Anonymous
2026-04-24 01:21:33
(1 month ago)
Forum/form spam
Web Spam
πΊπΈ
TPI-Abuse
2025-09-19 11:35:10
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 45.80.106.19 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 45.80.106.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 19 07:35:06.987756 2025] [security2:error] [pid 1555:tid 1555] [client 45.80.106.19:9473] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||desertdwellings.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "desertdwellings.com"] [uri "/"] [unique_id "aM0_6rZbqZg-pkk-j6iAmwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
backslash
2025-05-10 13:10:06
(1 year ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
Anonymous
2025-01-17 11:44:18
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
π¨π¦
wil.com
2024-09-26 05:43:27
(1 year ago)
GlobalProtect login attempts with user hblackwell.
VPN IP
Brute-Force
πΊπΈ
TPI-Abuse
2024-02-12 08:20:14
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 45.80.106.19 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.80.106.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 12 03:20:11.620802 2024] [security2:error] [pid 19757] [client 45.80.106.19:38199] [client 45.80.106.19] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||portalvasco.com|F|2"] [data ".mdb"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "portalvasco.com"] [uri "/gesauto/bancopruebas.mdb"] [unique_id "ZcnUu2if0y87vBng2E2y4gAAAAs"], referer: https://portalvasco.com/gesauto
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-02-09 06:04:54
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 45.80.106.19 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.80.106.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 09 01:04:51.198996 2024] [security2:error] [pid 21188] [client 45.80.106.19:37377] [client 45.80.106.19] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Barcalounger/Images/Briarwood II/Briarwood II/Stetson Coffee/originals/Thumbs.db"] [unique_id "ZcXAg4by35BSNvpcCvXxJQAAAAM"], referer: https://vitalitywebb.com/backstore/Barcalounger/Images/Briarwood%20II/Briarwood%20II/Stetson%20Coffee/originals/
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Roderic
2023-12-18 00:38:29
(2 years ago)
(apache-bow-document) Failed apache-bow-scanners trigger with match [redacted] from 45.80.106.19 (IL ...
show more
(apache-bow-document) Failed apache-bow-scanners trigger with match [redacted] from 45.80.106.19 (IL/Israel/-)
show less
Hacking
π¨π
backslash
2023-10-06 14:00:20
(2 years ago)
honeypot
Bad Web Bot
π¨π¦
Justmee
2023-09-29 22:50:14
(2 years ago)
Sep 29 16:50:10 server1 kernel: [1069522.381013] IPTABLES: IN=eth0 OUT= MAC=00:22:19:d7:2c:94:04:42: ...
show more
Sep 29 16:50:10 server1 kernel: [1069522.381013] IPTABLES: IN=eth0 OUT= MAC=00:22:19:d7:2c:94:04:42:1a:61:50:d8:08:00 SRC=45.80.106.19 DST=192.168.100.3 LEN=52 TOS=0x00 PREC=0x00 TTL=116 ID=110 DF PROTO=TCP SPT=56349 DPT=443 WINDOW=42340 RES=0x00 SYN URGP=0
Sep 29 16:50:11 server1 kernel: [1069523.385333] IPTABLES: IN=eth0 OUT= MAC=00:22:19:d7:2c:94:04:42:1a:61:50:d8:08:00 SRC=45.80.106.19 DST=192.168.100.3 LEN=52 TOS=0x00 PREC=0x00 TTL=116 ID=111 DF PROTO=TCP SPT=56349 DPT=443 WINDOW=42340 RES=0x00 SYN URGP=0
Sep 29 16:50:13 server1 kernel: [1069525.396867] IPTABLES: IN=eth0 OUT= MAC=00:22:19:d7:2c:94:04:42:1a:61:50:d8:08:00 SRC=45.80.106.19 DST=192.168.100.3 LEN=52 TOS=0x00 PREC=0x00 TTL=116 ID=112 DF PROTO=TCP SPT=56349 DPT=443 WINDOW=42340 RES=0x00 SYN URGP=0
...
show less
Hacking
Brute-Force
π¨π
backslash
2023-09-04 11:54:31
(2 years ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot