๐บ๐ธ
cwytech
2026-09-22 23:53:01
(15 hours ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wordpress-geofence-sus.
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 09:28:52
(1 day ago)
FortiWeb WAF: 34 attacks detected. Threat Score: 6800. Types: Client Management(17), GEO IP(17). Ori ...
show more
FortiWeb WAF: 34 attacks detected. Threat Score: 6800. Types: Client Management(17), GEO IP(17). Origin: China.
show less
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-09-22 08:12:18
(1 day ago)
(mod_security-custom) mod_security (id:210350) triggered by 47.106.184.133 (CN/China/Guangdong/Shenz ...
show more
(mod_security-custom) mod_security (id:210350) triggered by 47.106.184.133 (CN/China/Guangdong/Shenzhen/-/[AS37963 ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.,Ltd.]): 1 in the last 3600 secs (0-srv1)
show less
Hacking
๐บ๐ธ
lcpacs
2026-09-21 21:50:14
(1 day ago)
Auto-flagged by honeypot: tripped / โ accept-language: zh-CN โ client-supplied proxy headers (x-forw ...
show more
Auto-flagged by honeypot: tripped / โ accept-language: zh-CN โ client-supplied proxy headers (x-forwarded-proto:http) โ not US+en-US (country: CN, accept-language: zh-CN,zh;q=0.9,en-US;q=0.8,en;q=0.7)
show less
Bad Web Bot
Web App Attack
๐ฎ๐น
Progetto1
2026-09-21 10:30:09
(2 days ago)
Multiple exploit attempts
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 04:56:01
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 47.106.184.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 47.106.184.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:55:56.967008 2026] [security2:error] [pid 16133:tid 16133] [client 47.106.184.133:54034] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||got-stuff.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "got-stuff.net"] [uri "/"] [unique_id "arC43PRdCdSKuwHueAGt6gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 23:35:30
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 47.106.184.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 47.106.184.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:35:23.900173 2026] [security2:error] [pid 24418:tid 24418] [client 47.106.184.133:34866] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.technicallydental.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.technicallydental.com"] [uri "/"] [unique_id "arBtuxUX52Wf_ZtDekmYFQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 22:03:46
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 47.106.184.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 47.106.184.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:03:39.616681 2026] [security2:error] [pid 10346:tid 10346] [client 47.106.184.133:56500] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.cosplayculture.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.cosplayculture.com"] [uri "/"] [unique_id "arBYO8R6GLC9l7_T2IXMHwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 20:42:31
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 47.106.184.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 47.106.184.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 16:42:27.437876 2026] [security2:error] [pid 6881:tid 6881] [client 47.106.184.133:35258] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.xtrl.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.xtrl.com"] [uri "/"] [unique_id "arBFM2uloUxKHW9Vm9fO9wAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
HandyTreff.de
2026-09-20 19:38:48
(2 days ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -46.258 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -46.258 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Ve
show less
Web App Attack
Bad Web Bot
๐ฉ๐ช
LRob
2026-09-20 17:04:59
(2 days ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: / | 2026-09-20 17:04 UTC
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-20 17:04:40
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 47.106.184.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 47.106.184.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 13:04:34.276588 2026] [security2:error] [pid 1187:tid 1187] [client 47.106.184.133:50022] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||atassociates.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "atassociates.com"] [uri "/"] [unique_id "arASIj_LHgxg2D9_S9YdFgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 15:54:20
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 47.106.184.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 47.106.184.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:54:17.330989 2026] [security2:error] [pid 2588:tid 2588] [client 47.106.184.133:58394] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||boederinteriordesign.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "boederinteriordesign.com"] [uri "/"] [unique_id "arABqUrUkZXP8aYDs9fSiAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 15:33:58
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 47.106.184.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 47.106.184.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:33:51.345470 2026] [security2:error] [pid 27144:tid 27144] [client 47.106.184.133:58492] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||ondakompun.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "ondakompun.com"] [uri "/"] [unique_id "aq_836kR_TOrwmtIdIL5GAAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 15:18:38
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 47.106.184.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 47.106.184.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:18:30.494100 2026] [security2:error] [pid 27322:tid 27322] [client 47.106.184.133:42558] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||thegreatleapforward.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "thegreatleapforward.com"] [uri "/"] [unique_id "aq_5RnuOcThazNf-TdREEQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack