๐บ๐ธ
TPI-Abuse
2026-09-24 15:44:44
(1 day ago)
(mod_security) mod_security (id:210350) triggered by 161.115.234.227 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.234.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 11:44:36.653651 2026] [security2:error] [pid 14491:tid 14491] [client 161.115.234.227:54355] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||betweentwotearsandshit.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "betweentwotearsandshit.com"] [uri "/"] [unique_id "arVFZPA8z2yX0SYD9761kgAAAAI"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-13 14:45:07
(1 week ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: / | 2026-09-13 14:45 UTC
show less
Bad Web Bot
๐ฉ๐ช
Jochen Pretli
2026-08-29 09:55:15
(3 weeks ago)
connection to honeypot
Email Spam
Port Scan
Anonymous
2026-07-12 09:28:02
(2 months ago)
Malicious activity detected
Hacking
Web App Attack
Anonymous
2026-07-10 18:44:01
(2 months ago)
Malicious activity detected
Hacking
Web App Attack
๐ฉ๐ช
Reinhard
2026-07-10 11:13:38
(2 months ago)
Unknown activity, but too many attacks with too many users.
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-06 10:31:34
(2 months ago)
(mod_security) mod_security (id:210350) triggered by 161.115.234.227 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.234.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 06 06:31:30.879235 2026] [security2:error] [pid 7408:tid 7408] [client 161.115.234.227:47683] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||sparkleluminous.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "sparkleluminous.com"] [uri "/"] [unique_id "akuEAh1LoszSm4QlsrSkjQAAAA4"], referer: http://ohfrit.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-03 11:46:09
(2 months ago)
(mod_security) mod_security (id:210350) triggered by 161.115.234.227 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.234.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 07:46:05.668261 2026] [security2:error] [pid 12894:tid 12894] [client 161.115.234.227:42517] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||clarktec.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "clarktec.com"] [uri "/khclark.htm"] [unique_id "akeg_UEJzvmT1xauKehw7gAAAAM"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2026-05-28 00:13:40
(3 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ฉ๐ช
HandyTreff.de
2026-05-26 04:26:29
(4 months ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -42.569 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -42.569 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-20 03:43:44
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 161.115.234.227 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.234.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 19 23:43:39.697000 2026] [security2:error] [pid 4600:tid 4600] [client 161.115.234.227:35667] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||4azadi.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "4azadi.org"] [uri "/"] [unique_id "ag0t6-a6XH1YUw1ynbvqhQAAABI"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-16 13:09:02
(4 months ago)
Malicious activity detected
Hacking
Web App Attack
๐ฌ๐ง
2048
2026-05-01 12:50:59
(4 months ago)
2026-05-01T14:50:55.510213+02:00 machodeer kernel: [347770.433342] [UFW BLOCK] IN=ens3 OUT= MAC=REDA ...
show more
2026-05-01T14:50:55.510213+02:00 machodeer kernel: [347770.433342] [UFW BLOCK] IN=ens3 OUT= MAC=REDACTED SRC=161.115.234.227 DST=REDACTED LEN=60 TOS=0x00 PREC=0x00 TTL=49 ID=59758 DF PROTO=TCP SPT=57655 DPT=443 WINDOW=64240 RES=0x00 SYN URGP=0
2026-05-01T14:50:56.568899+02:00 machodeer kernel: [347771.492702] [UFW BLOCK] IN=ens3 OUT= MAC=REDACTED SRC=161.115.234.227 DST=REDACTED LEN=60 TOS=0x00 PREC=0x00 TTL=49 ID=59759 DF PROTO=TCP SPT=57655 DPT=443 WINDOW=64240 RES=0x00 SYN URGP=0
2026-05-01T14:50:57.593556+02:00 machodeer kernel: [347772.517375] [UFW BLOCK] IN=ens3 OUT= MAC=REDACTED SRC=161.115.234.227 DST=REDACTED LEN=60 TOS=0x00 PREC=0x00 TTL=49 ID=59760 DF PROTO=TCP SPT=57655 DPT=443 WINDOW=64240 RES=0x00 SYN URGP=0
show less
Port Scan