๐ฆ๐บ
aranguren.org
2026-09-01 11:05:17
(1 day ago)
[Tue Sep 01 21:05:05.204072 2026] [authz_core:error] [pid 2350426:tid 2350460] [client 2600:3c15::20 ...
show more
[Tue Sep 01 21:05:05.204072 2026] [authz_core:error] [pid 2350426:tid 2350460] [client 2600:3c15::2000:aff:fe0a:fcee:41928] AH01630: client denied by server configuration: /srv/http/
[Tue Sep 01 21:05:12.008657 2026] [authz_core:error] [pid 2354144:tid 2354202] [client 2600:3c15::2000:aff:fe0a:fcee:58660] AH01630: client denied by server configuration: /srv/http/
[Tue Sep 01 21:05:17.314223 2026] [authz_core:error] [pid 2354144:tid 2354183] [client 2600:3c15::2000:aff:fe0a:fcee:58676] AH01630: client denied by server configuration: /srv/http/
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
xmission.com
2026-08-15 15:15:44
(2 weeks ago)
2600:3c15::2000:aff:fe0a:fcee - - [15/Aug/2026:05:24:58 -0600] "CONNECT dooce.com:443 HTTP/1.1" 400 ...
show more
2600:3c15::2000:aff:fe0a:fcee - - [15/Aug/2026:05:24:58 -0600] "CONNECT dooce.com:443 HTTP/1.1" 400 150 "-" "-"
2600:3c15::2000:aff:fe0a:fcee - - [15/Aug/2026:05:40:42 -0600] "CONNECT dooce.com:443 HTTP/1.1" 400 150 "-" "-"
2600:3c15::2000:aff:fe0a:fcee - - [15/Aug/2026:06:36:38 -0600] "CONNECT dooce.com:443 HTTP/1.1" 400 150 "-" "-"
2600:3c15::2000:aff:fe0a:fcee - - [15/Aug/2026:08:55:48 -0600] "CONNECT dooce.com:443 HTTP/1.1" 400 150 "-" "-"
2600:3c15::2000:aff:fe0a:fcee - - [15/Aug/2026:09:15:43 -0600] "CONNECT dooce.com:443 HTTP/1.1" 400 150 "-" "-"
...
show less
Web App Attack
๐บ๐ธ
SX Communications
2026-07-29 10:39:36
(1 month ago)
HTTP application-layer DoS / botnet traffic from 2600:3c15::2000:aff:fe0a:fcee: repeated high-cost d ...
show more
HTTP application-layer DoS / botnet traffic from 2600:3c15::2000:aff:fe0a:fcee: repeated high-cost dynamic page and feed requests (profile/tag views, forums, tracker, RSS) at abusive rates via completed TCP/HTTPS. Likely compromised end-user host.
show less
DDoS Attack
Bad Web Bot
Exploited Host
๐ฉ๐ช
LRob
2026-07-25 00:40:11
(1 month ago)
CrowdSec: crowdsecurity/http-open-proxy | req: numericatous.fr:443 | UA: -
Hacking
๐ฉ๐ช
LRob
2026-07-24 03:17:38
(1 month ago)
CrowdSec: crowdsecurity/http-open-proxy | req: www.meteo-centre.fr:443 | UA: -
Hacking
๐ฉ๐ช
Jarda_H
2026-07-20 22:38:41
(1 month ago)
http-open-proxy
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-07-13 04:43:34
(1 month ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-open-proxy
Web App Attack
๐บ๐ธ
xmission.com
2026-07-10 13:44:45
(1 month ago)
2600:3c15::2000:aff:fe0a:fcee - - [10/Jul/2026:03:41:12 -0600] "CONNECT dooce.com:443 HTTP/1.1" 400 ...
show more
2600:3c15::2000:aff:fe0a:fcee - - [10/Jul/2026:03:41:12 -0600] "CONNECT dooce.com:443 HTTP/1.1" 400 150 "-" "-"
2600:3c15::2000:aff:fe0a:fcee - - [10/Jul/2026:04:54:11 -0600] "CONNECT dooce.com:443 HTTP/1.1" 400 150 "-" "-"
2600:3c15::2000:aff:fe0a:fcee - - [10/Jul/2026:07:32:08 -0600] "CONNECT dooce.com:443 HTTP/1.1" 400 150 "-" "-"
2600:3c15::2000:aff:fe0a:fcee - - [10/Jul/2026:07:33:16 -0600] "CONNECT dooce.com:443 HTTP/1.1" 400 150 "-" "-"
2600:3c15::2000:aff:fe0a:fcee - - [10/Jul/2026:07:44:45 -0600] "CONNECT dooce.com:443 HTTP/1.1" 400 150 "-" "-"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-27 10:52:45
(2 months ago)
(mod_security) mod_security (id:217210) triggered by 2600:3c15::2000:aff:fe0a:fcee (Unknown): 1 in t ...
