๐บ๐ธ
sandra361
2026-08-27 00:55:49
(7 hours ago)
Port scan detected: 6 attempts across 1 port (443). | Evidence: REAPER_TARPIT: IN=enp1s0 SRC=42.201. ...
show more
Port scan detected: 6 attempts across 1 port (443). | Evidence: REAPER_TARPIT: IN=enp1s0 SRC=42.201.192.52 LEN=40 TOS=0x00 PREC=0x00 TTL=51 ID=5020 DF PROTO=TCP SPT=50873 DPT=443 WINDOW=64240 RES=0x00 ACK FIN URGP=0
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-26 23:20:48
(9 hours ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.52 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 19:20:42.490537 2026] [security2:error] [pid 1023551:tid 1023581] [client 42.201.192.52:15320] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||gryphix.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "gryphix.com"] [uri "/"] [unique_id "ao90ysblEG4iDLO5Pk8tgAAAABM"], referer: https://hopesbrunchhouse.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 06:07:36
(1 day ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.52 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 02:07:31.006670 2026] [security2:error] [pid 7519:tid 7519] [client 42.201.192.52:34019] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||mark-et-ing-1llc.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "mark-et-ing-1llc.com"] [uri "/cgi-bin"] [unique_id "ao6Co8xCYCB-KNmlCIGkLgAAAI8"], referer: https://mark-et-ing-1llc.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 23:52:09
(1 day ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.52 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 19:52:05.594570 2026] [security2:error] [pid 14276:tid 14276] [client 42.201.192.52:60738] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||thelundbergs.us|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "thelundbergs.us"] [uri "/"] [unique_id "ao4qpSQq726hnlFxK9K9kAAAAAw"], referer: https://thelundbergs.us/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 20:59:06
(1 day ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.52 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 16:59:01.744098 2026] [security2:error] [pid 22206:tid 22293] [client 42.201.192.52:13551] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||madtruckerbill.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "madtruckerbill.com"] [uri "/"] [unique_id "ao4CFdSREbz8RoJobbDlNgAAAMc"], referer: https://madtruckerbill.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 18:09:01
(1 day ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.52 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 14:08:58.485505 2026] [security2:error] [pid 17423:tid 17423] [client 42.201.192.52:41964] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||thechoiceint.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "thechoiceint.com"] [uri "/"] [unique_id "ao3aOoRMOnJG29cPq-19vwAAAA0"], referer: https://thechoiceint.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 05:56:44
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.52 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 01:56:39.162120 2026] [security2:error] [pid 18863:tid 18863] [client 42.201.192.52:47394] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||recorplast.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "recorplast.com"] [uri "/"] [unique_id "ao0ul9l2dWQGdyxCTw8gfAAAAAU"], referer: https://recorplast.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 04:50:31
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.52 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 00:50:23.611721 2026] [security2:error] [pid 6631:tid 6631] [client 42.201.192.52:27164] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||rogerheath.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "rogerheath.com"] [uri "/"] [unique_id "ao0fD9_Q6GVtC_dhMJjF4wAAAAk"], referer: https://rogerheath.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 13:22:57
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.52 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 09:22:51.821129 2026] [security2:error] [pid 1109:tid 1109] [client 42.201.192.52:10254] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||pist.org.tr|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "pist.org.tr"] [uri "/"] [unique_id "aoxFq7WvcQRU5w6Wki3d-QAAABc"], referer: https://pist.org.tr/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Jochen Pretli
2026-08-23 19:56:38
(3 days ago)
connection to honeypot
Email Spam
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-23 18:02:33
(3 days ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.52 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 14:02:27.659248 2026] [security2:error] [pid 19171:tid 19171] [client 42.201.192.52:60511] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||allafricaadventures.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "allafricaadventures.com"] [uri "/"] [unique_id "aos1s3HQ3izltNQAwOO8zAAAABE"], referer: https://allafricaadventures.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 19:44:42
(6 days ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.52 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 15:44:35.915296 2026] [security2:error] [pid 26983:tid 26983] [client 42.201.192.52:42269] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||radiofamilia.com.mx|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "radiofamilia.com.mx"] [uri "/"] [unique_id "aodZI1oAOSB0vk4kcNpb8QAAAA8"], referer: https://radiofamilia.com.mx/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 01:03:51
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.52 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 21:03:45.493326 2026] [security2:error] [pid 13232:tid 13232] [client 42.201.192.52:37058] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||valueproducersalliance.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "valueproducersalliance.org"] [uri "/"] [unique_id "aoZScZ6-SFHy4Qf9m4Ni_gAAAFs"], referer: https://valueproducersalliance.org/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
conseilgouz
2026-08-19 17:22:59
(1 week ago)
saw-Joomla User : try to access forms...
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-19 03:13:22
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.52 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 23:13:14.956480 2026] [security2:error] [pid 28022:tid 28022] [client 42.201.192.52:45438] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||makaihe.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "makaihe.com"] [uri "/"] [unique_id "aoUfSnT516aY9M7ubZnx9gAAABA"], referer: https://makaihe.com/
show less
Brute-Force
Bad Web Bot
Web App Attack