๐ฉ๐ช
LRob
2026-09-14 08:47:20
(6 days ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: / | 2026-09-14 08:47 UTC
show less
Bad Web Bot
๐จ๐ฟ
ddw
2026-09-14 00:16:37
(1 week ago)
Access Violation Attempts - Multiple 403 Forbidden responses.
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-06 04:24:43
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 161.115.239.96 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.239.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 00:24:38.609139 2026] [security2:error] [pid 22391:tid 22391] [client 161.115.239.96:46287] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.spectorworld.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.spectorworld.com"] [uri "/contact"] [unique_id "apzrBlBigQ-MgWi5xmuhpAAAAAI"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Jochen Pretli
2026-08-26 16:44:47
(3 weeks ago)
connection to honeypot
Email Spam
Port Scan
๐ญ๐ฐ
Mehmet_The_Script_Kiddie
2026-08-26 06:43:39
(3 weeks ago)
AUTOMATED REPORT: URL probing: /
Bad Web Bot
Web App Attack
๐บ๐ธ
jkhorvath.com
2026-08-15 17:52:35
(1 month ago)
Request for URL /team
Phishing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 08:11:08
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 161.115.239.96 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.239.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 04:11:02.228312 2026] [security2:error] [pid 559107:tid 559107] [client 161.115.239.96:47775] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.b9k9.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.b9k9.com"] [uri "/Seed.html"] [unique_id "amhkFtCXudMDu2eGxiLoDgAAAAk"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 18:54:54
(2 months ago)
(mod_security) mod_security (id:210350) triggered by 161.115.239.96 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.239.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 14:54:48.810737 2026] [security2:error] [pid 7671:tid 7671] [client 161.115.239.96:46367] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.voodooshop.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.voodooshop.com"] [uri "/team.html"] [unique_id "alp6eMoqbQo1Jl5_8hjEnAAAABU"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 22:17:38
(2 months ago)
(mod_security) mod_security (id:210350) triggered by 161.115.239.96 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.239.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 18:17:31.506348 2026] [security2:error] [pid 18767:tid 18767] [client 161.115.239.96:47753] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||scc1.us|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "scc1.us"] [uri "/about"] [unique_id "allYe3ZyM4a1PA_ZTi-GRQAAAAY"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 01:22:26
(2 months ago)
(mod_security) mod_security (id:210350) triggered by 161.115.239.96 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.239.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 21:22:21.418716 2026] [security2:error] [pid 22422:tid 22422] [client 161.115.239.96:49455] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.accordionfactory.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.accordionfactory.com"] [uri "/Concerto/Colombo"] [unique_id "algyTefFsl_xBDkVpcbcMQAAABE"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-05 07:48:17
(2 months ago)
(mod_security) mod_security (id:210350) triggered by 161.115.239.96 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.239.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 05 03:48:08.930196 2026] [security2:error] [pid 21717:tid 21717] [client 161.115.239.96:54781] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.nashes.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.nashes.net"] [uri "/"] [unique_id "akoMOP1KkgabRSWwPVh0cQAAABY"], referer: http://franknash.net/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
2048
2026-05-30 06:17:54
(3 months ago)
2026-05-30T08:17:52.078097+02:00 machodeer kernel: [2829789.810770] [UFW BLOCK] IN=ens3 OUT= MAC=RED ...
show more
2026-05-30T08:17:52.078097+02:00 machodeer kernel: [2829789.810770] [UFW BLOCK] IN=ens3 OUT= MAC=REDACTED SRC=161.115.239.96 DST=REDACTED LEN=60 TOS=0x00 PREC=0x00 TTL=49 ID=4329 DF PROTO=TCP SPT=53207 DPT=80 WINDOW=64240 RES=0x00 SYN URGP=0
2026-05-30T08:17:53.084225+02:00 machodeer kernel: [2829790.816891] [UFW BLOCK] IN=ens3 OUT= MAC=REDACTED SRC=161.115.239.96 DST=REDACTED LEN=60 TOS=0x00 PREC=0x00 TTL=49 ID=4330 DF PROTO=TCP SPT=53207 DPT=80 WINDOW=64240 RES=0x00 SYN URGP=0
2026-05-30T08:17:54.108289+02:00 machodeer kernel: [2829791.840958] [UFW BLOCK] IN=ens3 OUT= MAC=REDACTED SRC=161.115.239.96 DST=REDACTED LEN=60 TOS=0x00 PREC=0x00 TTL=49 ID=4331 DF PROTO=TCP SPT=53207 DPT=80 WINDOW=64240 RES=0x00 SYN URGP=0
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-26 17:27:12
(3 months ago)
(mod_security) mod_security (id:210350) triggered by 161.115.239.96 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 161.115.239.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 13:27:05.116719 2026] [security2:error] [pid 32532:tid 32532] [client 161.115.239.96:40035] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||hienle.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "hienle.com"] [uri "/"] [unique_id "ahXX6UWvmB0i0lvFFWB91wAAAAA"], referer: http://hienle.net/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฐ
sbk97 (https://sayor.net)
2026-05-26 11:02:13
(3 months ago)
HTTP attack observed: GET / HTTP/2.0 | status=200 | response_size=59104
Port Scan
๐ต๐ฐ
sbk97 (https://sayor.net)
2026-05-26 11:02:13
(3 months ago)
HTTP attacks observed: GET / HTTP/2.0 | status=200
Port Scan