show more
(mod_security) mod_security (id:217210) triggered by 2600:3c15::2000:aff:fe0a:fcee (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 06:52:39.496111 2026] [security2:error] [pid 12502:tid 12502] [client 2600:3c15::2000:aff:fe0a:fcee:36542] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||brentsagnotti.com:443|F|4"] [data "CONNECT brentsagnotti.com:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "brentsagnotti.com"] [uri "/"] [unique_id "aj-rd1v1VzNZtwdFwVVI5QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-16 18:50:06
(2 months ago)
Detected Hacking, SQL Injection or general Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 20:21:31
(2 months ago)
(mod_security) mod_security (id:217210) triggered by 2600:3c15::2000:aff:fe0a:fcee (Unknown): 1 in t ...
show more
(mod_security) mod_security (id:217210) triggered by 2600:3c15::2000:aff:fe0a:fcee (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 16:21:25.982243 2026] [security2:error] [pid 24460:tid 24470] [client 2600:3c15::2000:aff:fe0a:fcee:36820] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||alicefaye.com:443|F|4"] [data "CONNECT alicefaye.com:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "alicefaye.com"] [uri "/"] [unique_id "aiXSxSIKVd891RiHAKQ6XgAAAQg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 10:14:15
(2 months ago)
(mod_security) mod_security (id:217210) triggered by 2600:3c15::2000:aff:fe0a:fcee (Unknown): 1 in t ...
show more
(mod_security) mod_security (id:217210) triggered by 2600:3c15::2000:aff:fe0a:fcee (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 06:14:09.658144 2026] [security2:error] [pid 4367:tid 4367] [client 2600:3c15::2000:aff:fe0a:fcee:36164] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||edscontracting.com:443|F|4"] [data "CONNECT edscontracting.com:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "edscontracting.com"] [uri "/"] [unique_id "aiFP8fbC23EDvuOiNXRWDAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-31 03:39:13
(3 months ago)
(mod_security) mod_security (id:217210) triggered by 2600:3c15::2000:aff:fe0a:fcee (Unknown): 1 in t ...
show more
(mod_security) mod_security (id:217210) triggered by 2600:3c15::2000:aff:fe0a:fcee (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 23:39:10.283618 2026] [security2:error] [pid 23435:tid 23493] [client 2600:3c15::2000:aff:fe0a:fcee:47218] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||wpe.uk.com:2083|F|4"] [data "CONNECT wpe.uk.com:2083 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "wpe.uk.com"] [uri "/"] [unique_id "ahutXjMRtNBk4EAOUqaHcQAAAc4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-31 02:46:21
(3 months ago)
(mod_security) mod_security (id:217210) triggered by 2600:3c15::2000:aff:fe0a:fcee (Unknown): 1 in t ...
show more
(mod_security) mod_security (id:217210) triggered by 2600:3c15::2000:aff:fe0a:fcee (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 22:46:17.494498 2026] [security2:error] [pid 30432:tid 30432] [client 2600:3c15::2000:aff:fe0a:fcee:47244] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||spacebooger.com:443|F|4"] [data "CONNECT spacebooger.com:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "spacebooger.com"] [uri "/"] [unique_id "ahug-V2Ywi5mraZgKvW-xQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-30 22:59:46
(3 months ago)
(mod_security) mod_security (id:217210) triggered by 2600:3c15::2000:aff:fe0a:fcee (Unknown): 1 in t ...
show more
(mod_security) mod_security (id:217210) triggered by 2600:3c15::2000:aff:fe0a:fcee (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 18:59:40.839137 2026] [security2:error] [pid 26849:tid 26849] [client 2600:3c15::2000:aff:fe0a:fcee:46846] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||bodiehistory.com:443|F|4"] [data "CONNECT bodiehistory.com:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "bodiehistory.com"] [uri "/"] [unique_id "ahtr3AitfmiwbN6vAnshKQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack