Anonymous
2026-06-10 06:32:10
(15 hours ago)
Illegitimate and/or suspicious requests.
Hacking
๐บ๐ธ
Starburst SysOp Team
2026-06-10 04:43:26
(17 hours ago)
(mod_security-custom) mod_security (id:210350) triggered by 124.156.205.199 (SG/Singapore/-/Singapor ...
show more
(mod_security-custom) mod_security (id:210350) triggered by 124.156.205.199 (SG/Singapore/-/Singapore/-/[AS132203 TENCENT-NET-AP-CN Tencent Building, Kejizhongyi Avenue]): 1 in the last 3600 secs (0-srv1)
show less
Hacking
๐ณ๐ฑ
ParaBug
2026-06-09 23:54:44
(22 hours ago)
124.156.205.199 - - [10/Jun/2026:01:54:44 +0200] "GET / HTTP/1.0" 400 568 "-" "-"
...
Phishing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 22:25:42
(23 hours ago)
(mod_security) mod_security (id:210350) triggered by 124.156.205.199 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 124.156.205.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 18:25:33.404234 2026] [security2:error] [pid 17300:tid 17300] [client 124.156.205.199:44452] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||192.64.151.16:80|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "192.64.151.16"] [uri "/"] [unique_id "aiiS3X_euo_yGlbZI5EGEAAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 22:07:59
(23 hours ago)
(mod_security) mod_security (id:210350) triggered by 124.156.205.199 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 124.156.205.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 18:07:53.758471 2026] [security2:error] [pid 20413:tid 20413] [client 124.156.205.199:57294] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.firebelly.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.firebelly.org"] [uri "/"] [unique_id "aiiOucBZZtAPIUEo7zrSlAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Sklurk
2026-06-09 21:36:20
(1 day ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 21:36:14
(1 day ago)
(mod_security) mod_security (id:210350) triggered by 124.156.205.199 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 124.156.205.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 17:36:09.315458 2026] [security2:error] [pid 28779:tid 28779] [client 124.156.205.199:55940] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||blackriverarc.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "blackriverarc.org"] [uri "/"] [unique_id "aiiHSXXqqun3nAFI3lsHawAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 21:16:39
(1 day ago)
(mod_security) mod_security (id:210350) triggered by 124.156.205.199 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 124.156.205.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 17:16:35.363914 2026] [security2:error] [pid 10010:tid 10010] [client 124.156.205.199:39620] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.pseudo.space|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.pseudo.space"] [uri "/"] [unique_id "aiiCs2YirWmlhLe4HyPfqwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Roper123
2026-06-09 20:52:33
(1 day ago)
Web app exploits
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 20:02:55
(1 day ago)
(mod_security) mod_security (id:210350) triggered by 124.156.205.199 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 124.156.205.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 16:02:46.612209 2026] [security2:error] [pid 28607:tid 28607] [client 124.156.205.199:48024] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||dci.legal|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "dci.legal"] [uri "/"] [unique_id "aihxZsFNRtx3JxybTslXkwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
brantknudson.org
2026-06-09 19:54:27
(1 day ago)
Incorrect Host header
Web App Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-09 19:26:04
(1 day ago)
(mod_security) mod_security (id:210350) triggered by 124.156.205.199 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 124.156.205.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 15:25:57.416765 2026] [security2:error] [pid 4363:tid 4363] [client 124.156.205.199:52806] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||casaroma-alassio.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "casaroma-alassio.com"] [uri "/"] [unique_id "aihoxUz8RkvgiKag3jrv7gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 19:03:47
(1 day ago)
(mod_security) mod_security (id:210350) triggered by 124.156.205.199 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 124.156.205.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 15:03:40.513240 2026] [security2:error] [pid 31528:tid 31528] [client 124.156.205.199:32828] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||shieldsenterprises.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "shieldsenterprises.com"] [uri "/"] [unique_id "aihjjGsI_1SmacXGnH59sAAAAAw"], referer: http://www.shieldsenterprisesusallc.info
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bescared
2026-06-09 18:59:38
(1 day ago)
F2B - Malicious activity detected. URL Probing. -151302cd-
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 18:18:45
(1 day ago)
(mod_security) mod_security (id:210350) triggered by 124.156.205.199 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 124.156.205.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 14:18:41.668017 2026] [security2:error] [pid 384:tid 384] [client 124.156.205.199:58080] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||iiiip.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "iiiip.org"] [uri "/"] [unique_id "aihZASSofluEYUPwGLXObgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack