Anonymous
2026-10-01 07:16:14
(19 hours ago)
Network service scanning detected by FortiGate; source quarantined.
Port Scan
๐บ๐ธ
TPI-Abuse
2026-10-01 05:08:05
(21 hours ago)
(mod_security) mod_security (id:210350) triggered by 213.230.78.226 (226.64.uzpak.uz): 1 in the last ...
show more
(mod_security) mod_security (id:210350) triggered by 213.230.78.226 (226.64.uzpak.uz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 01:07:57.855340 2026] [security2:error] [pid 4136:tid 4136] [client 213.230.78.226:28350] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||individualhealth.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "individualhealth.com"] [uri "/"] [unique_id "ar3qra1GIRvq9i5ND0Ho4QAAAAI"], referer: https://dabacklinks.store/dir/premium-backlink-services-100114
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Kejult
2026-09-30 14:39:09
(1 day ago)
Honeypot Finding: SMB activity on TCP/445; 4 Dionaea events.
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-30 01:09:20
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 213.230.78.226 (226.64.uzpak.uz): 1 in the last ...
show more
(mod_security) mod_security (id:210350) triggered by 213.230.78.226 (226.64.uzpak.uz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 21:09:14.588303 2026] [security2:error] [pid 31267:tid 31267] [client 213.230.78.226:6243] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||astrologydemo.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "astrologydemo.com"] [uri "/"] [unique_id "arxhOtDt947lYmnFpx4YXAAAAAM"], referer: https://web20submission.shop/dir/trusted-seo-backlinks-14604
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 04:57:41
(4 days ago)
(mod_security) mod_security (id:210350) triggered by 213.230.78.226 (226.64.uzpak.uz): 1 in the last ...
show more
(mod_security) mod_security (id:210350) triggered by 213.230.78.226 (226.64.uzpak.uz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 00:57:35.446552 2026] [security2:error] [pid 9206:tid 9206] [client 213.230.78.226:50833] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||ramoundos-systems.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "ramoundos-systems.com"] [uri "/"] [unique_id "ariiP-IAMf8mXvzlUPdBQwAAABI"], referer: https://webbacklinkchecker.site/dir/relevant-domain-backlinks-171972
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 02:40:11
(4 days ago)
(mod_security) mod_security (id:210350) triggered by 213.230.78.226 (226.64.uzpak.uz): 1 in the last ...
show more
(mod_security) mod_security (id:210350) triggered by 213.230.78.226 (226.64.uzpak.uz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 22:40:04.276161 2026] [security2:error] [pid 11185:tid 11185] [client 213.230.78.226:61203] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||darensicecream.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "darensicecream.com"] [uri "/"] [unique_id "ariCBIg0k9gaHLwBq0TiqwAAABk"], referer: https://bulkpadachecker.online/dir/organic-seo-links-50613
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ท
Kejult
2026-09-25 13:23:01
(6 days ago)
Honeypot Finding: SMB activity on TCP/445; 20 Dionaea events.
Port Scan
๐ฉ๐ช
Vegascosmetics
2026-09-21 07:32:05
(1 week ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after deep/obfuscated attack (encoding nest ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after deep/obfuscated attack (encoding nesting / CPU-drain risk). Evidence: High Priority: %25252F
show less
Hacking
Exploited Host
Web App Attack
๐ฆ๐บ
foobax
2026-09-21 04:10:54
(1 week ago)
closed the connection from port 58627
SSH
Port Scan
๐ฎ๐น
A000Z
2026-09-21 03:55:42
(1 week ago)
Fail2Ban: 213.230.78.226 was banned for Aggressive Bad Bot detected by Nginx/Fail2Ban. UA: Mozilla/5 ...
show more
Fail2Ban: 213.230.78.226 was banned for Aggressive Bad Bot detected by Nginx/Fail2Ban. UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36
show less
Bad Web Bot
๐ญ๐ฐ
sandra361
2026-09-20 23:08:17
(1 week ago)
Port scan detected: 5 attempts across 2 ports (22, 23). | Evidence: REAPER_TARPIT: IN=eth0 SRC=213.2 ...
show more
Port scan detected: 5 attempts across 2 ports (22, 23). | Evidence: REAPER_TARPIT: IN=eth0 SRC=213.230.78.226 LEN=40 TOS=0x14 PREC=0x00 TTL=49 ID=0 DF PROTO=TCP SPT=51662 DPT=23 WINDOW=0 RES=0x00 RST URGP=0
show less
Port Scan
๐บ๐ธ
้ฌผๅฝฑ233
2026-09-19 16:06:47
(1 week ago)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Sa ...
show more
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0
show less
Bad Web Bot
๐ฌ๐ง
BananaLlama
2026-09-18 22:39:20
(1 week ago)
Unsolicited SSH (TCP/22) connection attempts blocked at edge firewall; no public SSH service is expo ...
show more
Unsolicited SSH (TCP/22) connection attempts blocked at edge firewall; no public SSH service is exposed.
show less
Port Scan
SSH
๐บ๐ธ
TPI-Abuse
2026-09-18 13:35:43
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 213.230.78.226 (226.64.uzpak.uz): 1 in the last ...
show more
(mod_security) mod_security (id:210350) triggered by 213.230.78.226 (226.64.uzpak.uz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 09:35:38.387663 2026] [security2:error] [pid 6279:tid 6279] [client 213.230.78.226:18979] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.hvacmechanalysis.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.hvacmechanalysis.com"] [uri "/"] [unique_id "aq0-KsWH_mLNPxYTOFIZpgAAABg"], referer: https://bulkdaandpachecker.store/dir/strategic-seo-backlinks-96810
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 11:27:16
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 213.230.78.226 (226.64.uzpak.uz): 1 in the last ...
show more
(mod_security) mod_security (id:210350) triggered by 213.230.78.226 (226.64.uzpak.uz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 07:27:12.475103 2026] [security2:error] [pid 19796:tid 19931] [client 213.230.78.226:41389] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.grupojdg.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.grupojdg.com"] [uri "/"] [unique_id "aqvOkDrhHvJNc84hracMEAAAAY8"], referer: https://backlinkschecker.store/dir/ranking-focused-backlinks-86583
show less
Brute-Force
Bad Web Bot
Web App Attack