๐บ๐ธ
TPI-Abuse
2026-10-03 15:38:55
(4 days ago)
(mod_security) mod_security (id:210350) triggered by 38.9.221.217 (Dinamic-Somos-38-9-221-217.somosi ...
show more
(mod_security) mod_security (id:210350) triggered by 38.9.221.217 (Dinamic-Somos-38-9-221-217.somosinternet.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 11:38:50.844183 2026] [security2:error] [pid 9684:tid 9684] [client 38.9.221.217:49422] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||ajvaage.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "ajvaage.com"] [uri "/"] [unique_id "asEhik1EwygGmhGpyrsijgAAAAM"], referer: https://linkbuildingfreelancer.shop/dir/strategic-seo-backlinks-5210
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 04:09:55
(5 days ago)
(mod_security) mod_security (id:210350) triggered by 38.9.221.217 (Dinamic-Somos-38-9-221-217.somosi ...
show more
(mod_security) mod_security (id:210350) triggered by 38.9.221.217 (Dinamic-Somos-38-9-221-217.somosinternet.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 00:09:48.972710 2026] [security2:error] [pid 13179:tid 13179] [client 38.9.221.217:38736] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||rookscpa.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "rookscpa.com"] [uri "/"] [unique_id "asCADI960i95iOlvGVovwgAAAAM"], referer: https://backlinkspecialist.store/dir/advanced-link-building-178632
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-30 14:36:50
(1 week ago)
Shop search flood (L7 DDoS) | path: /40-meilleur-velo-electrique-entre-4000-et-5000-euros | query: o ...
show more
Shop search flood (L7 DDoS) | path: /40-meilleur-velo-electrique-entre-4000-et-5000-euros | query: order=product.position.asc&productListView=grid&q=Famille-Denna | src_port: 60530
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 09:52:36
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 38.9.221.217 (Dinamic-Somos-38-9-221-217.somosi ...
show more
(mod_security) mod_security (id:210350) triggered by 38.9.221.217 (Dinamic-Somos-38-9-221-217.somosinternet.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 05:52:31.526233 2026] [security2:error] [pid 7791:tid 7791] [client 38.9.221.217:7892] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||keystonebrass.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "keystonebrass.com"] [uri "/"] [unique_id "arzb30-a_oOoeIOzwf7OiQAAACA"], referer: https://qualitybacklinkgenerator.shop/dir/seo-outreach-backlinks-113158
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 05:16:21
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 38.9.221.217 (Dinamic-Somos-38-9-221-217.somosi ...
show more
(mod_security) mod_security (id:210350) triggered by 38.9.221.217 (Dinamic-Somos-38-9-221-217.somosinternet.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 01:16:14.021746 2026] [security2:error] [pid 32413:tid 32413] [client 38.9.221.217:36204] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||sovereignstartups.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "sovereignstartups.com"] [uri "/"] [unique_id "arybHuEn0HavCUyPe8_GJgAAAAA"], referer: https://freebacklinkgeneration.website/dir/backlinks-for-traffic-195250
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 20:01:34
(3 weeks ago)
(mod_security) mod_security (id:210350) triggered by 38.9.221.217 (Dinamic-Somos-38-9-221-217.somosi ...
show more
(mod_security) mod_security (id:210350) triggered by 38.9.221.217 (Dinamic-Somos-38-9-221-217.somosinternet.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 16:01:27.709094 2026] [security2:error] [pid 26947:tid 26947] [client 38.9.221.217:61872] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||mexicanfriedicecreammix.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "mexicanfriedicecreammix.com"] [uri "/"] [unique_id "aqr1l-IeHrWVkLrYmIyaOQAAADQ"], referer: https://bulkdacheckerfree.site/dir/quality-backlink-services-135366
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-20 07:14:17
(10 months ago)
scanning http requests from known botnet
Web App Attack
Anonymous
2025-11-15 02:23:03
(10 months ago)
scanning http requests from known botnet
Web App Attack