๐บ๐ธ
TPI-Abuse
2026-09-16 18:43:23
(3 hours ago)
(mod_security) mod_security (id:210350) triggered by 206.62.143.28 (Dinamic-Somos-206-62-143-28.somo ...
show more
(mod_security) mod_security (id:210350) triggered by 206.62.143.28 (Dinamic-Somos-206-62-143-28.somosinternet.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 14:43:19.581783 2026] [security2:error] [pid 5632:tid 5632] [client 206.62.143.28:44140] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||oxygenfarm.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "oxygenfarm.com"] [uri "/"] [unique_id "aqrjRyHKIyWoNbMLAjdPGwAAAAE"], referer: https://daandpachecker.online/dir/ethical-seo-backlinks-156833
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-08-25 07:55:15
(3 weeks ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐ฉ๐ช
LRob
2026-08-20 00:34:17
(3 weeks ago)
L7 DDoS: distributed flood on a shop's faceted search โ automated requests to search/sort URLs, one ...
show more
L7 DDoS: distributed flood on a shop's faceted search โ automated requests to search/sort URLs, one or two per address from thousands of addresses, no page assets loaded | path: /33-meilleur-velo-entre-5000-et-10000-euros | query: order=product.name.desc&q=Famille-Gain-Voltage-E%5C-Horizon+SUV
show less
DDoS Attack
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-08-14 09:12:29
(1 month ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after deep/obfuscated attack (encoding nest ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after deep/obfuscated attack (encoding nesting / CPU-drain risk). Evidence: DEEP ATTACK: Recursive currentUrl nesting detected
show less
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
kosada.com
2026-08-02 12:18:16
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
Anonymous
2026-07-21 00:00:00
(1 month ago)
"Security violation, excess traffic against library/education infrastructure"
Brute-Force
๐บ๐ธ
kosada.com
2026-07-13 23:18:41
(2 months ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐บ๐ธ
kosada.com
2026-06-29 03:48:45
(2 months ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐ซ๐ฎ
notelseit
2026-06-13 09:32:21
(3 months ago)
2026-06-13T11:32:13.137118+02:00 mail postfix/submission/smtpd[1560383]: warning: unknown[206.62.143 ...
show more
2026-06-13T11:32:13.137118+02:00 mail postfix/submission/smtpd[1560383]: warning: unknown[206.62.143.28]: SASL PLAIN authentication failed: (reason unavailable), [email protected]
2026-06-13T11:32:20.131366+02:00 mail postfix/submission/smtpd[1560383]: warning: unknown[206.62.143.28]: SASL LOGIN authentication failed: (reason unavailable), [email protected]
2026-06-13T11:32:20.629619+02:00 mail postfix/submission/smtpd[1560383]: disconnect from unknown[206.62.143.28] ehlo=2 starttls=1 auth=0/2 quit=1 commands=4/6
...
show less
Brute-Force
Email Spam
๐บ๐ธ
RAP
2026-05-03 12:49:01
(4 months ago)
2026-05-03 12:49:01 UTC Unauthorized activity to TCP port 23. Telnet
Port Scan
๐ซ๐ฎ
iamxorum
2026-05-03 08:30:30
(4 months ago)
2026-05-03T08:30:29.302214+00:00 XRM-01 kernel: [TELNET-TRAP] IN=eth0 OUT= MAC=92:00:06:e6:da:95:d2: ...
show more
2026-05-03T08:30:29.302214+00:00 XRM-01 kernel: [TELNET-TRAP] IN=eth0 OUT= MAC=92:00:06:e6:da:95:d2:74:7f:6e:37:e3:08:00 SRC=206.62.143.28 DST=46.62.222.43 LEN=60 TOS=0x00 PREC=0x00 TTL=50 ID=43344 DF PROTO=TCP SPT=38300 DPT=23 WINDOW=65535 RES=0x00 SYN URGP=0
...
show less
Port Scan
IoT Targeted
Anonymous
2026-04-25 03:03:03
(4 months ago)
RdpGuard detected brute-force attempt on IMAP
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-02-20 23:30:10
(6 months ago)
(mod_security) mod_security (id:218580) triggered by 206.62.143.28 (Dinamic-Somos-206-62-143-28.somo ...
show more
(mod_security) mod_security (id:218580) triggered by 206.62.143.28 (Dinamic-Somos-206-62-143-28.somosinternet.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 18:30:04.555453 2026] [security2:error] [pid 26539:tid 26539] [client 206.62.143.28:57972] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:\\\\/\\\\*[!+](?:[\\\\w\\\\s=_\\\\-()]+)?\\\\*\\\\/)" at ARGS:id. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/22_SQL_SQLi.conf"] [line "76"] [id "218580"] [rev "1"] [msg "COMODO WAF: MySQL in-line comment detected.||psdinnersready.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "SQLi"] [hostname "psdinnersready.com"] [uri "/index.php"] [unique_id "aZjufK_0Lqp9gx_EUSv5NQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Sklurk
2026-01-26 12:20:34
(7 months ago)
Web App Attack
Web App Attack
๐จ๐ญ
backslash
2026-01-25 01:06:16
(7 months ago)
block ruleset A5EE6C8F745F0934168261886A3817E5C386412A
Bad Web Bot