🇺🇸
TPI-Abuse
2026-09-17 14:21:07
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 217.64.97.41 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 217.64.97.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 10:21:03.068696 2026] [security2:error] [pid 517:tid 517] [client 217.64.97.41:47721] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||velvetculture.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "velvetculture.com"] [uri "/"] [unique_id "aqv3T929GNAWweuwU5ev5QAAABI"], referer: https://websitecheckerseo.store/dir/premium-backlink-building-224667
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-17 12:12:31
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 217.64.97.41 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 217.64.97.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 08:12:22.807788 2026] [security2:error] [pid 21866:tid 21866] [client 217.64.97.41:29881] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||hatefmusic.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "hatefmusic.com"] [uri "/"] [unique_id "aqvZJrELDnZqI0rqnJ9JwwAAAAM"], referer: https://freerankingchecker.online/dir/organic-visibility-backlinks-89677
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-08-26 19:42:02
(3 weeks ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
🇺🇸
gui-ying233
2026-08-23 12:02:17
(3 weeks ago)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Sa ...
show more
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36
show less
Bad Web Bot
Anonymous
2026-08-18 02:19:06
(1 month ago)
MikroTik Enterprise Honeypot
Port Scan
🇺🇸
kosada.com
2026-06-29 15:57:56
(2 months ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
Anonymous
2025-12-19 09:41:02
(9 months ago)
scanning http requests from known botnet
Web App Attack
🇺🇸
TPI-Abuse
2025-12-10 14:52:11
(9 months ago)
"Participant in large-scale DDoS Attack in which data injection was attmpted to gain unauthorized ac ...
show more
"Participant in large-scale DDoS Attack in which data injection was attmpted to gain unauthorized access"
show less
DDoS Attack
SQL Injection
Exploited Host
🇺🇸
TPI-Abuse
2025-12-04 21:45:05
(9 months ago)
(mod_security) mod_security (id:217210) triggered by 217.64.97.41 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:217210) triggered by 217.64.97.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 04 16:44:59.323208 2025] [security2:error] [pid 12577:tid 12577] [client 217.64.97.41:17262] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||www.corepsychcenter.com|F|4"] [data "GET http://www.corepsychcenter.com HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.corepsychcenter.com"] [uri "/"] [unique_id "aTIA296i916C68aoVa4UTgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
SMARTNET
2025-11-26 02:37:10
(9 months ago)
Aisuru(Mirai variant) DDoS
DDoS Attack
Anonymous
2025-11-18 17:39:55
(10 months ago)
scanning http requests from known botnet
Web App Attack
🇩🇪
Josef Matula
2025-10-17 11:46:31
(11 months ago)
ports, 445/24H:1/7D:1
Port Scan
🇫🇷
ericshim.me
2025-09-16 23:32:37
(1 year ago)
Dionaea honeypot SMB access at 2025-09-16T16:39:26.302962
Brute-Force
🇺🇸
creations.works
2025-09-16 18:12:01
(1 year ago)
Blocked by UFW on vds [445/tcp]
Source port: 24720
TTL: 109
Packet length: 52
TOS: 0x00
This report ...
show more
Blocked by UFW on vds [445/tcp]
Source port: 24720
TTL: 109
Packet length: 52
TOS: 0x00
This report was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Hacking
Brute-Force
🇳🇱
exxos
2025-07-31 03:30:31
(1 year ago)
HTTP1.x attacks
DDoS Attack