Anonymous
2023-11-22 13:44:54
(2 years ago)
disguised BOT - Blocked
Bad Web Bot
πΊπΈ
TPI-Abuse
2023-11-21 10:25:12
(2 years ago)
(mod_security) mod_security (id:210350) triggered by 154.91.138.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 154.91.138.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 21 05:25:07.312042 2023] [security2:error] [pid 911] [client 154.91.138.8:37530] [client 154.91.138.8] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||advmach.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "advmach.com"] [uri "/"] [unique_id "ZVyFg1BZzJ82zxMMddMWqgAAAAs"], referer: http://advmach.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2023-11-21 08:42:58
(2 years ago)
(mod_security) mod_security (id:210350) triggered by 154.91.138.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 154.91.138.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 21 03:42:53.177630 2023] [security2:error] [pid 21121] [client 154.91.138.8:39668] [client 154.91.138.8] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||americanacademyofteachersofsinging.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "americanacademyofteachersofsinging.org"] [uri "/"] [unique_id "ZVxtjcJ_VUXNeYtQgpivfwAAAA4"], referer: http://americanacademyofteachersofsinging.org/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2023-11-17 14:46:06
(2 years ago)
Disguised BOT - PERM BANNED IP RAnge - Continual abuses
Hacking
Brute-Force
Bad Web Bot
π©πͺ
PetrHu
2023-11-17 09:50:06
(2 years ago)
154.91.138.8 - - [17/Nov/2023:12:50:05 +0300] chia.ctrlaltdel.ch "GET /Public/Home/images/ren.png HT ...
show more
154.91.138.8 - - [17/Nov/2023:12:50:05 +0300] chia.ctrlaltdel.ch "GET /Public/Home/images/ren.png HTTP/1.1" 404 178 0.000 "http://chia.ctrlaltdel.ch/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36"
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2023-11-17 04:03:38
(2 years ago)
(mod_security) mod_security (id:210350) triggered by 154.91.138.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 154.91.138.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 16 23:03:30.441973 2023] [security2:error] [pid 8205] [client 154.91.138.8:52930] [client 154.91.138.8] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||web218.dnchosting.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "web218.dnchosting.com"] [uri "/"] [unique_id "ZVbmEpvM3bSbA0P7vx-QzwAAAAk"], referer: http://web218.dnchosting.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2023-11-16 18:25:36
(2 years ago)
(mod_security) mod_security (id:210350) triggered by 154.91.138.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 154.91.138.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 16 13:25:30.361125 2023] [security2:error] [pid 2431] [client 154.91.138.8:35304] [client 154.91.138.8] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||brent.ph|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "brent.ph"] [uri "/"] [unique_id "ZVZemkt9TM0mhSoiZ8Z7QQAAAA8"], referer: http://brentphillips.io/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2023-11-16 18:09:20
(2 years ago)
(mod_security) mod_security (id:210350) triggered by 154.91.138.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 154.91.138.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 16 13:09:12.529504 2023] [security2:error] [pid 16479] [client 154.91.138.8:32952] [client 154.91.138.8] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.benshermanguitar.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.benshermanguitar.com"] [uri "/classical/"] [unique_id "ZVZayEuCI5WIulZfWCI_MgAAAAA"], referer: http://benshermanclassicalguitar.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2023-11-16 17:54:15
(2 years ago)
(mod_security) mod_security (id:210350) triggered by 154.91.138.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 154.91.138.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 16 12:54:13.868518 2023] [security2:error] [pid 21322] [client 154.91.138.8:34388] [client 154.91.138.8] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||artbytracyjane.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "artbytracyjane.com"] [uri "/"] [unique_id "ZVZXRd5LR7zQereD8wn-DgAAAAU"], referer: http://artbytracyjane.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2023-11-16 17:23:34
(2 years ago)
(mod_security) mod_security (id:210350) triggered by 154.91.138.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 154.91.138.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 16 12:23:28.902888 2023] [security2:error] [pid 25778] [client 154.91.138.8:43826] [client 154.91.138.8] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||1005kixfm.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "1005kixfm.com"] [uri "/"] [unique_id "ZVZQEPPOkJDH4z2YcqoO6AAAAA0"], referer: http://1005kixfm.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2023-11-16 16:39:11
(2 years ago)
(mod_security) mod_security (id:210350) triggered by 154.91.138.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 154.91.138.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 16 11:39:06.123743 2023] [security2:error] [pid 4997] [client 154.91.138.8:43406] [client 154.91.138.8] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||acmax.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "acmax.com"] [uri "/"] [unique_id "ZVZFqjHq7wHO2FKBk6JoYwAAAAo"], referer: http://acmax.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2023-11-16 15:53:09
(2 years ago)
(mod_security) mod_security (id:210350) triggered by 154.91.138.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 154.91.138.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 16 10:53:01.323135 2023] [security2:error] [pid 6781] [client 154.91.138.8:54910] [client 154.91.138.8] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||web99.dnchosting.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "web99.dnchosting.com"] [uri "/"] [unique_id "ZVY63ff4CcHmx9A_FjT6LAAAAAI"], referer: http://web99.dnchosting.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2023-11-16 12:32:39
(2 years ago)
(mod_security) mod_security (id:210350) triggered by 154.91.138.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 154.91.138.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 16 07:32:34.992505 2023] [security2:error] [pid 24483] [client 154.91.138.8:53712] [client 154.91.138.8] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||autobee.biz|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "autobee.biz"] [uri "/"] [unique_id "ZVYL4hJRVAUOR7cPT9R_9gAAAAs"], referer: http://autobee.biz/
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
cybertechsec
2023-11-16 12:09:24
(2 years ago)
Wordpress_Attack
Bad Web Bot
πΊπΈ
TPI-Abuse
2023-11-16 11:48:58
(2 years ago)
(mod_security) mod_security (id:210350) triggered by 154.91.138.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 154.91.138.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 16 06:48:54.008855 2023] [security2:error] [pid 27935] [client 154.91.138.8:32972] [client 154.91.138.8] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||artocratic.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "artocratic.com"] [uri "/"] [unique_id "ZVYBpmUvl5_wPj1fl3-UGgAAAAw"], referer: http://artocratic.com/
show less
Brute-Force
Bad Web Bot
Web App Attack