πΊπΈ
TPI-Abuse
2026-09-17 12:43:33
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 212.34.19.225 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 212.34.19.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 08:43:28.010854 2026] [security2:error] [pid 4492:tid 4492] [client 212.34.19.225:36228] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||northfortworthalliance.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "northfortworthalliance.com"] [uri "/"] [unique_id "aqvgcCQ2-CFEwBl7VlUU6wAAABo"], referer: https://blogdachecker.space/dir/quality-backlink-services-150066
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-17 09:07:13
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 212.34.19.225 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 212.34.19.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 05:07:09.963460 2026] [security2:error] [pid 28994:tid 28994] [client 212.34.19.225:36100] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||rademeyer.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "rademeyer.com"] [uri "/"] [unique_id "aqutvZMoaXANwka6nq_8cgAAAAw"], referer: https://backlinkfreechecker.space/dir/relevant-seo-backlinks-171335
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
kosada.com
2026-08-26 18:07:18
(3 weeks ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
π©πͺ
HandyTreff.de
2026-07-30 18:32:16
(1 month ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -64.219 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -64.219 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Sa
show less
Web App Attack
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-06-12 12:57:13
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 212.34.19.225 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 212.34.19.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 08:57:07.056041 2026] [security2:error] [pid 32386:tid 32386] [client 212.34.19.225:57619] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 212.34.19.225 (+1 hits since last alert)|avantgarde-hk.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "avantgarde-hk.org"] [uri "/xmlrpc.php"] [unique_id "aiwCIwsLF8g2jmfiQdkgJQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-06-12 11:52:27
(3 months ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
πΈπ¬
mypatricks
2026-04-29 11:21:28
(4 months ago)
212.34.19.225 | Port: 10966 | DNS: 212.34.19.225 2026-04-29T19:21:27+08:00 Asia/Amman | IPs Spam lis ...
show more
212.34.19.225 | Port: 10966 | DNS: 212.34.19.225 2026-04-29T19:21:27+08:00 Asia/Amman | IPs Spam list | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36 HTTP/1.1 443 GET | URL: /?bfd014b37d53469cff14e1589a=EUR&code=EUR | Ref: - | Country: JO/Jordan/+02:00 IP City: Amman Windows 9f3dec561fdd8ab2-AMM/Amman, Jordan 1 hits/0 secs Robots 2
show less
Brute-Force
Web App Attack
Blog Spam
Web Spam
Exploited Host
πΊπΈ
TPI-Abuse
2026-04-06 14:07:17
(5 months ago)
(mod_security) mod_security (id:217210) triggered by 212.34.19.225 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:217210) triggered by 212.34.19.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 10:07:13.721481 2026] [security2:error] [pid 248493:tid 248493] [client 212.34.19.225:33836] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||rix.com.br|F|4"] [data "GET http://rix.com.br HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "rix.com.br"] [uri "/"] [unique_id "adO-EYNSAWdpJsqzDT2-3wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
backslash
2025-12-21 18:45:09
(8 months ago)
block ruleset 6B63410D189E6343B910F7440B8499558BEC52EB
Bad Web Bot
Anonymous
2025-11-17 17:25:09
(10 months ago)
scanning http requests from known botnet
Web App Attack