🇺🇸
TPI-Abuse
2026-09-16 17:22:16
(1 day ago)
(mod_security) mod_security (id:210350) triggered by 181.91.85.1 (181.91.85.1.ptr.personal.net.py): ...
show more
(mod_security) mod_security (id:210350) triggered by 181.91.85.1 (181.91.85.1.ptr.personal.net.py): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 13:22:08.872331 2026] [security2:error] [pid 3683:tid 3683] [client 181.91.85.1:36137] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||safetyfastclub.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "safetyfastclub.com"] [uri "/"] [unique_id "aqrQQMMpDEsgIPuZm8brrQAAAAM"], referer: https://dupurgeniefr.com/all/2517/4.html
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
ALPHANET
2026-09-04 08:40:58
(1 week ago)
Botnet or web spider not respecting robots.txt
DDoS Attack
Exploited Host
🇺🇸
kosada.com
2026-07-27 21:27:52
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
Anonymous
2026-07-08 17:03:44
(2 months ago)
Attribution: mikhail-smirnov-79830323 (LinkedIn/profile ID) employed by Angara Technologies Group (E ...
show more
Attribution: mikhail-smirnov-79830323 (LinkedIn/profile ID) employed by Angara Technologies Group (Explicitly identified himself as enemy a week before attack began) | Aggressive search filter manipulation / web scraper probe on port 443 | URI: Excessive filters used: /catalogsearch/result/?cat=83+&mul_connector_video=201&q=DVI+104+Tx%2FRx | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/532.2 (KHTML, like Gecko) Chrome/52.0.873.0 Safari/532.2 | (Magento Site)
show less
Hacking
Bad Web Bot
🇺🇸
stechusa
2026-07-06 16:38:27
(2 months ago)
[Askari]
Bad Web Bot
DDoS Attack
🇺🇸
stechusa
2026-07-06 15:52:53
(2 months ago)
[Askari] | Behavior: Targeting specific pages, Holding server worker, HTTP/1.1 over TLS, Concurrent ...
show more
[Askari] | Behavior: Targeting specific pages, Holding server worker, HTTP/1.1 over TLS, Concurrent page load during attack
show less
Bad Web Bot
DDoS Attack
🇵🇱
sefinek.net
2026-07-05 03:47:20
(2 months ago)
Triggered Cloudflare WAF (firewallCustom) from PY.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (G ...
show more
Triggered Cloudflare WAF (firewallCustom) from PY.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (GET) | Endpoint: /gallery/nekomimi-blue-hair-white-shirt-skirt | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.93 Safari/537.36 • Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇩🇪
Vegascosmetics
2026-06-15 10:41:23
(3 months ago)
(Kingcopy.org-AI-IDS-Report):IP automatically blocked after obfuscated redirect. Vegas Security
DDoS Attack
Hacking
Exploited Host
🇦🇷
Bruno
2026-05-05 17:07:01
(4 months ago)
Port Scanner: 181.91.85.1
Port Scan
🇺🇸
RAP
2026-05-01 15:38:38
(4 months ago)
2026-05-01 15:38:38 UTC Unauthorized activity to TCP port 23. Telnet
Port Scan
🇺🇸
TPI-Abuse
2026-05-01 04:10:35
(4 months ago)
(mod_security) mod_security (id:210381) triggered by 181.91.85.1 (181.91.85.1.ptr.personal.net.py): ...
show more
(mod_security) mod_security (id:210381) triggered by 181.91.85.1 (181.91.85.1.ptr.personal.net.py): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 01 00:10:27.961311 2026] [security2:error] [pid 5384:tid 5402] [client 181.91.85.1:8767] ModSecurity: Access denied with code 403 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "82"] [id "210381"] [rev "6"] [msg "COMODO WAF: URL Encoding Abuse Attack Attempt||www.mentzlaw.com|F|4"] [data "REQUEST_URI=/louisianakidneydamagelawyer/%url%"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.mentzlaw.com"] [uri "/louisianakidneydamagelawyer/%url%"] [unique_id "afQns4NDFiGEoEYAIJTIqQAAANA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-30 22:35:26
(4 months ago)
Unauthorized connection attempt on Port 23
Port Scan
Hacking
Exploited Host
Anonymous
2026-04-30 14:43:48
(4 months ago)
Port scanning. Port: 23
Port Scan
🇺🇸
kosada.com
2026-04-21 23:38:19
(4 months ago)
Web bot: DDoS
DDoS Attack
Bad Web Bot
🇳🇱
jjnxpct
2026-04-07 04:11:47
(5 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /de/component/avendre/blog (Rule ID: 932130) - Remote Command Execution: Unix Shell Expression Found
show less
Web App Attack