๐บ๐ธ
xmission.com
2026-06-15 13:15:44
(4 days ago)
Blocked by UFW (TCP on 80)
Source port: 36074
TTL: 55
Packet length: 60
TOS: 0x08
This report (for ...
show more
Blocked by UFW (TCP on 80)
Source port: 36074
TTL: 55
Packet length: 60
TOS: 0x08
This report (for 43.156.116.54) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack
๐บ๐ธ
itsnixk
2026-06-15 12:11:20
(4 days ago)
(mod_security) mod_security (id:920210) triggered by 43.156.116.54 (SG/Singapore/-): 1 in the last 3 ...
show more
(mod_security) mod_security (id:920210) triggered by 43.156.116.54 (SG/Singapore/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Mon Jun 15 08:11:13.904740 2026] [security2:error] [pid 387306:tid 387396] [client 43.156.116.54:56250] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "402"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [redacted] [severity "WARNING"] [ver "OWASP_CRS/4.26.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/"] [unique_id "ai_r4dDxfRSeQb7tHJgw1AAAAAc"]
show less
Port Scan
๐ฆ๐บ
PetePK
2026-06-15 07:59:03
(4 days ago)
Probed 4 time(s): TCP/80
Port Scan
๐จ๐ฟ
kronos
2026-06-15 06:21:19
(4 days ago)
IDS: FlowIntel scan-like source | SID:9900001 | session_sigs:1296 | alerts5m:1297
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-10 05:33:04
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 43.156.116.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 43.156.116.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 01:32:59.665235 2026] [security2:error] [pid 30364:tid 30364] [client 43.156.116.54:38376] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||turtlehill.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "turtlehill.org"] [uri "/"] [unique_id "aij3C5SRg_HtA5pQxB2fRgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Lezetho
2026-06-10 03:00:45
(1 week ago)
DDoS, WebSpam, Web Attack, and Brute-force blocked by Cloudflare
DDoS Attack
Email Spam
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-10 02:31:04
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 43.156.116.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 43.156.116.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 22:30:56.975820 2026] [security2:error] [pid 10081:tid 10081] [client 43.156.116.54:33358] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||candlecrawler.trade|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "candlecrawler.trade"] [uri "/"] [unique_id "aijMYFZfej893_WzvymW2AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 01:56:02
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 43.156.116.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 43.156.116.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 21:55:55.809725 2026] [security2:error] [pid 27396:tid 27396] [client 43.156.116.54:45234] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||elmawamarine.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "elmawamarine.com"] [uri "/"] [unique_id "aijEK8bOZlT_SpVXMLLBVwAAAAU"], referer: http://elmawamarine.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 13:04:16
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 43.156.116.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 43.156.116.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 09:04:10.090110 2026] [security2:error] [pid 30244:tid 30244] [client 43.156.116.54:51376] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||bees.properties|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "bees.properties"] [uri "/"] [unique_id "aigPStP7-q3v_0W2VA1qRwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 12:29:54
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 43.156.116.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 43.156.116.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 08:29:47.743713 2026] [security2:error] [pid 9481:tid 9481] [client 43.156.116.54:38140] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||192.64.150.233:80|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "192.64.150.233"] [uri "/"] [unique_id "aigHO7jNiC3d_Ybgjci7EwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 12:13:53
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 43.156.116.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 43.156.116.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 08:13:46.988793 2026] [security2:error] [pid 31936:tid 31936] [client 43.156.116.54:52988] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.enriquejezik.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.enriquejezik.com"] [uri "/"] [unique_id "aigDetQ7glxNOawoguTHPAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 11:57:06
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 43.156.116.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 43.156.116.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 07:56:58.597277 2026] [security2:error] [pid 32350:tid 32350] [client 43.156.116.54:51532] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||endriss.info|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "endriss.info"] [uri "/"] [unique_id "aif_iqsrCEuBua5XB31c4AAAADw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 11:41:04
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 43.156.116.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 43.156.116.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 07:41:00.700299 2026] [security2:error] [pid 11576:tid 11576] [client 43.156.116.54:42956] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||advantagept.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "advantagept.org"] [uri "/"] [unique_id "aif7zDpwEk09h1WpQB9ycQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 11:25:28
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 43.156.116.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 43.156.116.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 07:25:24.060488 2026] [security2:error] [pid 28088:tid 28088] [client 43.156.116.54:50040] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||fourminutedecision.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "fourminutedecision.com"] [uri "/index.php"] [unique_id "aif4JGZRIGHGZLnGYtqjSgAAAAc"], referer: http://barriewhite.xyz
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 11:08:49
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 43.156.116.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 43.156.116.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 07:08:40.881242 2026] [security2:error] [pid 26861:tid 26885] [client 43.156.116.54:38100] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.tvpin.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.tvpin.com"] [uri "/index.cgi"] [unique_id "aif0OCtr9lIys2oTLsvVgAAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack