πΊπΈ
Brian
2026-04-08 20:30:00
(4 months ago)
154.16.71.11
SQL Injection
π³π±
jjnxpct
2026-01-22 05:30:43
(7 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /en/component/avendre/ (Rule ID: 920210) - Multiple/Conflicting Connection Header Data Found
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-21 04:40:35
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 154.16.71.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 154.16.71.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 20 23:40:27.999806 2026] [security2:error] [pid 23236:tid 23236] [client 154.16.71.11:57495] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.r-390a.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.r-390a.net"] [uri "/Redux/04_Apr_05.pdf"] [unique_id "aXBYu8ZS_nJe6mObMvqW5QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-01-21 01:41:48
(7 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 24
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-21 00:41:46
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 154.16.71.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 154.16.71.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 20 19:41:16.802716 2026] [security2:error] [pid 6741:tid 6741] [client 154.16.71.11:59995] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||chinookdrivingacademy.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "chinookdrivingacademy.com"] [uri "/Contract_For_Life.htm"] [unique_id "aXAgrM7HI-F6g0H8ebIpLwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-20 23:53:57
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 154.16.71.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 154.16.71.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 20 18:53:54.193490 2026] [security2:error] [pid 7410:tid 7410] [client 154.16.71.11:40483] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||cauchosindustrialesespeciales.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "cauchosindustrialesespeciales.com"] [uri "/"] [unique_id "aXAVkko92bvG7rXZPIWMAAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-20 23:32:22
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 154.16.71.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 154.16.71.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 20 18:32:16.150771 2026] [security2:error] [pid 10160:tid 10160] [client 154.16.71.11:37967] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.cybersoftware.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.cybersoftware.org"] [uri "/"] [unique_id "aXAQgDqIhpSvcSnQQ_CZBwAAABY"], referer: http://get.globalprime.com/afs/come.php?atype=1&brandid=3&brandid=%27&cid=521&ctgid=1003
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-20 01:34:42
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 154.16.71.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 154.16.71.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 19 20:34:13.410392 2026] [security2:error] [pid 24411:tid 24468] [client 154.16.71.11:40455] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.seips.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.seips.org"] [uri "/viewitem.php"] [unique_id "aW7blbX3eOkUxb8GjOS50wAAAcM"], referer: http://www.seips.org/viewitem.php?ID=421%27++AND+GTID_SUBSET%28CAST%28VERSION%28%29+AS+CHAR%29%2C0x7e%29+%27
show less
Brute-Force
Bad Web Bot
Web App Attack
π±π»
garmtech.com
2026-01-19 21:35:51
(7 months ago)
IM360 WAF: SQL Injection Attack: Common DB Names Detected
SQL Injection
Anonymous
2026-01-19 21:30:04
(7 months ago)
| Multiple SQL injection attempts from same source ip.(multiple servers)
Hacking
SQL Injection
Web App Attack