๐บ๐ธ
TPI-Abuse
2026-03-18 14:57:13
(5 months ago)
(mod_security) mod_security (id:210350) triggered by 185.213.245.95 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 185.213.245.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 18 10:57:03.846372 2026] [security2:error] [pid 29057:tid 29080] [client 185.213.245.95:53515] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||particulierlb.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "particulierlb.com"] [uri "/contact-us"] [unique_id "abq9Pwc2g2LWt5buCKKLiAAAANM"], referer: https://particulierlb.com/contact-us
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-18 05:26:57
(5 months ago)
(mod_security) mod_security (id:210350) triggered by 185.213.245.95 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 185.213.245.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 18 01:26:51.039306 2026] [security2:error] [pid 25994:tid 25994] [client 185.213.245.95:29573] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||lusineweb.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "lusineweb.com"] [uri "/work"] [unique_id "abo3m3C5txCmoUHcrzZm_AAAAAM"], referer: https://lusineweb.com/work
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-10 23:25:07
(5 months ago)
(mod_security) mod_security (id:210350) triggered by 185.213.245.95 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 185.213.245.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 10 19:23:54.246243 2026] [security2:error] [pid 26470:tid 26470] [client 185.213.245.95:31829] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||pinebrookdesign.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "pinebrookdesign.com"] [uri "/our-story"] [unique_id "abCoCl0RekSRUn-w7yxeLAAAABg"], referer: https://pinebrookdesign.com/our-story
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-05 23:37:58
(5 months ago)
(mod_security) mod_security (id:210350) triggered by 185.213.245.95 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 185.213.245.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 05 18:37:51.700301 2026] [security2:error] [pid 7239:tid 7239] [client 185.213.245.95:39853] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||starsnurses.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "starsnurses.com"] [uri "/contact-us"] [unique_id "aaoTz65nQuiv7vkGRayDdAAAAAo"], referer: https://starsnurses.com/contact-us
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-04 12:30:20
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 185.213.245.95 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 185.213.245.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 04 07:30:00.663240 2026] [security2:error] [pid 11880:tid 11880] [client 185.213.245.95:41963] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||hazardrecords.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "hazardrecords.org"] [uri "/aboutus"] [unique_id "aaglyCclxoPCnQqc0WbccAAAAAA"], referer: https://hazardrecords.org/aboutus
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-03 04:12:21
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 185.213.245.95 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 185.213.245.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 02 23:12:12.055343 2026] [security2:error] [pid 1782:tid 1782] [client 185.213.245.95:41849] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||brbcar.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "brbcar.com"] [uri "/"] [unique_id "aaZfnALtVavE_3DkJkMaEQAAAA0"], referer: http://brbcar.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-01 04:31:37
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 185.213.245.95 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.213.245.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 28 23:31:31.850851 2026] [security2:error] [pid 10145:tid 10145] [client 185.213.245.95:43625] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bacona.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bacona.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aaPBI97GUEdUYv-XESBqUgAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-01 00:49:50
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 185.213.245.95 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.213.245.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 28 19:49:43.024989 2026] [security2:error] [pid 7825:tid 7825] [client 185.213.245.95:41519] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nothotmail.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nothotmail.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aaONJ7QyJ8uXe18iSFNFXwAAAA0"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-25 13:13:08
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 185.213.245.95 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 185.213.245.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 25 08:12:59.760810 2026] [security2:error] [pid 21334:tid 21358] [client 185.213.245.95:41059] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||switchbl8.nl|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "switchbl8.nl"] [uri "/"] [unique_id "aZ71W_CLG9hXrL6dIwTzIAAAAFY"], referer: https://switchbl8.nl
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-07-26 10:32:08
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-07-23 04:25:09
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ต๐น
compulab.pt
2025-07-01 21:21:53
(1 year ago)
WHMCS reset password brute force
Brute-Force
Web App Attack
๐บ๐ธ
MPL
2025-05-28 06:42:57
(1 year ago)
tcp/443 (2 or more attempts)
Port Scan
๐บ๐ธ
MPL
2025-05-28 06:42:57
(1 year ago)
tcp/443 (4 or more attempts)
Port Scan
๐น๐ท
rtbh.com.tr
2025-05-24 20:08:21
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force