|
๐บ๐ธ
ezsystems.com
|
|
|
Web Spam
|
|
|
๐ฉ๐ช
Skyrider
|
|
crowdsecurity/http-open-proxy
|
Hacking
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210740) triggered by 194.102.38.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210740) triggered by 194.102.38.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 05:39:44.960303 2026] [security2:error] [pid 22136:tid 22136] [client 194.102.38.53:59432] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||marveldirectory.com:443|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "marveldirectory.com"] [uri "/"] [unique_id "agWYYIxFoto9rIW51LpGDQAAABY"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210740) triggered by 194.102.38.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210740) triggered by 194.102.38.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 00:05:01.660037 2026] [security2:error] [pid 3036:tid 3036] [client 194.102.38.53:25470] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||gkerby.com:443|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "gkerby.com"] [uri "/"] [unique_id "agVJ7dCUGKLXbTDAhgj64QAAAA8"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:217210) triggered by 194.102.38.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:217210) triggered by 194.102.38.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 02:49:57.252276 2026] [security2:error] [pid 29502:tid 29543] [client 194.102.38.53:33206] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||www.myrtlebeachdiet.com:443|F|4"] [data "CONNECT www.myrtlebeachdiet.com:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.myrtlebeachdiet.com"] [uri "/"] [unique_id "agLNlZ8aVOHA0sXDy78PdgAAAUw"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ธ๐ฎ
administrator
|
|
2026-04-06 13:52:05,333 fail2ban.actions [1117]: NOTICE [apache-badbots] Ban 194.102.38.53
2 ...
show more
2026-04-06 13:52:05,333 fail2ban.actions [1117]: NOTICE [apache-badbots] Ban 194.102.38.53
2026-04-08 17:36:33,880 fail2ban.actions [1117]: NOTICE [apache-badbots] Ban 194.102.38.53
2026-04-06 13:52:05,333 fail2ban.actions [1117]: NOTICE [apache-badbots] Ban 194.102.38.53
...
show less
|
Bad Web Bot
Web Spam
Email Spam
Blog Spam
Port Scan
Brute-Force
Web App Attack
|
|
|
๐ต๐ฑ
webadmin
|
|
194.102.38.53 - - [19/Apr/2026:04:59:01 +0200] "CONNECT inweo.eu:443 HTTP/1.1" 400 150 "-" "-"
194.1 ...
show more
194.102.38.53 - - [19/Apr/2026:04:59:01 +0200] "CONNECT inweo.eu:443 HTTP/1.1" 400 150 "-" "-"
194.102.38.53 - - [19/Apr/2026:04:59:01 +0200] "CONNECT inweo.eu:443 HTTP/1.1" 400 150 "-" "-"
194.102.38.53 - - [19/Apr/2026:04:59:02 +0200] "CONNECT inweo.eu:443 HTTP/1.1" 400 150 "-" "-"
194.102.38.53 - - [19/Apr/2026:04:59:03 +0200] "CONNECT inweo.eu:443 HTTP/1.1" 400 150 "-" "-"
194.102.38.53 - - [19/Apr/2026:04:59:05 +0200] "CONNECT inweo.eu:443 HTTP/1.1" 400 150 "-" "-"
...
show less
|
Web App Attack
|
|
|
๐ฉ๐ช
Skyrider
|
|
crowdsecurity/http-open-proxy
|
Hacking
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:217210) triggered by 194.102.38.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:217210) triggered by 194.102.38.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 15 12:09:30.255713 2026] [security2:error] [pid 3970325:tid 3970325] [client 194.102.38.53:37217] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||haverhillhouse.com:443|F|4"] [data "CONNECT haverhillhouse.com:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "haverhillhouse.com"] [uri "/"] [unique_id "ad-4Oj4UMpM-sUzGLx8OcgAAAAU"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฎ๐น
VHosting
|
|
Detected attack and reported by a human
|
Brute-Force
Web App Attack
SSH
DDoS Attack
Exploited Host
Bad Web Bot
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 194.102.38.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 194.102.38.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 09 15:06:25.076989 2026] [security2:error] [pid 976467:tid 976467] [client 194.102.38.53:39985] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jpwatters.net"] [uri "/.env"] [unique_id "adf4sdY6Q5NSksjcZ5uMHwAAAA8"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 194.102.38.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 194.102.38.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 09 14:38:51.889882 2026] [security2:error] [pid 1057778:tid 1057778] [client 194.102.38.53:40317] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nashes.net"] [uri "/.env"] [unique_id "adfyO_1SaJDVsleVJ5EPKgAAAAE"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|