๐บ๐ธ
TPI-Abuse
2026-10-06 00:53:30
(3 hours ago)
(mod_security) mod_security (id:210350) triggered by 181.110.191.181 (host181.181-110-191.telecom.ne ...
show more
(mod_security) mod_security (id:210350) triggered by 181.110.191.181 (host181.181-110-191.telecom.net.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 20:53:26.085470 2026] [security2:error] [pid 17325:tid 17325] [client 181.110.191.181:43126] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||hartflicker.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "hartflicker.com"] [uri "/"] [unique_id "asRGhku2E72tGMjs2p_5UQAAAAc"], referer: https://competitorbacklinkchecker.shop/dir/strategic-seo-backlinks-89510
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 05:18:03
(1 day ago)
(mod_security) mod_security (id:210350) triggered by 181.110.191.181 (host181.181-110-191.telecom.ne ...
show more
(mod_security) mod_security (id:210350) triggered by 181.110.191.181 (host181.181-110-191.telecom.net.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 01:17:55.839212 2026] [security2:error] [pid 27589:tid 27589] [client 181.110.191.181:32848] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||alternative-security.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "alternative-security.com"] [uri "/"] [unique_id "asHhgz1AY2al2jcHXSsHTgAAAAY"], referer: https://competitorlinkbuilding.space/dir/competitive-seo-backlinks-7779
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 11:22:38
(5 days ago)
(mod_security) mod_security (id:210350) triggered by 181.110.191.181 (host181.181-110-191.telecom.ne ...
show more
(mod_security) mod_security (id:210350) triggered by 181.110.191.181 (host181.181-110-191.telecom.net.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 07:22:35.083646 2026] [security2:error] [pid 21940:tid 21940] [client 181.110.191.181:50522] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||michaelwakim.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "michaelwakim.com"] [uri "/"] [unique_id "arzw-1WwjRNSNI0iHNY1nAAAAAo"], referer: https://web20backlinks.space/dir/trusted-backlink-services-135893
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 02:32:37
(6 days ago)
(mod_security) mod_security (id:210350) triggered by 181.110.191.181 (host181.181-110-191.telecom.ne ...
show more
(mod_security) mod_security (id:210350) triggered by 181.110.191.181 (host181.181-110-191.telecom.net.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 22:32:31.936338 2026] [security2:error] [pid 13026:tid 13026] [client 181.110.191.181:52566] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||billiardlifetapleague.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "billiardlifetapleague.com"] [uri "/"] [unique_id "arx0v17_xDOYb5F9fq2JiwAAAAQ"], referer: https://aibacklinkcreator.store/dir/natural-seo-backlinks-23934
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 05:52:22
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 181.110.191.181 (host181.181-110-191.telecom.ne ...
show more
(mod_security) mod_security (id:210350) triggered by 181.110.191.181 (host181.181-110-191.telecom.net.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 01:52:13.053233 2026] [security2:error] [pid 32156:tid 32156] [client 181.110.191.181:61113] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||liquid-libido.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "liquid-libido.com"] [uri "/"] [unique_id "arddjWZ9WUPyxfkdhsbtvAAAAAg"], referer: https://bulkdapachecker.space/dir/strong-domain-backlinks-122870
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
ALPHANET
2026-09-19 11:00:09
(2 weeks ago)
Botnet or web spider not respecting robots.txt
DDoS Attack
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-09-19 04:16:56
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 181.110.191.181 (host181.181-110-191.telecom.ne ...
show more
(mod_security) mod_security (id:210730) triggered by 181.110.191.181 (host181.181-110-191.telecom.net.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 00:16:49.032593 2026] [security2:error] [pid 30282:tid 30282] [client 181.110.191.181:54464] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ufcmusic.com|F|2"] [data ".js.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ufcmusic.com"] [uri "/knexfile.js.old"] [unique_id "aq4MsU-fje4RyRRQcv6cCQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
vtchost.com
2026-09-14 04:11:54
(3 weeks ago)
requested HTTP honeypot page - ignored robots.txt - bad crawler
...
Bad Web Bot
Exploited Host
๐บ๐ธ
้ฌผๅฝฑ233
2026-08-30 17:07:11
(1 month ago)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Sa ...
show more
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
show less
Bad Web Bot
๐บ๐ธ
kosada.com
2026-08-26 22:31:43
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐ฉ๐ช
LRob
2026-08-20 01:44:02
(1 month ago)
L7 DDoS: distributed flood on a shop's faceted search โ automated requests to search/sort URLs, one ...
show more
L7 DDoS: distributed flood on a shop's faceted search โ automated requests to search/sort URLs, one or two per address from thousands of addresses, no page assets loaded | path: /29-meilleur-velo-entre-1000-et-2000-euros | query: order=product.position.asc&productListView=grid&q=Disponibilit%C3%A9-En+stock%2FMarque-Bergamont%2FTaille-L
show less
DDoS Attack
Web App Attack
Anonymous
2026-08-10 13:07:06
(1 month ago)
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show more
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in email-link.asp
show less
Exploited Host
Bad Web Bot
๐ฉ๐ช
EGP Abuse Dept
2026-06-09 03:25:02
(3 months ago)
Scraping webshop URLs (www.elliptigobenelux.com), likely botnet drone
Bad Web Bot
Exploited Host
๐ฉ๐ช
SMARTNET
2026-05-27 06:03:53
(4 months ago)
Aisuru(Mirai variant) DDoS | Incident ID: 5b730afc-5cec-4742-843f-18085cc64e5c
DDoS Attack
๐บ๐ธ
RAP
2026-05-24 13:36:54
(4 months ago)
2026-05-24 13:36:54 UTC Unauthorized activity to TCP port 23. Telnet
Port Scan