🇺🇸
TPI-Abuse
2026-09-21 11:10:38
(39 minutes ago)
(mod_security) mod_security (id:210730) triggered by 138.0.65.136 (138.0.65.136-static.onnettelecom. ...
show more
(mod_security) mod_security (id:210730) triggered by 138.0.65.136 (138.0.65.136-static.onnettelecom.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 07:10:03.412154 2026] [security2:error] [pid 11743:tid 11767] [client 138.0.65.136:30696] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aassone.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aassone.com"] [uri "/bak/app.db"] [unique_id "arEQiwxqkv3aGDMwxZohLAAAAQw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Tilellit.PRO
2026-09-20 04:27:54
(1 day ago)
WooCommerce YITH AJAX Filder product_cat filter flood attempt with taxonomies
DDoS Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-20 02:59:00
(1 day ago)
(mod_security) mod_security (id:210350) triggered by 138.0.65.136 (138.0.65.136-static.onnettelecom. ...
show more
(mod_security) mod_security (id:210350) triggered by 138.0.65.136 (138.0.65.136-static.onnettelecom.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 22:58:55.874455 2026] [security2:error] [pid 31303:tid 31303] [client 138.0.65.136:61489] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||usaangelinvestors.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "usaangelinvestors.com"] [uri "/"] [unique_id "aq9L729rL76HQaXXhZGI0AAAAAU"], referer: https://customhumanrobots.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-17 04:48:34
(4 days ago)
(mod_security) mod_security (id:210350) triggered by 138.0.65.136 (138.0.65.136-static.onnettelecom. ...
show more
(mod_security) mod_security (id:210350) triggered by 138.0.65.136 (138.0.65.136-static.onnettelecom.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 00:48:27.481305 2026] [security2:error] [pid 17028:tid 17028] [client 138.0.65.136:30952] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||ggisoftware.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "ggisoftware.com"] [uri "/"] [unique_id "aqtxG9Hz9htvbkKy-AhT3gAAAAw"], referer: https://bestofthefirstcoast.com/all/1187/30.html
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
ALPHANET
2026-09-16 07:05:03
(5 days ago)
Botnet or web spider not respecting robots.txt
DDoS Attack
Exploited Host
🇺🇸
kosada.com
2026-07-27 00:34:41
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
🇩🇪
pltcldvlpr
2026-06-15 07:14:29
(3 months ago)
Bogus Useragent: 138.0.65.136 - - [14/Jun/2026:15:24:03 +0200] "GET /protocol?id=bb_6_81¶graph=4 ...
show more
Bogus Useragent: 138.0.65.136 - - [14/Jun/2026:15:24:03 +0200] "GET /protocol?id=bb_6_81¶graph=490881&seq=808 HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/5.0)" asn=262595 org="OnNet Telecomunica\xC3\xA7\xC3\xB5es LTDA" country=BR
...
show less
Bad Web Bot
Anonymous
2025-11-25 20:50:05
(9 months ago)
scanning http requests from known botnet
Web App Attack
Anonymous
2025-11-18 23:22:11
(10 months ago)
scanning http requests from known botnet
Web App Attack
🇧🇷
OuverneY
2025-08-26 14:38:48
(1 year ago)
Port Scan