πΊπΈ
TPI-Abuse
2026-08-23 16:23:38
(2 hours ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 12:23:35.406504 2026] [security2:error] [pid 17039:tid 17069] [client 42.201.192.19:59008] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||certifiedebusinessconsultant.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "certifiedebusinessconsultant.com"] [uri "/crop/ui/packages"] [unique_id "aoseh_D-rEBvIlhl-Ibn6gAAAFY"], referer: https://certifiedebusinessconsultant.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
ππ·
bubausluge
2026-08-22 14:33:21
(1 day ago)
Blocked by https://aegis.hr β WAF: ModSec rule match - (MITRE T1190), 1 attempts, Period: 2026-08-22 ...
show more
Blocked by https://aegis.hr β WAF: ModSec rule match - (MITRE T1190), 1 attempts, Period: 2026-08-22 14:15:28 to 2026-08-22 14:15:28
show less
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-08-22 07:58:47
(1 day ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 03:58:40.883884 2026] [security2:error] [pid 15563:tid 15563] [client 42.201.192.19:47469] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||zaril.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "zaril.com"] [uri "/"] [unique_id "aolWsMd-QYJad6LjbOpl8QAAAAA"], referer: https://zaril.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
conseilgouz
2026-08-21 15:44:38
(2 days ago)
avw-(visforms) : try to access forms...
Hacking
πΊπΈ
TPI-Abuse
2026-08-21 14:26:19
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 10:26:11.075827 2026] [security2:error] [pid 6184:tid 6184] [client 42.201.192.19:32188] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||seescribe.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "seescribe.com"] [uri "/"] [unique_id "aohgA8YUIJKQpwPPsO43xQAAAAM"], referer: https://seescribe.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-21 13:30:06
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 09:30:00.678242 2026] [security2:error] [pid 8233:tid 8233] [client 42.201.192.19:29008] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||nancybarrera.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "nancybarrera.com"] [uri "/"] [unique_id "aohS2J-fMqnazg-oVgwbUQAAAAA"], referer: https://nancybarrera.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-08-20 12:42:54
(3 days ago)
[20/Aug/2026:15:42:54 +0300] -- 42.201.192.19 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-c ...
show more
[20/Aug/2026:15:42:54 +0300] -- 42.201.192.19 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-content/uploads/sites/58/2017/05/21-45.pdf HTTP/1.1
show less
Bad Web Bot
Web App Attack
πΊπΈ
MPL
2026-08-20 01:56:48
(3 days ago)
tcp/443 (5 or more attempts)
Port Scan
πΊπΈ
TPI-Abuse
2026-08-18 17:55:43
(5 days ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 13:55:36.155980 2026] [security2:error] [pid 29872:tid 29872] [client 42.201.192.19:32205] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||enchantmenttours.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "enchantmenttours.com"] [uri "/"] [unique_id "aoScmLOsMN_Xsw6pPos3JQAAAAA"], referer: https://enchantmenttours.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-18 12:13:48
(5 days ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 08:13:44.152766 2026] [security2:error] [pid 2317:tid 2317] [client 42.201.192.19:58934] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||kbalan.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "kbalan.com"] [uri "/"] [unique_id "aoRMeDrEgnvbSmzgynM-AwAAAAQ"], referer: https://kbalan.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-18 09:33:28
(5 days ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 05:33:20.589921 2026] [security2:error] [pid 3276:tid 3276] [client 42.201.192.19:62143] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||chicagowca.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "chicagowca.com"] [uri "/"] [unique_id "aoQm4EzzeUq-jI2hgFo38wAAAAI"], referer: https://chicagowca.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-18 06:55:33
(5 days ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 02:55:27.505016 2026] [security2:error] [pid 464:tid 464] [client 42.201.192.19:52076] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.lockdownclaim.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.lockdownclaim.com"] [uri "/"] [unique_id "aoQB3zUrVzHwkT9Mdt5KCgAAAAo"], referer: https://lockdownclaim.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-18 05:40:28
(5 days ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 01:40:20.541041 2026] [security2:error] [pid 9009:tid 9009] [client 42.201.192.19:15383] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||fgrotary.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "fgrotary.org"] [uri "/speaker/wrap-up-meeting"] [unique_id "aoPwRAnOrV0P8bObCqhV5QAAACg"], referer: https://fgrotary.org/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-18 01:21:40
(5 days ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 21:21:33.162641 2026] [security2:error] [pid 10130:tid 10130] [client 42.201.192.19:21852] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||schonplanet.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "schonplanet.com"] [uri "/"] [unique_id "aoOznRwvY1paCf2VDerX3gAAAAM"], referer: https://schonplanet.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 23:26:14
(5 days ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 19:26:08.188071 2026] [security2:error] [pid 15627:tid 15627] [client 42.201.192.19:32377] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||nhgrange.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "nhgrange.org"] [uri "/"] [unique_id "aoOYkEOiwCMma8ITrzXqwgAAAAE"], referer: https://nhgrange.org/
show less
Brute-Force
Bad Web Bot
Web App Attack