๐บ๐ธ
TPI-Abuse
2026-10-05 19:12:02
(3 hours ago)
(mod_security) mod_security (id:210350) triggered by 109.224.242.157 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 109.224.242.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 15:11:56.542722 2026] [security2:error] [pid 19031:tid 19031] [client 109.224.242.157:35286] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||restaurant-napkins.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "restaurant-napkins.com"] [uri "/"] [unique_id "asP2fHcU-BH3YmkNce_KPgAAAAs"], referer: https://backlinkplatform.space/dir/custom-seo-backlinks-175555
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
neron
2026-10-02 16:06:42
(3 days ago)
CrowdSec blocked: ssh:bruteforce detected via OPNsense firewall
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 15:25:42
(3 days ago)
(mod_security) mod_security (id:210350) triggered by 109.224.242.157 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 109.224.242.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:25:38.488114 2026] [security2:error] [pid 21807:tid 21807] [client 109.224.242.157:54203] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||angelaridgwaydressage.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "angelaridgwaydressage.com"] [uri "/"] [unique_id "ar_M8tfp-O1ImjZZ-oT9VwAAAAU"], referer: https://locallinkbuildingservice.online/dir/backlinks-for-traffic-9850
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 11:52:57
(3 days ago)
(mod_security) mod_security (id:210350) triggered by 109.224.242.157 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 109.224.242.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 07:52:52.538760 2026] [security2:error] [pid 28300:tid 28300] [client 109.224.242.157:45908] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||transcapitalsolutions.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "transcapitalsolutions.com"] [uri "/"] [unique_id "ar-bFF--e5NNBj5b33NgVQAAAA0"], referer: https://backlinkautomation.shop/dir/results-driven-link-building-216781
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
xavier-momain.eu
2026-10-01 19:00:53
(4 days ago)
CrowdSec ban โ scenario: ssh:bruteforce
Brute-Force
SSH
๐น๐ท
neron
2026-10-01 16:06:37
(4 days ago)
CrowdSec blocked: ssh:bruteforce detected via OPNsense firewall
Hacking
Web App Attack
๐น๐ท
neron
2026-09-29 11:51:38
(6 days ago)
CrowdSec blocked: ssh:bruteforce detected via OPNsense firewall
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 13:34:06
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 109.224.242.157 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 109.224.242.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 09:33:59.484291 2026] [security2:error] [pid 24287:tid 24287] [client 109.224.242.157:45242] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||crowmoonmarketing.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "crowmoonmarketing.com"] [uri "/"] [unique_id "arfJx2yKj-yBH-PkXOYkPAAAACA"], referer: https://bestdachecker.space/dir/backlinks-for-traffic-47550
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 09:28:17
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 109.224.242.157 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 109.224.242.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 05:27:20.033780 2026] [security2:error] [pid 25650:tid 25775] [client 109.224.242.157:36720] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/config/parameters.yml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "giere.org.giere.us"] [uri "/app/config/parameters.yml.txt"] [unique_id "arObeKsYoM-F8S6jjvcrIAAAAkI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
้ฌผๅฝฑ233
2026-09-19 07:31:19
(2 weeks ago)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Sa ...
show more
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36 Edg/144.0.0.0
show less
Bad Web Bot
๐ซ๐ท
Sklurk
2026-09-17 08:48:24
(2 weeks ago)
Web App Attack
Web App Attack
๐บ๐ธ
้ฌผๅฝฑ233
2026-09-16 18:04:12
(2 weeks ago)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Sa ...
show more
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36 Edg/144.0.0.0
show less
Bad Web Bot
๐ฉ๐ช
Vegascosmetics
2026-09-16 10:35:35
(2 weeks ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after deep/obfuscated attack (encoding nest ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after deep/obfuscated attack (encoding nesting / CPU-drain risk). Evidence: High Priority: %25252F
show less
Hacking
Exploited Host
Web App Attack
Anonymous
2026-09-15 06:18:24
(2 weeks ago)
denied traffic to a non-approved destination port. destination port 53860.
Port Scan
๐ณ๐ฑ
DonAtari
2026-09-15 04:51:14
(2 weeks ago)
DShield firewall scan - UDP to port 22538
Brute-Force
SSH