Anonymous
2026-09-21 09:34:39
(14 hours ago)
FortiWeb WAF: 53 attacks detected. Threat Score: 5400. Types: GEO IP(27), Client Management(26). Ori ...
show more
FortiWeb WAF: 53 attacks detected. Threat Score: 5400. Types: GEO IP(27), Client Management(26). Origin: China.
show less
Web App Attack
๐ฉ๐ช
Tsumugi Kotobuki
2026-09-21 05:04:12
(19 hours ago)
Port Scan on Honeypot | Ports: 80/HTTP | Proto: TCP(1) | Flags: all SYN | TTL: 47 | Len: 60B | Win: ...
show more
Port Scan on Honeypot | Ports: 80/HTTP | Proto: TCP(1) | Flags: all SYN | TTL: 47 | Len: 60B | Win: 32120(1) | F2B/ufw-honeypot@2026-09-21T05:04:12Z
show less
Port Scan
Hacking
๐บ๐ธ
slay3r9903
2026-09-21 03:31:54
(20 hours ago)
IP address blocked by Cloudflare security rules due to suspicious activity and security violations.
Hacking
Bad Web Bot
๐ฆ๐บ
MAGIC
2026-09-21 02:10:27
(22 hours ago)
VM5 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-21 01:39:48
(22 hours ago)
(mod_security) mod_security (id:210350) triggered by 47.92.51.20 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210350) triggered by 47.92.51.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 21:39:42.445974 2026] [security2:error] [pid 27555:tid 27555] [client 47.92.51.20:39140] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.jaojoco.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.jaojoco.com"] [uri "/"] [unique_id "arCK3puCIlV0AE2f7Rcr9wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 23:51:02
(1 day ago)
Web App Attack, Hacking
Hacking
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-09-20 23:21:10
(1 day ago)
Multiple/Conflicting Connection Header Data Found. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(? ...
show more
Multiple/Conflicting Connection Header Data Found. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. (920210-mnz6-1)
show less
Hacking
๐บ๐ธ
HamSammich
2026-09-20 21:06:27
(1 day ago)
Automated sensor: 2 HTTP connection/probe attempts over the last 24h (latest 2026-09-20T21:06Z).
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 17:38:45
(1 day ago)
(mod_security) mod_security (id:210350) triggered by 47.92.51.20 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210350) triggered by 47.92.51.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 13:38:42.179273 2026] [security2:error] [pid 19663:tid 19663] [client 47.92.51.20:56922] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||jamessummers.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "jamessummers.org"] [uri "/"] [unique_id "arAaIt9gZv_ET6wzK_lHHAAAAAc"], referer: http://jamessummers.org
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
PENJAGA.AUM
2026-09-20 17:33:32
(1 day ago)
47.92.51.20 - Attack: Possible XSS attack, js event handler
Web App Attack
SQL Injection
Spoofing
๐บ๐ธ
TPI-Abuse
2026-09-20 16:27:57
(1 day ago)
(mod_security) mod_security (id:210350) triggered by 47.92.51.20 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210350) triggered by 47.92.51.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 12:27:52.367740 2026] [security2:error] [pid 1876:tid 1876] [client 47.92.51.20:43060] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||ramseycountycorruption.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "ramseycountycorruption.com"] [uri "/"] [unique_id "arAJiGXcOHF3nCjuwPYSaAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
LSPCCU
2026-09-20 16:27:00
(1 day ago)
TSEC Honeypot Network report. Threat score: 70/100. Categories: Hacking. Honeypot: galah, h0neytr4p. ...
show more
TSEC Honeypot Network report. Threat score: 70/100. Categories: Hacking. Honeypot: galah, h0neytr4p. Context: 47.92.51.20 classified as botnet node participating in coordinated attack campaigns (high confidence).
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-20 15:59:08
(1 day ago)
(mod_security) mod_security (id:210350) triggered by 47.92.51.20 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210350) triggered by 47.92.51.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:59:02.409371 2026] [security2:error] [pid 24623:tid 24623] [client 47.92.51.20:50584] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||weathercarib.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "weathercarib.net"] [uri "/"] [unique_id "arACxnkqjEzr8MaEA7_IgwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:35:04
(1 day ago)
(mod_security) mod_security (id:210350) triggered by 47.92.51.20 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210350) triggered by 47.92.51.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:34:55.711508 2026] [security2:error] [pid 21039:tid 21039] [client 47.92.51.20:38370] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||generationedm.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "generationedm.com"] [uri "/"] [unique_id "aq_vD_ZxiOCYdnpmRxKHcgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:53:34
(1 day ago)
(mod_security) mod_security (id:210350) triggered by 47.92.51.20 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210350) triggered by 47.92.51.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:53:29.623249 2026] [security2:error] [pid 5121:tid 5121] [client 47.92.51.20:46662] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.proprocessor.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.proprocessor.com"] [uri "/sausage-stuffers.htm"] [unique_id "aq_lWdDg9Ao0QY9IilE2QwAAACE"], referer: http://electricsausagestuffers.com
show less
Brute-Force
Bad Web Bot
Web App Attack