๐บ๐ธ
TPI-Abuse
2026-10-04 08:09:17
(4 days ago)
(mod_security) mod_security (id:210350) triggered by 206.84.81.152 (Dinamic-Somos-206-84-81-152.somo ...
show more
(mod_security) mod_security (id:210350) triggered by 206.84.81.152 (Dinamic-Somos-206-84-81-152.somosinternet.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 04:09:10.196519 2026] [security2:error] [pid 6197:tid 6197] [client 206.84.81.152:6208] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||justicehoward.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "justicehoward.com"] [uri "/"] [unique_id "asIJpr47heJyMGrWgBY1oQAAABY"], referer: https://createbacklinks.online/dir/relevant-domain-backlinks-109972
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 00:43:59
(4 days ago)
(mod_security) mod_security (id:210350) triggered by 206.84.81.152 (Dinamic-Somos-206-84-81-152.somo ...
show more
(mod_security) mod_security (id:210350) triggered by 206.84.81.152 (Dinamic-Somos-206-84-81-152.somosinternet.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 20:43:53.499495 2026] [security2:error] [pid 3492:tid 3492] [client 206.84.81.152:50660] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||blindshine.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "blindshine.com"] [uri "/"] [unique_id "asGhSUIsWn1CPfpybllkhQAAABY"], referer: https://automatedbacklinks.website/dir/link-building-experts-25552
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
micropedro
2026-09-29 23:18:09
(1 week ago)
6 incidents: malicious activity. First: 2026-09-24 10:15, Last: 2026-09-29 19:18 UTC. Triggers: unkn ...
show more
6 incidents: malicious activity. First: 2026-09-24 10:15, Last: 2026-09-29 19:18 UTC. Triggers: unknown.
show less
Port Scan
๐บ๐ธ
micropedro
2026-09-23 00:16:31
(2 weeks ago)
4 incidents: malicious activity. First: 2026-09-09 19:50, Last: 2026-09-22 20:16 UTC. Triggers: unkn ...
show more
4 incidents: malicious activity. First: 2026-09-09 19:50, Last: 2026-09-22 20:16 UTC. Triggers: unknown.
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-17 08:33:43
(3 weeks ago)
(mod_security) mod_security (id:210350) triggered by 206.84.81.152 (Dinamic-Somos-206-84-81-152.somo ...
show more
(mod_security) mod_security (id:210350) triggered by 206.84.81.152 (Dinamic-Somos-206-84-81-152.somosinternet.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 04:33:37.813502 2026] [security2:error] [pid 4190:tid 4190] [client 206.84.81.152:45984] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||lancemarthaler.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "lancemarthaler.com"] [uri "/"] [unique_id "aqul4WuY0bwZZe55xV_MrgAAAAw"], referer: https://seocheckerfree.space/dir/manual-seo-backlinks-118015
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
micropedro
2026-09-06 12:17:40
(1 month ago)
4 incidents: malicious activity. First: 2026-09-04 06:51, Last: 2026-09-06 08:17 UTC. Triggers: unkn ...
show more
4 incidents: malicious activity. First: 2026-09-04 06:51, Last: 2026-09-06 08:17 UTC. Triggers: unknown.
show less
Port Scan
๐ฉ๐ช
Vegascosmetics
2026-09-05 08:22:55
(1 month ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB repu ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB reputation policy (no URL signature). Evidence: Suspicion-Ban (Score 84>=65, Abuse 98, NonEU, first-seen, Change* path)
show less
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
ras07
2026-09-04 14:00:09
(1 month ago)
Brute force SSH login attempts.
Brute-Force
SSH
๐ซ๐ท
security.rdmc.fr
2026-09-04 13:19:05
(1 month ago)
Port Scan Attack proto:TCP src:56972 dst:23
Port Scan
๐จ๐ฟ
Prcek
2026-09-04 11:54:50
(1 month ago)
PortScan:HOST=206.84.81.152,DPORTS=22,23
Port Scan
๐ง๐ท
noconex
2026-09-04 06:34:12
(1 month ago)
Wazuh Alert | Rule ID: 100199 | Desc: Suricata: (ET SCAN Potential SSH Scan) detectado de 206.84.81. ...
show more
Wazuh Alert | Rule ID: 100199 | Desc: Suricata: (ET SCAN Potential SSH Scan) detectado de 206.84.81.152
show less
Port Scan
Brute-Force
SSH
๐น๐ญ
Sawasdee
2026-09-04 01:09:09
(1 month ago)
SSH break in attempt
...
SSH
๐ฆ๐น
urnilxfgbez
2026-09-02 22:45:00
(1 month ago)
Last 24 Hours suspicious: (DPT=445|DPT=3389|DPT=22|DPT=3306|DPT=8080|DPT=23|DPT=5900|DPT=1433)
Port Scan
Anonymous
2026-09-02 19:40:01
(1 month ago)
SSH brute-force: 3 blocked connection attempts to port 22 between 2026-09-02 19:37 and 2026-09-02 19 ...
show more
SSH brute-force: 3 blocked connection attempts to port 22 between 2026-09-02 19:37 and 2026-09-02 19:37 UTC (OPNsense firewall log).
show less
Brute-Force
SSH
๐บ๐ธ
MPL
2026-09-02 19:12:55
(1 month ago)
tcp ports: 23,22 (22 or more attempts)
Port Scan