๐บ๐ธ
TPI-Abuse
2026-10-04 07:32:12
(4 days ago)
(mod_security) mod_security (id:210350) triggered by 181.209.37.230 (230.37.209.181.in-addr.arpa): 1 ...
show more
(mod_security) mod_security (id:210350) triggered by 181.209.37.230 (230.37.209.181.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 03:32:06.199481 2026] [security2:error] [pid 25773:tid 25773] [client 181.209.37.230:43952] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||cerrovictoria.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "cerrovictoria.com"] [uri "/"] [unique_id "asIA9kafxpSYbWilttXkvwAAAA0"], referer: https://freelinkbuilding.site/dir/seo-boosting-backlinks-36836
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-03 00:25:19
(5 days ago)
denied SSH access attempt. destination port 22.
Port Scan
Brute-Force
SSH
๐ง๐ท
noconex
2026-09-30 23:39:22
(1 week ago)
Wazuh Alert | Rule ID: 100199 | Desc: Suricata: (ET SCAN Potential SSH Scan) detectado de 181.209.37 ...
show more
Wazuh Alert | Rule ID: 100199 | Desc: Suricata: (ET SCAN Potential SSH Scan) detectado de 181.209.37.230
show less
Port Scan
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-28 22:00:36
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 181.209.37.230 (230.37.209.181.in-addr.arpa): 1 ...
show more
(mod_security) mod_security (id:210350) triggered by 181.209.37.230 (230.37.209.181.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 18:00:26.016338 2026] [security2:error] [pid 12183:tid 12206] [client 181.209.37.230:53154] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||iacsb.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "iacsb.com"] [uri "/"] [unique_id "arrjeipBMIZdMVcif2dSZQAAAJU"], referer: https://certifiedlifecoach.org/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
้ฌผๅฝฑ233
2026-09-21 02:22:59
(2 weeks ago)
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0. ...
show more
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-18 00:22:37
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 181.209.37.230 (230.37.209.181.in-addr.arpa): 1 ...
show more
(mod_security) mod_security (id:210350) triggered by 181.209.37.230 (230.37.209.181.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 20:22:29.338786 2026] [security2:error] [pid 16248:tid 16248] [client 181.209.37.230:45046] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.greatwesternfirearms.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.greatwesternfirearms.com"] [uri "/"] [unique_id "aqyERX8mxLrpW10QyV84sQAAAAY"], referer: https://backlinkcheckerfree.space/dir/competitive-seo-backlinks-85579
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
savasboluk
2026-09-11 00:11:18
(3 weeks ago)
Seczar SecureOps โ SSH Brute Force (6 events) โ quarantined 43200m on ABB-GATE
SSH
Brute-Force
๐ง๐ท
noconex
2026-09-09 02:23:07
(4 weeks ago)
Wazuh Alert | Rule ID: 100199 | Desc: Suricata: (ET SCAN Potential SSH Scan) detectado de 181.209.37 ...
show more
Wazuh Alert | Rule ID: 100199 | Desc: Suricata: (ET SCAN Potential SSH Scan) detectado de 181.209.37.230
show less
Port Scan
Brute-Force
SSH
๐ณ๐ฑ
EGP Abuse Dept
2026-09-08 00:54:06
(1 month ago)
Unauthorized connection to SSH port 22
Port Scan
Hacking
SSH
๐ง๐ท
noconex
2026-09-08 00:40:07
(1 month ago)
Wazuh Alert | Rule ID: 100199 | Desc: Suricata: (ET SCAN Potential SSH Scan) detectado de 181.209.37 ...
show more
Wazuh Alert | Rule ID: 100199 | Desc: Suricata: (ET SCAN Potential SSH Scan) detectado de 181.209.37.230
show less
Port Scan
Brute-Force
SSH
๐ฉ๐ช
bescared
2026-09-03 21:38:11
(1 month ago)
F2B - Malicious activity detected. Unauthorized connection attempt: Telnet. -c23856ef-
Port Scan
๐ฉ๐ช
Da_tschek
2026-09-03 09:30:20
(1 month ago)
Port scanning
Port Scan
Hacking
๐ซ๐ท
Hiigara
2026-09-02 19:01:07
(1 month ago)
connection attempt : 181.209.37.230 on port : tcp/22 (SSH)
Port Scan
๐ง๐ท
noconex
2026-09-02 08:00:07
(1 month ago)
Wazuh Alert | Rule ID: 100199 | Desc: Suricata: (ET SCAN Potential SSH Scan) detectado de 181.209.37 ...
show more
Wazuh Alert | Rule ID: 100199 | Desc: Suricata: (ET SCAN Potential SSH Scan) detectado de 181.209.37.230
show less
Port Scan
Brute-Force
SSH
Anonymous
2026-09-02 06:28:49
(1 month ago)
denied SSH access attempt. destination port 22.
Port Scan
Brute-Force
SSH