🇦🇺
nzhost.co.nz
2026-09-03 13:20:14
(2 days ago)
$f2bV_matches
Hacking
Brute-Force
🇩🇪
Reinhard
2026-08-28 08:44:10
(1 week ago)
Unknown activity, but too many attacks with too many users.
Hacking
🇺🇸
TPI-Abuse
2026-07-28 10:18:34
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 161.115.239.182 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.239.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 06:18:27.525300 2026] [security2:error] [pid 1703373:tid 1703409] [client 161.115.239.182:53915] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||briteh.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "briteh.com"] [uri "/nobledyn/index"] [unique_id "amiB897tMDjCyNL3Fjpy4gAAAAc"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-26 17:19:40
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 161.115.239.182 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.239.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 13:19:36.330077 2026] [security2:error] [pid 3478466:tid 3478466] [client 161.115.239.182:60131] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||prcomputersolutions.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "prcomputersolutions.com"] [uri "/"] [unique_id "amZBqCHIuBUhnXuMi-DwhAAAAAY"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-26 10:54:16
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 161.115.239.182 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.239.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 06:54:10.213375 2026] [security2:error] [pid 3762025:tid 3762025] [client 161.115.239.182:55897] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.handymanhall.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.handymanhall.com"] [uri "/"] [unique_id "amXnUnPSLzmBDMDYvZIEkQAAAAg"], referer: http://handymanhall.net/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-25 05:46:49
(1 month ago)
Unauthorized access (80/tcp/http)
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-07-12 10:07:50
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 161.115.239.182 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.239.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 12 06:07:41.999747 2026] [security2:error] [pid 5250:tid 5250] [client 161.115.239.182:39835] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.businessvaluationapp.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.businessvaluationapp.com"] [uri "/"] [unique_id "alNnbXqiY4eSQeaQiJaFXAAAABc"], referer: http://businessvaluecast.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-11 03:34:18
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 161.115.239.182 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.239.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 10 23:34:12.743330 2026] [security2:error] [pid 18312:tid 18312] [client 161.115.239.182:43225] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.affourtit-bowmaker.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.affourtit-bowmaker.com"] [uri "/"] [unique_id "alG5tJdaEVExOfp_ffvMpwAAAAE"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-06 18:54:40
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 161.115.239.182 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.239.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 06 14:54:36.307947 2026] [security2:error] [pid 3662:tid 3662] [client 161.115.239.182:53173] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||bowdens-landing.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "bowdens-landing.com"] [uri "/"] [unique_id "akv57PlYHaweipSbK8ZReQAAABQ"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-01 20:54:07
(2 months ago)
(mod_security) mod_security (id:210350) triggered by 161.115.239.182 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.239.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 16:54:00.100673 2026] [security2:error] [pid 32587:tid 32629] [client 161.115.239.182:56413] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.alzooma.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.alzooma.com"] [uri "/wiwox/accubal/accubal_c.htm"] [unique_id "akV-aNCJ0rH0vFUt2iLlDwAAAEQ"], referer: http://accubal.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
HandyTreff.de
2026-05-25 16:31:17
(3 months ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -39.847 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -39.847 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51
show less
Web App Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-05-24 04:57:20
(3 months ago)
(mod_security) mod_security (id:210350) triggered by 161.115.239.182 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.239.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 24 00:57:14.044644 2026] [security2:error] [pid 13413:tid 13427] [client 161.115.239.182:58897] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.flutelesson.nl|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.flutelesson.nl"] [uri "/nl"] [unique_id "ahKFKpLVA80Wis9Cj__zHQAAAAQ"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-22 15:25:08
(3 months ago)
(mod_security) mod_security (id:210350) triggered by 161.115.239.182 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.239.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 11:25:01.059653 2026] [security2:error] [pid 19494:tid 19494] [client 161.115.239.182:60967] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||eezinet.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "eezinet.net"] [uri "/"] [unique_id "ahB1TXderBzoN_-80vMfqAAAABM"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-16 03:32:26
(3 months ago)
(mod_security) mod_security (id:210350) triggered by 161.115.239.182 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.239.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 23:32:18.576646 2026] [security2:error] [pid 17896:tid 17896] [client 161.115.239.182:45995] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||trafficstopper.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "trafficstopper.com"] [uri "/"] [unique_id "agflQsRouW5ye0Z1V5p-qwAAAA4"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Buster
2026-05-08 11:51:00
(3 months ago)
Taking part in distributed attack from Perm Blocked ASN
Open Proxy
Brute-Force