๐บ๐ธ
TPI-Abuse
2026-09-14 09:00:29
(4 days ago)
(mod_security) mod_security (id:210350) triggered by 161.115.234.146 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.234.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 05:00:24.890217 2026] [security2:error] [pid 22350:tid 22350] [client 161.115.234.146:38235] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||periodpiano.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "periodpiano.org"] [uri "/"] [unique_id "aqe3qAUtjfWXs3iAhcf11QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 18:49:38
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 161.115.234.146 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.234.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 14:49:33.687657 2026] [security2:error] [pid 2508193:tid 2508272] [client 161.115.234.146:52855] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.howardhallis.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.howardhallis.com"] [uri "/broof"] [unique_id "ameoPXif0AlgVAy5PLNF4wAAAcI"], referer: http://broof.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 15:06:30
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 161.115.234.146 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.234.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 11:06:25.877325 2026] [security2:error] [pid 2780703:tid 2780703] [client 161.115.234.146:34767] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.sjtent.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.sjtent.com"] [uri "/cat-18-1-79/2-x-7-bone-shaped-dog-breeds.htm"] [unique_id "amYicchAPZZA9hvfsrKYzwAAAAo"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-07-24 20:29:08
(1 month ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after repeated server-error fuzzing. Eviden ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after repeated server-error fuzzing. Evidence: Repeated Server Errors (500)
show less
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 15:52:03
(2 months ago)
(mod_security) mod_security (id:210350) triggered by 161.115.234.146 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.234.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 11:51:57.755665 2026] [security2:error] [pid 10627:tid 10632] [client 161.115.234.146:38939] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||rawsynergy.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "rawsynergy.com"] [uri "/store"] [unique_id "ajv9HcDb1oDOP_OV8gAn3AAAAAI"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2026-05-28 00:13:38
(3 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-19 13:21:02
(3 months ago)
(mod_security) mod_security (id:210350) triggered by 161.115.234.146 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.234.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 19 09:20:54.921018 2026] [security2:error] [pid 25853:tid 25853] [client 161.115.234.146:35219] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.forestvalleyfarm.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.forestvalleyfarm.com"] [uri "/"] [unique_id "agxjtgTuNaUCPACSZArfVQAAAAg"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-19 00:08:47
(3 months ago)
(mod_security) mod_security (id:210350) triggered by 161.115.234.146 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.234.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 18 20:08:41.399535 2026] [security2:error] [pid 6714:tid 6720] [client 161.115.234.146:60563] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.ethicmark.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.ethicmark.org"] [uri "/"] [unique_id "aguqCQMeUbWkqhPVzOn9rQAAAUQ"], referer: http://ethicmark.net/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-17 04:21:57
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 161.115.234.146 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.234.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 00:21:49.750855 2026] [security2:error] [pid 25283:tid 25283] [client 161.115.234.146:59925] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||rondeal.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "rondeal.com"] [uri "/"] [unique_id "aglCXVs2H1d2aVwbQDojfwAAABE"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 20:30:19
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 161.115.234.146 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.234.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 16:30:14.821692 2026] [security2:error] [pid 5480:tid 5480] [client 161.115.234.146:54335] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||travelsupersonic.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "travelsupersonic.com"] [uri "/"] [unique_id "af5H1hgvbyVv8l3_2_cLoQAAAAk"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-30 03:52:11
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 161.115.234.146 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.234.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 29 23:52:06.941284 2026] [security2:error] [pid 30603:tid 30628] [client 161.115.234.146:45589] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.financialanalyst.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.financialanalyst.org"] [uri "/"] [unique_id "afLR5hCfZJrkBwG-2Vu1qAAAAJc"], referer: http://aafmboard.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-28 05:51:18
(4 months ago)
Malicious activity detected
Hacking
Web App Attack
๐ญ๐ฐ
Mehmet_The_Script_Kiddie
2026-02-07 14:01:11
(7 months ago)
AUTOMATED REPORT: URL probing: /
Bad Web Bot
Web App Attack
๐ฌ๐ง
spamverify.com
2025-11-22 00:05:59
(9 months ago)
Honeypot Hit: Port Scan (443) HTTPS
Web Spam
Blog Spam
Bad Web Bot
Web App Attack