πΊπΈ
TPI-Abuse
2026-09-18 20:51:41
(6 hours ago)
(mod_security) mod_security (id:210350) triggered by 138.59.142.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 138.59.142.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 16:51:33.846049 2026] [security2:error] [pid 20802:tid 20802] [client 138.59.142.8:45813] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||guitarsouth.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "guitarsouth.com"] [uri "/"] [unique_id "aq2kVcfE4qA2Zh4KLNIVBAAAABI"], referer: https://quickseochecker.space/dir/natural-seo-backlinks-87134
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-18 18:55:42
(8 hours ago)
(mod_security) mod_security (id:210350) triggered by 138.59.142.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 138.59.142.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 14:55:37.617427 2026] [security2:error] [pid 27796:tid 27796] [client 138.59.142.8:37480] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||buildpower.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "buildpower.com"] [uri "/"] [unique_id "aq2JKb286CQycEPJgAs5EwAAABI"], referer: https://backlinkscheckers.store/dir/contextual-seo-backlinks-30517
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΉ
urnilxfgbez
2026-08-31 22:45:00
(2 weeks ago)
Last 24 Hours suspicious: (DPT=445|DPT=3389|DPT=22|DPT=3306|DPT=8080|DPT=23|DPT=5900|DPT=1433)
Port Scan
πΊπΈ
cwytech
2026-08-26 20:19:15
(3 weeks ago)
Fleet-wide ban from the Ghostfleet π». Triggered by scenario: cwy/pf-geofence-high.
Hacking
π«π·
Lat31320
2026-08-26 13:14:12
(3 weeks ago)
gate - SSH brute force
...
Brute-Force
SSH
πΊπΈ
kosada.com
2026-08-26 11:00:21
(3 weeks ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
π©πͺ
FD-IX
2026-08-26 00:29:46
(3 weeks ago)
Fail2Ban: Automated WooCommerce filter abuse from distributed botnet activity.
Bad Web Bot
π§π·
noconex
2026-08-25 01:17:09
(3 weeks ago)
Wazuh Alert | Rule ID: 100199 | Desc: Suricata: (ET SCAN Potential SSH Scan) detectado de 138.59.142 ...
show more
Wazuh Alert | Rule ID: 100199 | Desc: Suricata: (ET SCAN Potential SSH Scan) detectado de 138.59.142.8
show less
Port Scan
Brute-Force
SSH
πΈπ¬
garrymenata
2026-08-23 18:01:39
(3 weeks ago)
138.59.142.8 - - [24/Aug/2026:00:46:16 +0700] "GET / HTTP/1.1" 403 3258 "-" "Dalvik/2.1.0 (Linux; U; ...
show more
138.59.142.8 - - [24/Aug/2026:00:46:16 +0700] "GET / HTTP/1.1" 403 3258 "-" "Dalvik/2.1.0 (Linux; U; Android 12; Dcolor GD2 Build/SGZ4.240805.001)"
138.59.142.8 - - [24/Aug/2026:00:46:17 +0700] "GET / HTTP/1.1" 403 3258 "-" "Dalvik/2.1.0 (Linux; U; Android 12; Dcolor GD2 Build/SGZ4.240805.001)"
138.59.142.8 - - [24/Aug/2026:00:46:19 +0700] "GET / HTTP/1.1" 403 3258 "-" "Dalvik/2.1.0 (Linux; U; Android 12; Dcolor GD2 Build/SGZ4.240805.001)"
...
show less
DDoS Attack
Bad Web Bot
πΊπΈ
MPL
2026-08-23 02:08:30
(3 weeks ago)
tcp ports: 23,22 (20 or more attempts)
Port Scan
π§πΎ
sashan
2026-08-21 23:32:55
(4 weeks ago)
2026-08-22T02:31:15.257124+03:00 gate kernel: nftables: JAIL-SSH IN=wan OUT= MAC= SRC=138.59.142.8 D ...
show more
2026-08-22T02:31:15.257124+03:00 gate kernel: nftables: JAIL-SSH IN=wan OUT= MAC= SRC=138.59.142.8 DST=xxx.xxx.xxx.xxx LEN=60 TOS=0x00 PREC=0x00 TTL=50 ID=50007 DF PROTO=TCP SPT=49998 DPT=22 WINDOW=65535 RES=0x00 SYN URGP=0
...
show less
Port Scan
π«π·
security.rdmc.fr
2026-08-20 15:50:22
(4 weeks ago)
Port Scan Attack proto:TCP src:44534 dst:23
Port Scan
Anonymous
2026-08-20 09:55:57
(4 weeks ago)
Network service scanning detected by FortiGate; source quarantined.
Port Scan
πΊπΈ
RAP
2026-08-20 08:30:26
(4 weeks ago)
2026-08-20 08:30:26 UTC Unauthorized activity to TCP port 22. SSH
SSH
π§π·
noconex
2026-08-20 00:27:13
(4 weeks ago)
Wazuh Alert | Rule ID: 100199 | Desc: Suricata: (ET SCAN Potential SSH Scan) detectado de 138.59.142 ...
show more
Wazuh Alert | Rule ID: 100199 | Desc: Suricata: (ET SCAN Potential SSH Scan) detectado de 138.59.142.8
show less
Port Scan
Brute-Force
SSH