๐บ๐ธ
TPI-Abuse
2026-10-03 14:37:51
(10 hours ago)
(mod_security) mod_security (id:210350) triggered by 181.116.43.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 181.116.43.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 10:37:44.620257 2026] [security2:error] [pid 19821:tid 19821] [client 181.116.43.57:14110] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||gellertdealers.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "gellertdealers.com"] [uri "/"] [unique_id "asETOMS-1FAwE8dzBRH8FgAAAAY"], referer: https://highdrbacklinks.space/dir/seo-link-building-services-80007
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 13:20:35
(11 hours ago)
(mod_security) mod_security (id:210350) triggered by 181.116.43.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 181.116.43.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 09:20:27.600499 2026] [security2:error] [pid 20275:tid 20275] [client 181.116.43.57:17276] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||scrunchiebutt.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "scrunchiebutt.com"] [uri "/"] [unique_id "asEBG_jCjc-XD5jH4CusnwAAAAM"], referer: https://backlinksearchengine.online/dir/ranking-focused-backlinks-184383
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-03 13:43:56
(2 months ago)
CrowdSec: Distributed L7 HTTP flood on WordPress 'The Events Calendar' AJAX endpoints (request_forma ...
show more
CrowdSec: Distributed L7 HTTP flood on WordPress 'The Events Calendar' AJAX endpoints (request_format~json) - DDoS | req: /calendrier-2/action~agenda/cat_ids~146,136/tag_ids~678,480,418,469,618,479,757,451/request_format~json/ | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.67 Safari/537.36
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-16 08:27:59
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 181.116.43.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 181.116.43.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 16 04:27:50.902643 2026] [security2:error] [pid 4788:tid 4788] [client 181.116.43.57:63416] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Himolla-ZeroStress-Recliner/Images/Sinatra/Thumbs.db"] [unique_id "abe_BtFpNRUeJpxw7w68bgAAAA4"], referer: https://vitalitywebb.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-25 20:50:48
(9 months ago)
scanning http requests from known botnet
Web App Attack
Anonymous
2024-12-01 19:08:34
(1 year ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
Anonymous
2024-11-22 03:16:40
(1 year ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
Anonymous
2024-11-01 00:02:30
(1 year ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host