π¦πΊ
FireGuard Server
2026-09-14 04:30:07
(3 weeks ago)
Blocked by os-abuseipdb; 5 hits, proto=tcp, ports=443
Port Scan
Hacking
πΊπΈ
sandra361
2026-09-14 04:12:49
(3 weeks ago)
Port scan detected: 6 attempts across 1 port (443). | Evidence: REAPER_TARPIT: IN=enp1s0 SRC=42.201. ...
show more
Port scan detected: 6 attempts across 1 port (443). | Evidence: REAPER_TARPIT: IN=enp1s0 SRC=42.201.192.30 LEN=487 TOS=0x00 PREC=0x00 TTL=51 ID=12294 DF PROTO=TCP SPT=42216 DPT=443 WINDOW=64240 RES=0x00 ACK PSH URGP=0
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-09-14 01:13:44
(3 weeks ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 21:13:36.222783 2026] [security2:error] [pid 21809:tid 21809] [client 42.201.192.30:35533] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||schmitzcomm.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "schmitzcomm.net"] [uri "/"] [unique_id "aqdKQA8AEVEv4GJGHEZbmQAAAA8"], referer: https://five.co.in/redirect.php?ref_host=puummpru.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-13 22:57:18
(3 weeks ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 18:57:10.843624 2026] [security2:error] [pid 5643:tid 5643] [client 42.201.192.30:28886] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||arsndetx.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "arsndetx.com"] [uri "/"] [unique_id "aqcqRsntBPC4FLNDYf1slgAAAAI"], referer: https://five.co.in/redirect.php?ref_host=hodlvpn.xyz
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-13 14:13:19
(3 weeks ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 10:13:13.097510 2026] [security2:error] [pid 32599:tid 32599] [client 42.201.192.30:32252] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.thesteeldrumman.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.thesteeldrumman.com"] [uri "/"] [unique_id "aqaveSovjzW8WYdpFafqqQAAAAw"], referer: https://five.co.in/redirect.php?ref_host=keepingtrucking.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-13 08:27:10
(3 weeks ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 04:27:02.705209 2026] [security2:error] [pid 10713:tid 10713] [client 42.201.192.30:15230] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||bpcompany.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "bpcompany.net"] [uri "/"] [unique_id "aqZeVl1gjvtT0fM4Z_rwDQAAAA4"], referer: https://five.co.in/redirect.php?ref_host=oc55healthandlifestyle.info
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-13 06:03:30
(3 weeks ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 02:03:22.712857 2026] [security2:error] [pid 11580:tid 11580] [client 42.201.192.30:32241] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||clipper1970.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "clipper1970.com"] [uri "/"] [unique_id "aqY8qn2_qjoXhdbDuzf-vwAAAAw"], referer: https://five.co.in/redirect.php?ref_host=smallbusinessstrategists.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-13 00:50:36
(4 weeks ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 20:50:32.156744 2026] [security2:error] [pid 7514:tid 7514] [client 42.201.192.30:30477] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||soudertonbigred.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "soudertonbigred.org"] [uri "/"] [unique_id "aqXzWDDdHqnvsjHz-M_hXQAAAAs"], referer: https://phillywrestling.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-12 21:18:55
(4 weeks ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 17:18:51.764472 2026] [security2:error] [pid 55419:tid 55419] [client 42.201.192.30:52159] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||angelpc.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "angelpc.net"] [uri "/"] [unique_id "aqXBuzxltof0cVwDDcZUbAAAAAU"], referer: https://addurl.in/redirect.php?ref_host=kupandacapital.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-12 20:44:11
(4 weeks ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 16:44:06.041428 2026] [security2:error] [pid 3454:tid 3457] [client 42.201.192.30:50694] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||montanatribes.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "montanatribes.org"] [uri "/"] [unique_id "aqW5lpT0qIvEZ7poy8eE1AAAAAE"], referer: https://five.co.in/redirect.php?ref_host=muenchenmarketing.de
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-12 20:09:36
(4 weeks ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 16:09:32.681852 2026] [security2:error] [pid 7185:tid 7185] [client 42.201.192.30:40406] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||angelsofrhodeisland.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "angelsofrhodeisland.com"] [uri "/"] [unique_id "aqWxfFn1AlV1yvcr5Ofd0gAAAC4"], referer: https://five.co.in/redirect.php?ref_host=tonyartists.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-12 12:40:46
(4 weeks ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 08:40:39.665998 2026] [security2:error] [pid 15760:tid 15762] [client 42.201.192.30:60777] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.vote4joegardner.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.vote4joegardner.com"] [uri "/403.shtml"] [unique_id "aqVIR4lilghVP2QGfd8pcwAAAQA"], referer: https://five.co.in/redirect.php?ref_host=nwatracking.com
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
LRob
2026-09-12 08:46:19
(4 weeks ago)
Asking over plain http and never following the redirect served β a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served β a crawler that reads nothing it asks for | method: GET | path: /evenement_details/rando-des-fours | 2026-09-12 08:46 UTC
show less
Bad Web Bot
Anonymous
2026-09-11 14:33:00
(4 weeks ago)
"Security violation, excess traffic against library/education infrastructure"
Brute-Force
πΊπΈ
eacontent
2026-09-10 09:20:00
(1 month ago)
[Thu Sep 10 03:47:34.357955 2026] [security2:error] [pid 10720:tid 10741] [client 42.201.192.30:1008 ...
show more
[Thu Sep 10 03:47:34.357955 2026] [security2:error] [pid 10720:tid 10741] [client 42.201.192.30:10081] [client 42.201.192.30] ModSecurity: Warning. Pattern match "\\\\b(keep-alive|close),\\\\s?(keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "198"] [id "920210"] [rev "2"] [msg "Multiple/Conflicting Connection Header Data Found."] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.0.0"] [maturity "6"] [accuracy "8"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/INVALID_HREQ"] [hostname "supplylinedemo.net"] [uri "/pages/non-insulated-terminals-p2696.html"] [unique_id "aqJgljg0qLt2XZiexjh28QAAAdM"], referer: https://supplylinedemo.net/
show less
Hacking