🇺🇸
TPI-Abuse
2026-09-08 04:14:46
(1 day ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:14:41.044003 2026] [security2:error] [pid 13128:tid 13128] [client 42.201.192.1:25577] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||talentstar2025.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "talentstar2025.com"] [uri "/spotlight/spotlight-welcome"] [unique_id "ap-LsRlCvlJ7m2CeTkKgPgAAAAk"], referer: https://talentstar2025.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 09:21:49
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:21:43.344702 2026] [security2:error] [pid 5480:tid 5480] [client 42.201.192.1:22161] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.creartest.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.creartest.com"] [uri "/403.shtml"] [unique_id "apaZJ04_xgQ5Vy7AafIZ0QAAAAU"], referer: https://creartest.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2026-08-31 07:40:36
(1 week ago)
[31/Aug/2026:10:40:36 +0300] -- 42.201.192.1 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-co ...
show more
[31/Aug/2026:10:40:36 +0300] -- 42.201.192.1 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-content/uploads/sites/58/2017/06/9-51.pdf HTTP/1.1
show less
Bad Web Bot
Web App Attack
Anonymous
2026-08-30 14:03:03
(1 week ago)
Web attack
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 07:39:34
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 03:39:28.287242 2026] [security2:error] [pid 6699:tid 6699] [client 42.201.192.1:50534] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||jamisongreen.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "jamisongreen.com"] [uri "/"] [unique_id "apE7MAflVxLQJu0B3MrjJwAAABI"], referer: https://bikisbeautifulpeople.blogspot.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 00:23:05
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 20:23:00.221017 2026] [security2:error] [pid 10553:tid 10553] [client 42.201.192.1:28663] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||klam.nyc|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "klam.nyc"] [uri "/"] [unique_id "apDU5JcQ25jxfXdSDY1eMwAAAHo"], referer: https://sahammurah.com/all/1626/14.html
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 14:33:18
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 10:33:12.522877 2026] [security2:error] [pid 10249:tid 10249] [client 42.201.192.1:27141] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||sundollsforever.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "sundollsforever.org"] [uri "/"] [unique_id "apBKqDW4DDSVyI_tVsX71AAAAAQ"], referer: https://s-tribe.net/all/534/3.html
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 09:25:46
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 05:25:41.574135 2026] [security2:error] [pid 2278204:tid 2278235] [client 42.201.192.1:10235] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||wbwstudio.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "wbwstudio.com"] [uri "/"] [unique_id "apAClZTTt_PFTEZE2NoB0gAAABU"], referer: https://sahammurah.com/all/3146/1.html
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 08:20:07
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 04:20:04.136800 2026] [security2:error] [pid 11219:tid 11219] [client 42.201.192.1:42451] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||fedeolivaperu.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "fedeolivaperu.com"] [uri "/"] [unique_id "ao_zNA-ZExojTykzP2CR2AAAAAo"], referer: https://fedeolivaperu.com/images?c=n;o=d
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 02:05:29
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 22:05:23.510228 2026] [security2:error] [pid 27908:tid 27908] [client 42.201.192.1:55854] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||yerevanpress.am|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "yerevanpress.am"] [uri "/"] [unique_id "ao-bY-divdiPV2L5czegKgAAAB4"], referer: https://yerevanpress.am/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 00:35:34
(1 week ago)
nginx-444 from fail2ban
...
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 16:47:30
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 12:47:22.572176 2026] [security2:error] [pid 5721:tid 5721] [client 42.201.192.1:30670] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||schonfashion.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "schonfashion.com"] [uri "/"] [unique_id "ao8YmurrnasPCHuNnR9pvwAAABU"], referer: https://schonmusic.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 09:57:10
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 05:57:02.180606 2026] [security2:error] [pid 3630:tid 3630] [client 42.201.192.1:37130] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||varnadorefamily.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "varnadorefamily.com"] [uri "/"] [unique_id "ao64bs2wffV-rQvbm8RN6QAAACA"], referer: https://hotonlinegaming.com/all/3064/4.html
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
HamSammich
2026-08-26 07:03:03
(2 weeks ago)
Automated sensor: 1 HTTPS connection/probe attempts over the last 24h (latest 2026-08-26T07:03Z).
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 05:50:57
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 01:50:49.281353 2026] [security2:error] [pid 31523:tid 31523] [client 42.201.192.1:38953] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||isslv.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "isslv.net"] [uri "/"] [unique_id "ao5-ufuuMiMVG3jZJ056ZgAAABg"], referer: https://isslv.net/
show less
Brute-Force
Bad Web Bot
Web App Attack