๐บ๐ธ
TPI-Abuse
2026-10-07 21:28:05
(3 days ago)
(mod_security) mod_security (id:210350) triggered by 205.147.22.38 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 205.147.22.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 17:28:01.071347 2026] [security2:error] [pid 8535:tid 8535] [client 205.147.22.38:48909] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||southtncardio.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "southtncardio.com"] [uri "/"] [unique_id "asa5YXw_qLTX9IBwzZ-wCgAAAAU"], referer: https://backlinksubmitter.online/dir/powerful-seo-backlinks-195203
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 02:37:43
(5 days ago)
(mod_security) mod_security (id:210350) triggered by 205.147.22.38 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 205.147.22.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 22:37:37.377438 2026] [security2:error] [pid 13256:tid 13256] [client 205.147.22.38:36591] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||jimwilsonstudios.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "jimwilsonstudios.com"] [uri "/"] [unique_id "asRe8UPfMkb7qbTfeBiNnwAAAAw"], referer: https://backlinkmarketplace.space/dir/backlinks-for-seo-106942
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 01:23:10
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 205.147.22.38 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 205.147.22.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 21:23:03.181658 2026] [security2:error] [pid 6606:tid 6606] [client 205.147.22.38:33690] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||jhollingshead.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "jhollingshead.com"] [uri "/"] [unique_id "ar8Hd362idJyjSA8j0MIkAAAAAY"], referer: https://automaticbacklinkmaker.site/dir/backlinks-for-organic-growth-106645
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-01 10:35:31
(1 week ago)
[ti-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 205 ...
show more
[ti-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 205.147.22.38 - - \[01/Oct/2026:12:29:53 +0200\] "GET /backup/.env.php HTTP/1.1" 404 2237 "-" "Mozilla/5.0 \(Windows NT 10.0\; Win64\; x64\) AppleWebKit/537.36"
...
show less
Bad Web Bot
Web App Attack
๐จ๐ฟ
lp
2026-09-30 13:51:42
(1 week ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 205.147.22.38
2026-09-30T14:20:33+02: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 205.147.22.38
2026-09-30T14:20:33+02:00 vpn Access-Reject 'xzahv03' station: 205.147.22.38 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-09-30 02:23:56
(1 week ago)
Try to access /xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 22:21:09
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 205.147.22.38 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 205.147.22.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 18:21:02.514708 2026] [security2:error] [pid 21536:tid 21536] [client 205.147.22.38:38649] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||oximoron.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "oximoron.com"] [uri "/"] [unique_id "arroTgkx1zm0RxNFJkpnwwAAAAc"], referer: https://politikpornoshop.blogspot.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-26 10:13:24
(2 weeks ago)
denied traffic to a honeypot user target.
Port Scan
Hacking
Anonymous
2026-09-26 09:57:18
(2 weeks ago)
Unauthorized VPN login attempts
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-22 04:21:46
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 205.147.22.38 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 205.147.22.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 00:21:38.309904 2026] [security2:error] [pid 2618:tid 2618] [client 205.147.22.38:15519] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||kontikimotorcycles.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "kontikimotorcycles.com"] [uri "/"] [unique_id "arICUsLtuewYg1B_2GG0jwAAAAk"], referer: https://jjskewlstuff3.blogspot.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 20:44:56
(3 weeks ago)
(mod_security) mod_security (id:210350) triggered by 205.147.22.38 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 205.147.22.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 16:44:52.098572 2026] [security2:error] [pid 5292:tid 5292] [client 205.147.22.38:37830] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||albrittonmcclain.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "albrittonmcclain.com"] [uri "/"] [unique_id "aq2ixA3pyeqy-7vLyVEuMAAAABI"], referer: https://dougmcgrew.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 07:02:04
(4 weeks ago)
(mod_security) mod_security (id:225170) triggered by 205.147.22.38 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 205.147.22.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 03:01:59.101041 2026] [security2:error] [pid 23616:tid 23616] [client 205.147.22.38:21037] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||htu.modernsalessolutions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "htu.modernsalessolutions.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqT456yBz6w3Ifi0dpIjuAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2026-09-03 05:37:00
(1 month ago)
IPBlock protected site ID [4055-d][s=01].
Persistent 404, vulnerability scanner
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 02:20:41
(1 month ago)
Web attack
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2026-08-29 00:13:07
(1 month ago)
HTTP DDoS Attack Layer 7
DDoS Attack