๐ซ๐ฎ
saamkuu
2026-10-05 05:42:05
(2 days ago)
DDoS botnet: TCP connection flood, 15 connections to port 443.
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 01:16:06
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 181.13.142.69 (host69.181-13-142.telecom.net.ar ...
show more
(mod_security) mod_security (id:210350) triggered by 181.13.142.69 (host69.181-13-142.telecom.net.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 21:16:02.191667 2026] [security2:error] [pid 16317:tid 16317] [client 181.13.142.69:36581] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||ggisoft.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "ggisoft.com"] [uri "/"] [unique_id "ar20UkevvJ7Nsge1P7oDIgAAAB4"], referer: https://linkbuildingconsultancy.store/dir/professional-link-building-81406
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 12:16:45
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 181.13.142.69 (host69.181-13-142.telecom.net.ar ...
show more
(mod_security) mod_security (id:210350) triggered by 181.13.142.69 (host69.181-13-142.telecom.net.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 08:16:37.569792 2026] [security2:error] [pid 2353:tid 2353] [client 181.13.142.69:53431] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||mousseron.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "mousseron.com"] [uri "/"] [unique_id "arkJJcicB7T4P8J9dPfXHAAAAAI"], referer: https://bulkbacklinkanalyzer.online/dir/editorial-seo-backlinks-140716
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
ipfyx
2026-09-27 03:10:02
(1 week ago)
Port scanning
Port Scan
๐ซ๐ท
ipfyx
2026-09-25 03:10:02
(1 week ago)
Port scanning
Port Scan
๐ซ๐ท
ipfyx
2026-09-23 03:10:02
(2 weeks ago)
Port scanning
Port Scan
๐บ๐ธ
้ฌผๅฝฑ233
2026-09-21 11:20:37
(2 weeks ago)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Sa ...
show more
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36 Edg/144.0.0.0
show less
Bad Web Bot
๐ซ๐ท
ipfyx
2026-09-21 03:10:02
(2 weeks ago)
Port scanning
Port Scan
๐ซ๐ท
ipfyx
2026-09-19 03:10:02
(2 weeks ago)
Port scanning
Port Scan
๐ซ๐ท
ipfyx
2026-09-18 03:10:03
(2 weeks ago)
Port scanning
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-17 16:15:31
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 181.13.142.69 (host69.181-13-142.telecom.net.ar ...
show more
(mod_security) mod_security (id:210350) triggered by 181.13.142.69 (host69.181-13-142.telecom.net.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 12:15:29.003381 2026] [security2:error] [pid 5493:tid 5493] [client 181.13.142.69:34032] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.mininomotorfix.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.mininomotorfix.com"] [uri "/403.shtml"] [unique_id "aqwSIWPbDkm2_SR2JpxjZwAAAAk"], referer: https://checkurlbacklinks.store/dir/professional-seo-links-137230
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
amaco
2026-09-17 10:09:41
(2 weeks ago)
SSH brute-force attempt detected.
Port Scan
Brute-Force
SSH
๐ซ๐ท
ipfyx
2026-09-17 03:10:03
(2 weeks ago)
Port scanning
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-16 07:22:13
(3 weeks ago)
(mod_security) mod_security (id:210350) triggered by 181.13.142.69 (host69.181-13-142.telecom.net.ar ...
show more
(mod_security) mod_security (id:210350) triggered by 181.13.142.69 (host69.181-13-142.telecom.net.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 03:22:05.583457 2026] [security2:error] [pid 26114:tid 26114] [client 181.13.142.69:56682] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||studioyau.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "studioyau.com"] [uri "/"] [unique_id "aqpDnadTSh6xh479kgHi3QAAAAg"], referer: https://mary-valente.blogspot.com/2011/12/happy-holidays-bloggers-today-one-blog.html
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
RAP
2026-09-15 14:07:43
(3 weeks ago)
2026-09-15 14:07:43 UTC Unauthorized activity to TCP port 23. Telnet
Port Scan