๐บ๐ธ
TPI-Abuse
2026-09-17 03:27:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 170.231.250.39 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 170.231.250.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 23:27:50.959270 2026] [security2:error] [pid 691:tid 691] [client 170.231.250.39:45793] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "laydox.com"] [uri "/.env"] [unique_id "aqteNusM8R3na2XbuTWNkgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-04 11:26:29
(1 month ago)
FortiWeb WAF: 24 attacks detected. Threat Score: 10646730. Types: Client Management(12), Signature D ...
show more
FortiWeb WAF: 24 attacks detected. Threat Score: 10646730. Types: Client Management(12), Signature Detection(12). Origin: United States.
show less
Web App Attack
Anonymous
2026-07-24 12:20:39
(1 month ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
Anonymous
2026-07-21 20:02:35
(1 month ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-18 10:23:29
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 170.231.250.39 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 170.231.250.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 18 05:23:21.340735 2025] [security2:error] [pid 20577:tid 20577] [client 170.231.250.39:60757] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.teleplussolutions.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.teleplussolutions.com"] [uri "/services/telecom-audit"] [unique_id "aUPWGW8LI5JiXCq44qluzQAAAB0"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-28 02:11:21
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 170.231.250.39 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 170.231.250.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 27 21:11:15.933396 2025] [security2:error] [pid 23608:tid 23608] [client 170.231.250.39:61979] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||pharmasalesconnect.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "pharmasalesconnect.com"] [uri "/"] [unique_id "aSkEw5adthxmjv7B9w6HCAAAABQ"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-31 09:32:08
(10 months ago)
(mod_security) mod_security (id:210350) triggered by 170.231.250.39 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 170.231.250.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 31 05:32:03.150420 2025] [security2:error] [pid 15612:tid 15612] [client 170.231.250.39:36783] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.studiopilates.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.studiopilates.net"] [uri "/packages/"] [unique_id "aQSCE1QUsQke9PJoFtIcrAAAABM"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
rtbh.com.tr
2025-04-18 20:06:10
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐น๐ท
rtbh.com.tr
2025-04-18 00:06:09
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐น๐ท
rtbh.com.tr
2025-04-17 20:06:09
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐ฉ๐ช
ghostwarriors
2025-04-16 13:50:11
(1 year ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ksol-hostmaster
2025-04-16 13:48:02
(1 year ago)
2025/04/16 15:48:01 [error] 16924#273157: *1757768 limiting requests, excess: 0.754 by zone "crawler ...
show more
2025/04/16 15:48:01 [error] 16924#273157: *1757768 limiting requests, excess: 0.754 by zone "crawler", client: 170.231.250.39, server: crxforum.ksol.io, request: "GET /showTopic.php?action=showComment&commentUniqId=4b93904cef1ea%27&seed=5f89f9de8ad7a&topicId=130 HTTP/1.1", host: "crxforum.ksol.io"
...
show less
Bad Web Bot
Anonymous
2025-02-28 18:37:29
(1 year ago)
wordpress-trap
Web App Attack