🇩🇪
ghostwarriors
2026-08-31 07:50:24
(3 days ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ksol-hostmaster
2026-08-31 07:38:46
(3 days ago)
2026/08/31 09:38:46 [error] 76877#161168: *1198952 access forbidden by rule, client: 161.115.234.161 ...
show more
2026/08/31 09:38:46 [error] 76877#161168: *1198952 access forbidden by rule, client: 161.115.234.161, server: hondaforum.hu, request: "GET / HTTP/2.0", host: "hondaforum.hu", referrer: "https://www.google.com"
...
show less
Web Spam
🇦🇺
Bay13
2026-08-30 23:57:15
(4 days ago)
CrowdSec:custom/http-backdoors-attempts
Web App Attack
🇺🇸
TPI-Abuse
2026-08-18 04:54:06
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 161.115.234.161 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 161.115.234.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 00:53:59.002376 2026] [security2:error] [pid 30610:tid 30610] [client 161.115.234.161:43131] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||perthdps.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "perthdps.com"] [uri "/convicts/[email protected] "] [unique_id "aoPlZqHtucD3AyVZ0QqKzgAAAAg"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-16 02:06:09
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 161.115.234.161 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.234.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 22:06:04.783356 2026] [security2:error] [pid 1150:tid 1150] [client 161.115.234.161:52169] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||aliciagrant.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "aliciagrant.com"] [uri "/contact"] [unique_id "aoEbDPhUC-RC1xkf_HWdoQAAAAU"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
jkhorvath.com
2026-08-15 17:52:34
(2 weeks ago)
Request for URL /team
Phishing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-08 07:46:16
(3 weeks ago)
(mod_security) mod_security (id:210350) triggered by 161.115.234.161 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.234.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 08 03:46:08.839070 2026] [security2:error] [pid 3658006:tid 3658006] [client 161.115.234.161:38035] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.alexetjeremy.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.alexetjeremy.com"] [uri "/about"] [unique_id "anbewIK3u81oZThFfERBtAAAABA"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
Michael McCarthy
2026-07-28 04:08:19
(1 month ago)
Web Spam
🇳🇱
hxsain
2026-07-27 15:58:08
(1 month ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /assets/Login-BsgZCIwX.js | UA: Empty string • Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-07-24 23:23:01
(1 month ago)
Malicious activity detected
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-07-15 07:49:56
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 161.115.234.161 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.234.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 03:49:49.442632 2026] [security2:error] [pid 6071:tid 6071] [client 161.115.234.161:46267] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||IC1surplus.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "ic1surplus.com"] [uri "/"] [unique_id "alc7ndhcbarTo-z4EmoxBQAAAAM"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-09 10:05:23
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 161.115.234.161 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.234.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 09 06:05:18.091261 2026] [security2:error] [pid 19463:tid 19463] [client 161.115.234.161:53559] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.voodooshop.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.voodooshop.com"] [uri "/about.html"] [unique_id "ak9yXjnXdMualgbZ93XvAwAAAAM"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-08 22:00:32
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 161.115.234.161 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.234.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 08 18:00:23.051618 2026] [security2:error] [pid 24823:tid 24823] [client 161.115.234.161:48899] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||dhappraisalservices.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "dhappraisalservices.com"] [uri "/"] [unique_id "ak7Id55_H-5wZ9fFTQNqPQAAAA4"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-21 23:26:32
(2 months ago)
(mod_security) mod_security (id:210350) triggered by 161.115.234.161 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.234.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 19:26:25.403781 2026] [security2:error] [pid 7748:tid 7748] [client 161.115.234.161:51999] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||aares2025.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "aares2025.net"] [uri "/"] [unique_id "ajhzIRtequJZ5mZtMQPz7AAAAA8"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-21 03:27:41
(2 months ago)
(mod_security) mod_security (id:210350) triggered by 161.115.234.161 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.234.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 23:27:38.335369 2026] [security2:error] [pid 1714:tid 1714] [client 161.115.234.161:34619] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||keystonestandard.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "keystonestandard.com"] [uri "/index.php"] [unique_id "ajdaKgG68EOoFKHmXQiqygAAAAo"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack