πΊπΈ
stechusa
2026-05-01 09:30:32
(1 month ago)
[Askari] | country=CN | Behavior: HTTP/1.1 over TLS, Concurrent page load during attack, No referrer ...
show more
[Askari] | country=CN | Behavior: HTTP/1.1 over TLS, Concurrent page load during attack, No referrer on deep pages, Targeting specific pages
show less
Bad Web Bot
DDoS Attack
π¦πΉ
centurion
2026-03-27 16:48:59
(2 months ago)
Unauthorized attempt on siem [21/tcp]
Source port: 12085
TTL: 50
Packet length: 44
TOS: 0x00
https:/ ...
show more
Unauthorized attempt on siem [21/tcp]
Source port: 12085
TTL: 50
Packet length: 44
TOS: 0x00
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
FTP Brute-Force
Brute-Force
Anonymous
2026-03-27 15:36:32
(2 months ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
πΊπΈ
kosada.com
2025-09-25 16:39:29
(9 months ago)
Web bot: DDoS
DDoS Attack
Bad Web Bot
πΊπΈ
TPI-Abuse
2025-09-24 22:56:08
(9 months ago)
(mod_security) mod_security (id:217291) triggered by 124.230.120.10 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:217291) triggered by 124.230.120.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 24 18:56:03.395541 2025] [security2:error] [pid 32185:tid 32185] [client 124.230.120.10:48829] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(\\\\n|\\\\r)" at ARGS_NAMES:\\r\\n4\\r\\nm. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "145"] [id "217291"] [rev "2"] [msg "HTTP Header Injection Attack via payload (CR/LF detected)||kountz.org|F|2"] [data "Matched Data: \\x0d found within ARGS_NAMES:\\x5cr\\x5cn4\\x5cr\\x5cnm: \\x0d\\x0a4\\x0d\\x0am"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "kountz.org"] [uri "/calendar.php"] [unique_id "aNR3A1GhjfHtHZ_2YPnHWgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-22 15:25:44
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 124.230.120.10 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 124.230.120.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 22 11:25:37.365720 2025] [security2:error] [pid 17914:tid 17914] [client 124.230.120.10:61433] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.passwordresearch.com|F|4"] [data "close, keep-alive"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.passwordresearch.com"] [uri "/papers/paper153.html"] [unique_id "aNFqcTdGiDSCwx96w-0bhgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-22 05:02:06
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 124.230.120.10 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 124.230.120.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 22 01:02:01.928705 2025] [security2:error] [pid 32087:tid 32087] [client 124.230.120.10:27678] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.renju.net|F|4"] [data "close, keep-alive"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.renju.net"] [uri "/game/149350/"] [unique_id "aNDYSa6SOPWR-QK5lOYaFwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-15 17:20:19
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 124.230.120.10 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 124.230.120.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 15 13:20:12.557953 2025] [security2:error] [pid 30099:tid 30099] [client 124.230.120.10:33476] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.renju.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.renju.net"] [uri "/tournament/150/game/92041/"] [unique_id "aMhKzG88VbIcULQZ5JcHpwAAAAA"], referer: https://www.renju.net/game/92041/
show less
Brute-Force
Bad Web Bot
Web App Attack