] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||centralbaptistalcoa.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "centralbaptistalcoa.org"] [uri "/"] [unique_id "aotOk3B7yRjsmXUbryBazQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
neron
2026-08-21 18:25:59
(1 week ago)
CrowdSec blocked: tcp:scan detected via OPNsense firewall
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 09:42:52
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 104.28.160.175 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 104.28.160.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 05:42:47.113625 2026] [security2:error] [pid 26110:tid 26110] [client 104.28.160.175:47277] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||joshuashands.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "joshuashands.org"] [uri "/"] [unique_id "aobMF4OQPTERrr4xRuYDAgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 16:06:54
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 104.28.160.175 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 104.28.160.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 12:06:49.121755 2026] [security2:error] [pid 27534:tid 27534] [client 104.28.160.175:33794] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||alltecmachine.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "alltecmachine.com"] [uri "/"] [unique_id "aoXUmVUCv7NHilH9wn3SDQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 15:45:03
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 104.28.160.175 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 104.28.160.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 11:44:56.291268 2026] [security2:error] [pid 20934:tid 20934] [client 104.28.160.175:32820] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||beirutbazar.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "beirutbazar.com"] [uri "/"] [unique_id "aoXPeH_zCEM4Hd6hAnJe_gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 14:39:09
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 104.28.160.175 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 104.28.160.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 10:39:01.505662 2026] [security2:error] [pid 5974:tid 5974] [client 104.28.160.175:32929] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||matteozacchino.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "matteozacchino.com"] [uri "/"] [unique_id "aoXABQx7-qjbD0-fQnZHLAAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
neron
2026-08-19 12:26:20
(1 week ago)
CrowdSec blocked: tcp:scan detected via OPNsense firewall
Hacking
Web App Attack
Anonymous
2026-08-18 08:35:15
(2 weeks ago)
Web scanner: GET /.env.sample
Web App Attack
Hacking
๐น๐ท
neron
2026-08-12 23:06:48
(2 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack