Anonymous
2026-07-22 06:01:36
(1 day ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 07:19:01
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 31.204.31.226 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 31.204.31.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 03:18:50.538824 2026] [security2:error] [pid 28351:tid 28351] [client 31.204.31.226:60723] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||hvacmechanalysis.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "hvacmechanalysis.com"] [uri "/about"] [unique_id "ab5GWs59xchdtrFR0DGqSQAAABw"], referer: https://hvacmechanalysis.com/about
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-18 10:49:59
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 31.204.31.226 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 31.204.31.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 18 06:49:53.327228 2026] [security2:error] [pid 4081:tid 4081] [client 31.204.31.226:47731] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.controvac.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.controvac.com"] [uri "/home/nuestra-empresa/"] [unique_id "abqDUWJYUMVvHA433cTYsgAAABA"], referer: https://www.controvac.com/home/nuestra-empresa/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-16 17:14:16
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 31.204.31.226 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 31.204.31.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 16 13:14:11.089494 2026] [security2:error] [pid 16495:tid 16495] [client 31.204.31.226:29185] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||dupagekanewildliferemoval.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "dupagekanewildliferemoval.com"] [uri "/about"] [unique_id "abg6Y1_-REgKlAzVPIjduQAAAB4"], referer: https://dupagekanewildliferemoval.com/about
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-11 04:08:57
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 31.204.31.226 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 31.204.31.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 11 00:07:52.321330 2026] [security2:error] [pid 21693:tid 21693] [client 31.204.31.226:54401] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||muskogeecleaning.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "muskogeecleaning.com"] [uri "/about-us"] [unique_id "abDqmEhIxJIsn1iEB3EOLQAAAAs"], referer: https://muskogeecleaning.com/about-us
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-04 09:51:10
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 31.204.31.226 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 31.204.31.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 04 04:51:04.965465 2026] [security2:error] [pid 511:tid 511] [client 31.204.31.226:41383] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||dominionfinancialadvisors.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "dominionfinancialadvisors.com"] [uri "/financial-planning/do-i-need-a-fee-only-financial-advisor"] [unique_id "aagAiH8vK3hlpbuu7W0ynAAAABc"], referer: https://dominionfinancialadvisors.com/financial-planning/do-i-need-a-fee-only-financial-advisor
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-24 15:54:00
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 31.204.31.226 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 31.204.31.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 24 10:53:50.551270 2026] [security2:error] [pid 6622:tid 6622] [client 31.204.31.226:48605] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||ktnwassociatesinc.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "ktnwassociatesinc.com"] [uri "/about"] [unique_id "aZ3JjmQamBowQ-_JxMFsEQAAAAQ"], referer: https://ktnwassociatesinc.com/about
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
cloudmax
2025-08-01 15:44:18
(11 months ago)
Cloudmax IPS Block - Suspicious activity. Possible port scanning, service reconnaissance, or vulnera ...
show more
Cloudmax IPS Block - Suspicious activity. Possible port scanning, service reconnaissance, or vulnerability probing
show less
Port Scan