Anonymous
2026-07-24 12:19:29
(5 hours ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
Anonymous
2026-07-21 20:34:05
(2 days ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 10:15:27
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 170.231.250.185 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 170.231.250.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 06:15:19.027741 2026] [security2:error] [pid 31162:tid 31162] [client 170.231.250.185:34955] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||indyham.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "indyham.com"] [uri "/about"] [unique_id "abvMtz6B1HhIp_fqEzZADwAAAAI"], referer: https://indyham.com/about
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-18 15:12:45
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 170.231.250.185 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 170.231.250.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 18 11:12:37.537110 2026] [security2:error] [pid 12542:tid 12542] [client 170.231.250.185:52257] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||tomslawmd.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "tomslawmd.com"] [uri "/about/"] [unique_id "abrA5Utt3bFtWRhxUKDGxAAAABQ"], referer: https://tomslawmd.com/about/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-03 15:51:14
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 170.231.250.185 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 170.231.250.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 03 10:50:05.124481 2026] [security2:error] [pid 30211:tid 30211] [client 170.231.250.185:54501] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.northfortworthalliance.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.northfortworthalliance.com"] [uri "/company"] [unique_id "aacDLa0ir0pOWQRcWL4XNQAAABI"], referer: https://www.northfortworthalliance.com/company
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-08-04 15:28:02
(11 months ago)
Botnet - login attempts with leaked random user/pass lists
Hacking
Brute-Force
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-04-21 14:19:41
(1 year ago)
WP Login Scan Activities
Web App Attack
Anonymous
2025-02-24 23:44:16
(1 year ago)
wordpress-trap
Web App Attack