Anonymous
2026-07-23 02:23:22
(7 hours ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2026-07-22 01:34:38
(1 day ago)
21 attempts against mh-misbehave-ban on pavo
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-22 01:34:15
(1 day ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-27 21:59:20
(3 months ago)
(mod_security) mod_security (id:210350) triggered by 31.204.28.148 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 31.204.28.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 27 17:59:12.747484 2026] [security2:error] [pid 13372:tid 13372] [client 31.204.28.148:33285] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||naghmehfarahmand.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "naghmehfarahmand.com"] [uri "/about-us"] [unique_id "acb9sI1Uv1zQxWXb_s65fQAAAAU"], referer: https://naghmehfarahmand.com/about-us
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-27 17:37:18
(3 months ago)
(mod_security) mod_security (id:210350) triggered by 31.204.28.148 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 31.204.28.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 27 13:37:08.388832 2026] [security2:error] [pid 2538:tid 2538] [client 31.204.28.148:32529] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||todi.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "todi.org"] [uri "/consolazione_it.html"] [unique_id "acbARG31TpFFr9Ca9qcWOAAAABI"], referer: https://todi.org/consolazione_it.html
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 02:58:31
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 31.204.28.148 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 31.204.28.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 22:56:47.489930 2026] [security2:error] [pid 20758:tid 20780] [client 31.204.28.148:36921] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.willmanlawfirm.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.willmanlawfirm.com"] [uri "/"] [unique_id "ab4I70F41ZPiKtf471qWWAAAAVM"], referer: http://www.willmanlawfirm.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 09:22:33
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 31.204.28.148 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 31.204.28.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 05:22:28.217905 2026] [security2:error] [pid 8946:tid 8946] [client 31.204.28.148:31183] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||globalsolutions.technology|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "globalsolutions.technology"] [uri "/about"] [unique_id "ab0R1BO38u1wcXrYhWlG_gAAAA0"], referer: https://globalsolutions.technology/about
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
jjnxpct
2026-03-15 04:50:35
(4 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /about-us (Rule ID: 920210) - Multiple/Conflicting Connection Header Data Found
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-14 12:09:56
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 31.204.28.148 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 31.204.28.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 08:09:45.928369 2026] [security2:error] [pid 31254:tid 31313] [client 31.204.28.148:46427] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||maritimeclinic.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "maritimeclinic.net"] [uri "/our-story"] [unique_id "abVQCfghJBl93QczK6tBIgAAAUc"], referer: https://maritimeclinic.net/our-story
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-12 02:40:55
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 31.204.28.148 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 31.204.28.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 11 22:40:50.250935 2026] [security2:error] [pid 31996:tid 31996] [client 31.204.28.148:64277] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||indiahouseportland.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "indiahouseportland.com"] [uri "/about-us"] [unique_id "abInsnbp-BgX78LKtwS3xwAAAAo"], referer: https://indiahouseportland.com/about-us
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-11 23:49:09
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 31.204.28.148 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 31.204.28.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 11 19:49:00.250215 2026] [security2:error] [pid 24292:tid 24292] [client 31.204.28.148:39071] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||nowell.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "nowell.net"] [uri "/contactus"] [unique_id "abH_bEH9BZPOSJUXXTtVzAAAAAU"], referer: https://nowell.net/contactus
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-03 22:43:57
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 31.204.28.148 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 31.204.28.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 03 17:43:53.286509 2026] [security2:error] [pid 7425:tid 7425] [client 31.204.28.148:35689] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||ecomim.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "ecomim.com"] [uri "/about"] [unique_id "aadkKfZ3JzzVxSN3O81tkQAAAA4"], referer: https://ecomim.com/about
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-03 22:26:35
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 31.204.28.148 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 31.204.28.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 03 17:26:27.499566 2026] [security2:error] [pid 28011:tid 28011] [client 31.204.28.148:64183] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||robertmcatee.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "robertmcatee.com"] [uri "/contactus"] [unique_id "aadgEw7pVOMY9fj0teQ0zQAAABE"], referer: https://robertmcatee.com/contactus
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-16 02:25:29
(8 months ago)
botnet
DDoS Attack