🇺🇸
TPI-Abuse
2026-09-10 12:58:49
(14 hours ago)
(mod_security) mod_security (id:217210) triggered by 5.42.127.131 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:217210) triggered by 5.42.127.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 08:58:42.244439 2026] [security2:error] [pid 29018:tid 29018] [client 5.42.127.131:53414] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||lauracooper.co:443|F|4"] [data "CONNECT lauracooper.co:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "lauracooper.co"] [uri "/"] [unique_id "aqKpghWIe5KfqP4rj2KC7gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 11:12:33
(2 days ago)
(mod_security) mod_security (id:217210) triggered by 5.42.127.131 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:217210) triggered by 5.42.127.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:12:28.292951 2026] [security2:error] [pid 7281:tid 7281] [client 5.42.127.131:45532] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||decypher.design:443|F|4"] [data "CONNECT decypher.design:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "decypher.design"] [uri "/"] [unique_id "ap_tnJHvmxmbfSfb-k6__AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Skyrider
2026-09-08 04:39:46
(2 days ago)
crowdsecurity/http-open-proxy
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 03:16:51
(3 days ago)
(mod_security) mod_security (id:217210) triggered by 5.42.127.131 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:217210) triggered by 5.42.127.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:16:44.349870 2026] [security2:error] [pid 15489:tid 15489] [client 5.42.127.131:41000] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||www.limobusrichmond.com:443|F|4"] [data "CONNECT www.limobusrichmond.com:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.limobusrichmond.com"] [uri "/"] [unique_id "ap9-HI41Vgqc2kJ_tqxg0wAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-08 01:35:03
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 15:44:29
(3 days ago)
(mod_security) mod_security (id:217210) triggered by 5.42.127.131 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:217210) triggered by 5.42.127.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 11:44:23.331998 2026] [security2:error] [pid 28382:tid 28382] [client 5.42.127.131:45980] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||www.oldmaninthepeanut.com:443|F|4"] [data "CONNECT www.oldmaninthepeanut.com:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.oldmaninthepeanut.com"] [uri "/"] [unique_id "ap7b163GpNCgOHethCY13AAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
r4fo.com
2026-09-06 18:27:15
(4 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-open-proxy
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 15:00:34
(4 days ago)
(mod_security) mod_security (id:217210) triggered by 5.42.127.131 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:217210) triggered by 5.42.127.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 11:00:28.154339 2026] [security2:error] [pid 27539:tid 27568] [client 5.42.127.131:57784] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||www.tapdd.com:443|F|4"] [data "CONNECT www.tapdd.com:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.tapdd.com"] [uri "/"] [unique_id "ap2ADF-vYQLI_Fbx-6mzFAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack