๐บ๐ธ
threatintelligence_bvc
2026-02-23 14:29:32
(3 months ago)
Brute-Force
๐บ๐ธ
threatintelligence_bvc
2026-01-10 02:07:35
(5 months ago)
Brute-Force
๐ซ๐ท
dynamix
2025-11-28 12:20:24
(6 months ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-28 12:01:06
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 191.96.150.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 191.96.150.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 28 07:01:00.724924 2025] [security2:error] [pid 1398724:tid 1398724] [client 191.96.150.173:25651] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.jellisonrepair.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.jellisonrepair.com"] [uri "/"] [unique_id "aSmO_KtXmo2vwjC82XwVrgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-28 11:42:25
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 191.96.150.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 191.96.150.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 28 06:42:20.538950 2025] [security2:error] [pid 16167:tid 16167] [client 191.96.150.173:51899] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.restaurant-napkins.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.restaurant-napkins.com"] [uri "/"] [unique_id "aSmKnNa-WXGuVMNiuh1nOgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-28 11:15:59
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 191.96.150.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 191.96.150.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 28 06:15:55.511860 2025] [security2:error] [pid 11923:tid 12006] [client 191.96.150.173:49737] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.clearwaterpumpservices.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.clearwaterpumpservices.com"] [uri "/"] [unique_id "aSmEa7zNfKn6zr22bEWigwAAAJg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-28 10:57:49
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 191.96.150.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 191.96.150.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 28 05:57:44.904368 2025] [security2:error] [pid 5857:tid 5857] [client 191.96.150.173:11786] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.donutlocations.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.donutlocations.com"] [uri "/duluth-ga.html"] [unique_id "aSmAKAHOiw6wSipQ48CVKgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
rtbh.com.tr
2025-07-07 20:07:34
(11 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐น๐ท
rtbh.com.tr
2025-07-07 00:07:32
(11 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐ฉ๐ช
SpaceHost-Server
2025-07-06 22:28:41
(11 months ago)
Brute-Force
Web App Attack
๐น๐ท
rtbh.com.tr
2025-07-06 20:07:33
(11 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐บ๐ธ
octageeks.com
2025-07-06 04:15:56
(11 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐ฉ๐ช
LRob.fr
2025-07-06 03:45:16
(11 months ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
๐ณ๐ฑ
Savvii
2025-07-06 03:20:29
(11 months ago)
10 attempts against mh-misc-ban on kale
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-06 02:42:37
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 191.96.150.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 191.96.150.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 05 22:42:29.523792 2025] [security2:error] [pid 31450:tid 31450] [client 191.96.150.173:29172] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.rotentendales.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.rotentendales.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aGnilXhlv5NKyYNTsbKlPAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack