🇺🇸
TPI-Abuse
2026-09-11 06:19:04
(4 hours ago)
(mod_security) mod_security (id:210350) triggered by 183.87.97.64 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 183.87.97.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 02:18:56.607318 2026] [security2:error] [pid 14906:tid 14906] [client 183.87.97.64:25396] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||recetabook.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "recetabook.com"] [uri "/"] [unique_id "aqOdUJUHOLrGH7Qb2S6GyAAAAAM"], referer: https://antojoentucocina.com/receta/bizcocho-chocolate-almendra-sin-gluten
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-11 05:00:48
(6 hours ago)
Asking over plain http and never following the redirect served — a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served — a crawler that reads nothing it asks for | method: GET | path: / | 2026-09-11 05:00 UTC
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-11 03:40:25
(7 hours ago)
(mod_security) mod_security (id:210350) triggered by 183.87.97.64 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 183.87.97.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 23:40:18.359501 2026] [security2:error] [pid 28401:tid 28401] [client 183.87.97.64:59215] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||creationorevolution.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "creationorevolution.net"] [uri "/chapter10originoflife.pdf"] [unique_id "aqN4IlMvyRohcQBio2nioQAAAAc"], referer: https://creationorevolution.net/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 04:44:30
(5 days ago)
(mod_security) mod_security (id:210350) triggered by 183.87.97.64 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 183.87.97.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 00:44:21.909639 2026] [security2:error] [pid 19507:tid 19507] [client 183.87.97.64:50809] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||michaelcarrollgreen.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "michaelcarrollgreen.com"] [uri "/"] [unique_id "apzvpR1VMyB2kvNfw-TLiQAAACM"], referer: https://michaelcarrollgreen.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 06:48:28
(6 days ago)
(mod_security) mod_security (id:210350) triggered by 183.87.97.64 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 183.87.97.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 02:48:21.803030 2026] [security2:error] [pid 8314:tid 8314] [client 183.87.97.64:17063] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||dodojuice.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "dodojuice.com"] [uri "/msds/pdfs/dodo-juice-dish-soap-sds-belgian(french).pdf"] [unique_id "apu7NfkuhBOPxNx8047ysQAAAAg"], referer: https://dodojuice.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 16:21:07
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 183.87.97.64 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 183.87.97.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 12:21:04.345855 2026] [security2:error] [pid 1434472:tid 1434536] [client 183.87.97.64:13633] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||eatdrinkgroove.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "eatdrinkgroove.com"] [uri "/thegroove.html"] [unique_id "apmecItntfbmxZBJxyvqGgAAAcA"], referer: https://eatdrinkgroove.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 12:18:02
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 183.87.97.64 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 183.87.97.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 08:17:57.683817 2026] [security2:error] [pid 10035:tid 10060] [client 183.87.97.64:33904] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||ioqm.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "ioqm.com"] [uri "/"] [unique_id "apLN9SGq06eqtA3PEJqZYAAAABE"], referer: https://newyorklifecoach.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Jochen Pretli
2026-08-29 09:20:05
(1 week ago)
connection to honeypot
Email Spam
Port Scan
🇺🇸
MPL
2026-08-29 01:14:14
(1 week ago)
tcp/443 (10 or more attempts)
Port Scan
🇺🇸
sandra361
2026-08-28 20:33:49
(1 week ago)
Port scan detected: 6 attempts across 1 port (443). | Evidence: REAPER_TARPIT: IN=enp1s0 SRC=183.87. ...
show more
Port scan detected: 6 attempts across 1 port (443). | Evidence: REAPER_TARPIT: IN=enp1s0 SRC=183.87.97.64 LEN=40 TOS=0x00 PREC=0x00 TTL=51 ID=5900 DF PROTO=TCP SPT=16951 DPT=443 WINDOW=64240 RES=0x00 ACK FIN URGP=0
show less
Port Scan
🇺🇸
TPI-Abuse
2026-08-28 10:24:55
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 183.87.97.64 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 183.87.97.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 06:24:52.020756 2026] [security2:error] [pid 12160:tid 12160] [client 183.87.97.64:16889] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||waggonerfinancial.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "waggonerfinancial.com"] [uri "/"] [unique_id "apFh9Ccotu029Z4lsWwVkQAAABU"], referer: https://canadapsilocybin.com/all/3131/21.html
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 11:48:46
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 183.87.97.64 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 183.87.97.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 07:48:40.950529 2026] [security2:error] [pid 26689:tid 26689] [client 183.87.97.64:30415] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||atlanticcitypartybuses.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "atlanticcitypartybuses.com"] [uri "/"] [unique_id "apAkGKIkh-lUCiXUQDZ34wAAABU"], referer: https://aclimousine.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 00:59:18
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 183.87.97.64 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 183.87.97.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 20:59:12.612693 2026] [security2:error] [pid 20632:tid 20632] [client 183.87.97.64:33978] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.investorscalifornia.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.investorscalifornia.com"] [uri "/"] [unique_id "ao-L4IfcNw9PMNNZUMlBNwAAAA4"], referer: https://garantaconsulting.com/funding-capital
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 12:48:27
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 183.87.97.64 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 183.87.97.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 08:48:24.146036 2026] [security2:error] [pid 30688:tid 30688] [client 183.87.97.64:60466] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||indiahouseportland.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "indiahouseportland.com"] [uri "/contact-us"] [unique_id "ao7gmJZEOUdAxzoSgUp5xgAAADU"], referer: https://indiahouseportland.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 03:39:31
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 183.87.97.64 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 183.87.97.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 23:39:25.033090 2026] [security2:error] [pid 3164429:tid 3164440] [client 183.87.97.64:40565] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||fluitles.eu|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "fluitles.eu"] [uri "/"] [unique_id "ao5f7flPLW7E8xMpNSczhAAAAYU"], referer: https://fluitles.eu/
show less
Brute-Force
Bad Web Bot
Web App Attack