🇺🇸
TPI-Abuse
2026-09-05 13:21:14
(4 hours ago)
(mod_security) mod_security (id:210350) triggered by 38.154.90.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 38.154.90.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 09:21:08.741907 2026] [security2:error] [pid 5652:tid 5652] [client 38.154.90.11:34755] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||stevedegroodt.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "stevedegroodt.com"] [uri "/robots.txt"] [unique_id "apwXRFABBqwUDwfxf9j5ZgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:50:47
(1 day ago)
(mod_security) mod_security (id:210350) triggered by 38.154.90.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 38.154.90.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:50:40.698082 2026] [security2:error] [pid 20903:tid 20903] [client 38.154.90.11:38739] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||got-stuff.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "got-stuff.net"] [uri "/sitemap.xml"] [unique_id "apro0DPfo8wTL_a0k17A4AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 14:27:49
(3 days ago)
(mod_security) mod_security (id:210350) triggered by 38.154.90.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 38.154.90.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 10:27:41.150913 2026] [security2:error] [pid 14108:tid 14108] [client 38.154.90.11:33493] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||bloomandfleur.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "bloomandfleur.com"] [uri "/robots.txt"] [unique_id "apgyXWkmYyqMbJwTFaR29AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-18 21:29:40
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 38.154.90.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 38.154.90.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 17:29:34.408374 2026] [security2:error] [pid 2180:tid 2180] [client 38.154.90.11:49028] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||contentdividend.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "contentdividend.com"] [uri "/sitemap.xml"] [unique_id "aoTOvjfpJ-nFU83qSyD8sgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
cwytech
2026-08-16 03:59:52
(2 weeks ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: cwy/tpot-web-high.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-27 22:24:05
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 38.154.90.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 38.154.90.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 18:24:00.510731 2026] [security2:error] [pid 2451001:tid 2451001] [client 38.154.90.11:48399] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||pcmechanic.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "pcmechanic.com"] [uri "/"] [unique_id "amfagDdVul4NVWzb7kCSggAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-24 04:57:08
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 38.154.90.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 38.154.90.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 00:57:02.580383 2026] [security2:error] [pid 453531:tid 453531] [client 38.154.90.11:42938] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||jimlawless.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "jimlawless.net"] [uri "/"] [unique_id "amLwnmoQxJtl0pjWnQpWpgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-14 23:20:23
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 38.154.90.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 38.154.90.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 14 19:20:14.654553 2026] [security2:error] [pid 23499:tid 23499] [client 38.154.90.11:59630] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||elgatocapa.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "elgatocapa.com"] [uri "/robots.txt"] [unique_id "albELlnuq1Kn42kohFTuIAAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-07-10 03:26:42
(1 month ago)
Multiple/Conflicting Connection Header Data Found. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(? ...
show more
Multiple/Conflicting Connection Header Data Found. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. (920210-197)
show less
Hacking
🇫🇷
masterguru
2026-07-06 06:50:55
(1 month ago)
Multiple/Conflicting Connection Header Data Found. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(? ...
show more
Multiple/Conflicting Connection Header Data Found. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. (920210-195)
show less
Hacking
🇺🇸
TPI-Abuse
2026-07-05 12:24:08
(2 months ago)
(mod_security) mod_security (id:210350) triggered by 38.154.90.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 38.154.90.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 05 08:24:05.216548 2026] [security2:error] [pid 26557:tid 26557] [client 38.154.90.11:57776] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||faithlines.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "faithlines.com"] [uri "/"] [unique_id "akpM5Vnh3kmQUMYO4O8KZwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-22 02:00:37
(2 months ago)
(mod_security) mod_security (id:210350) triggered by 38.154.90.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 38.154.90.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 22:00:31.959801 2026] [security2:error] [pid 23160:tid 23160] [client 38.154.90.11:38902] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||cynosurephotography.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "cynosurephotography.com"] [uri "/robots.txt"] [unique_id "ajiXP8Gp-zBaW_SuNO__9QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-15 00:30:17
(2 months ago)
(mod_security) mod_security (id:210350) triggered by 38.154.90.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 38.154.90.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 20:30:09.260453 2026] [security2:error] [pid 20248:tid 20248] [client 38.154.90.11:38810] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.bernsteinip.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.bernsteinip.com"] [uri "/"] [unique_id "ai9HkYwszez7fH2mUEcCwgAAACw"], referer: http://www.bernsteinip.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-11 15:06:53
(2 months ago)
(mod_security) mod_security (id:210350) triggered by 38.154.90.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 38.154.90.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 11:06:47.411247 2026] [security2:error] [pid 30063:tid 30094] [client 38.154.90.11:57695] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||powercoupling.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "powercoupling.com"] [uri "/robots.txt"] [unique_id "airPB8FMd4Zncyb9P4igLgAAAJg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-08 11:26:45
(2 months ago)
(mod_security) mod_security (id:210350) triggered by 38.154.90.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 38.154.90.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 07:26:37.660288 2026] [security2:error] [pid 26452:tid 26452] [client 38.154.90.11:32923] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||satanisdead.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "satanisdead.com"] [uri "/sitemap.xml"] [unique_id "aiam7ej24Jg4gcDT2lR7BQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack