πΊπΈ
TPI-Abuse
2026-06-17 04:31:55
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 00:31:48.170798 2026] [security2:error] [pid 14428:tid 14428] [client 42.201.192.49:35446] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||cier.xyz|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "cier.xyz"] [uri "/"] [unique_id "ajIjNIGBouNxg0h4XEEw5AAAABk"], referer: https://cier.xyz/
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
prologic
2026-06-13 03:22:02
(6 days ago)
Coordinated application-layer DDoS against git.mills.io (self-hosted Gitea), 2026-06-12 ~20:30-21:10 ...
show more
Coordinated application-layer DDoS against git.mills.io (self-hosted Gitea), 2026-06-12 ~20:30-21:10 UTC. Deliberately expensive multi-label Gitea issue-search queries (/issues?type=all&state=closed&sort=...&labels=<multiple IDs>, ~60-113s CPU each) flooded the backend via proxy/hosting networks. ~36,700 source IPs, ~1 request per IP, identical TLS fingerprint (TLS1.3 0x1301) and one spoofed Chrome UA = single automated tool.
show less
DDoS Attack
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-12 08:36:43
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 04:36:40.113304 2026] [security2:error] [pid 8165:tid 8370] [client 42.201.192.49:37358] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||esgcommission.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "esgcommission.org"] [uri "/"] [unique_id "aivFGIMhLxxHWsBMeGqV9QAAAkc"], referer: http://esgcommission.org/
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨πΏ
netmagnet
2026-06-07 09:14:33
(1 week ago)
Automated HTTP request flood (1737 requests in ~10 min) to lovecpokladu.cz using spam ?backlink= que ...
show more
Automated HTTP request flood (1737 requests in ~10 min) to lovecpokladu.cz using spam ?backlink= query params; bad web bot / web app attack from Huawei Cloud HK.
show less
Web Spam
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-03 22:45:49
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 18:45:43.178660 2026] [security2:error] [pid 23148:tid 23148] [client 42.201.192.49:20538] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.stpetersplayers.co.uk|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.stpetersplayers.co.uk"] [uri "/"] [unique_id "aiCulw2TkJozHBurwzQP_QAAAA0"], referer: http://www.stpetersplayers.co.uk/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
kosada.com
2026-05-28 10:02:39
(3 weeks ago)
Web bot: DDoS
DDoS Attack
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-05-20 18:54:28
(4 weeks ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 14:54:20.548326 2026] [security2:error] [pid 31901:tid 31901] [client 42.201.192.49:37114] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||portalvasco.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "portalvasco.com"] [uri "/blog/2014/02/una-red-paneuropea-para-investigar-las-prioridades-en-seguridad-vial"] [unique_id "ag4DXAbHyOIOAgCmp2IXUQAAAA4"], referer: https://portalvasco.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
kosada.com
2026-05-17 23:51:39
(1 month ago)
Web bot: DDoS
DDoS Attack
Bad Web Bot