🇺🇸
TPI-Abuse
2026-09-16 21:59:06
(4 days ago)
(mod_security) mod_security (id:210350) triggered by 178.57.85.83 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 178.57.85.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 17:59:00.411899 2026] [security2:error] [pid 15311:tid 15311] [client 178.57.85.83:59960] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||modmove.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "modmove.com"] [uri "/2026/09/15/"] [unique_id "aqsRJCNw4ZkYNTBl8Xin7QAAAAo"], referer: https://modmove.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-16 17:02:15
(4 days ago)
(mod_security) mod_security (id:210350) triggered by 178.57.85.83 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 178.57.85.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 13:02:06.818610 2026] [security2:error] [pid 22474:tid 22474] [client 178.57.85.83:65418] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||greenmountainfeeds.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "greenmountainfeeds.com"] [uri "/"] [unique_id "aqrLjiGFK7A2vdxSwvQlrwAAAA0"], referer: https://bestofthefirstcoast.com/all/1243/1.html
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-16 08:17:53
(5 days ago)
(mod_security) mod_security (id:210350) triggered by 178.57.85.83 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 178.57.85.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 04:17:44.719380 2026] [security2:error] [pid 11220:tid 11220] [client 178.57.85.83:55656] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||homebuilt.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "homebuilt.org"] [uri "/vendors/powerplants/imflyn.html"] [unique_id "aqpQqHc7o2Q-yn9nvPdfSAAAAAA"], referer: https://homebuilt.org/vendors/powerplants/auto.html
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 19:15:49
(5 days ago)
(mod_security) mod_security (id:210350) triggered by 178.57.85.83 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 178.57.85.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:15:09.326556 2026] [security2:error] [pid 27259:tid 27259] [client 178.57.85.83:54357] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||player-care.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "player-care.com"] [uri "/"] [unique_id "aqmZPca2GpG7dzqLTHxY8AAAABk"], referer: https://harmonyclubwaltz.blogspot.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
nyuuzyou
2026-09-08 14:46:18
(1 week ago)
Client failed challenge verification, marked as suspicious. HTTP request received over TCP on applic ...
show more
Client failed challenge verification, marked as suspicious. HTTP request received over TCP on application ports 80/443. Observed 2026-09-08T14:46:18Z.
show less
Bad Web Bot
🇳🇱
exxos
2025-10-03 07:08:21
(11 months ago)
Attacks with Bad user agents
Hacking
🇨🇦
Largnet SOC
2023-08-11 21:04:38
(3 years ago)
178.57.85.83 triggered Icarus honeypot on port 22. Check us out on github.
Port Scan
Hacking