🇦🇺
nzhost.co.nz
2026-09-03 13:20:42
(2 days ago)
$f2bV_matches
Hacking
Brute-Force
🇩🇪
Jochen Pretli
2026-08-29 01:33:11
(1 week ago)
connection to honeypot
Email Spam
Port Scan
🇳🇱
soverin
2026-07-30 19:22:09
(1 month ago)
Network scan on port 80
Email Spam
🇺🇸
TPI-Abuse
2026-07-24 10:35:32
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 161.115.234.20 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.234.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 06:35:24.205276 2026] [security2:error] [pid 118976:tid 118976] [client 161.115.234.20:33425] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||alosi.us|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "alosi.us"] [uri "/jt25"] [unique_id "amM_7G8nAmjXtXqIFThAbQAAAAE"], referer: http://jewelrytraders.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-11 21:51:05
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 161.115.234.20 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.234.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 11 17:50:56.841224 2026] [security2:error] [pid 16949:tid 16949] [client 161.115.234.20:58809] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||drkerryklett.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "drkerryklett.com"] [uri "/"] [unique_id "alK6wEMgrpAjSc85I-OTXgAAAAw"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
MPL
2026-07-06 21:19:13
(1 month ago)
tcp/443 (14 or more attempts)
Port Scan
🇺🇸
TPI-Abuse
2026-07-03 21:04:38
(2 months ago)
(mod_security) mod_security (id:210350) triggered by 161.115.234.20 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.234.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 17:04:31.743266 2026] [security2:error] [pid 28426:tid 28426] [client 161.115.234.20:47517] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||transporting.to|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "transporting.to"] [uri "/Adia/"] [unique_id "akgj3_5jSXq_VQuhLjA-5gAAAAg"], referer: http://adiasplace.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
nzhost.co.nz
2026-07-01 15:03:17
(2 months ago)
$f2bV_matches
Hacking
Brute-Force
🇨🇦
dispensight
2026-06-04 23:48:34
(3 months ago)
Automated scan (stale UA fingerprint): 1 GET request to help.dispensight.cloud. Paths: /. UA: Mozill ...
show more
Automated scan (stale UA fingerprint): 1 GET request to help.dispensight.cloud. Paths: /. UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51 Safari/537.36 Edg/99.0.1150.30. Server Mania Inc (Los Angeles, United States).
show less
Bad Web Bot
🇦🇺
MAGIC
2026-05-19 00:31:42
(3 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-05-16 12:03:29
(3 months ago)
(mod_security) mod_security (id:210350) triggered by 161.115.234.20 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.234.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 08:03:25.744334 2026] [security2:error] [pid 13859:tid 13873] [client 161.115.234.20:49949] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||osp.schoprint.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "osp.schoprint.com"] [uri "/"] [unique_id "aghdDcNBiyyA9loI_F5WogAAAUw"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
HandyTreff.de
2026-05-16 01:58:38
(3 months ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -33.782 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -33.782 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51
show less
Web App Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-05-08 01:44:58
(3 months ago)
(mod_security) mod_security (id:210350) triggered by 161.115.234.20 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.234.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 21:44:53.307016 2026] [security2:error] [pid 19251:tid 19251] [client 161.115.234.20:51285] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||cafink.name|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "cafink.name"] [uri "/$1"] [unique_id "af1AFZtM0xRTTHSP9vtG3wAAAAg"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Flo Flo
2026-04-30 04:06:31
(4 months ago)
161.115.234.20 - - - [30/Apr/2026:06:06:29 +0200] "flad.xyz" "GET / HTTP/2.0" 444 0 "https://www.goo ...
show more
161.115.234.20 - - - [30/Apr/2026:06:06:29 +0200] "flad.xyz" "GET / HTTP/2.0" 444 0 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51 Safari/537.36 Edg/99.0.1150.30" 0.000
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-04-29 19:40:27
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 161.115.234.20 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.234.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 29 15:40:21.222241 2026] [security2:error] [pid 18654:tid 18654] [client 161.115.234.20:35525] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||scadainthecloud.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "scadainthecloud.com"] [uri "/"] [unique_id "afJepSOwByaT8D6YKwR8swAAAAs"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack