๐บ๐ธ
TPI-Abuse
2026-01-05 10:16:32
(9 months ago)
(mod_security) mod_security (id:210740) triggered by 65.21.158.206 (static.206.158.21.65.clients.you ...
show more
(mod_security) mod_security (id:210740) triggered by 65.21.158.206 (static.206.158.21.65.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 05 05:16:26.433993 2026] [security2:error] [pid 27107:tid 27107] [client 65.21.158.206:35570] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||lifestylemedica.com|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "lifestylemedica.com"] [uri "/lsm/contacto/"] [unique_id "aVuPenzXafqxj7oOGCOkBwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-19 05:10:30
(9 months ago)
(mod_security) mod_security (id:210740) triggered by 65.21.158.206 (static.206.158.21.65.clients.you ...
show more
(mod_security) mod_security (id:210740) triggered by 65.21.158.206 (static.206.158.21.65.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 19 00:10:24.328431 2025] [security2:error] [pid 1874:tid 1874] [client 65.21.158.206:36952] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||shivermedia.com|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "shivermedia.com"] [uri "/learn/how-to-analyze-a-brand-strategy-step-by-step-framework-examples/"] [unique_id "aUTeQAwmPhnjBvXdC2xjtwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-28 05:46:40
(11 months ago)
(mod_security) mod_security (id:210740) triggered by 65.21.158.206 (static.206.158.21.65.clients.you ...
show more
(mod_security) mod_security (id:210740) triggered by 65.21.158.206 (static.206.158.21.65.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 28 01:46:35.731689 2025] [security2:error] [pid 4882:tid 4882] [client 65.21.158.206:33306] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||modmove.com|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "modmove.com"] [uri "/news/check-out-the-official-trailer-for-reminders-of-him/"] [unique_id "aQBYu2Sons6_l1HT5PttfgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-07 05:09:31
(11 months ago)
(mod_security) mod_security (id:210740) triggered by 65.21.158.206 (static.206.158.21.65.clients.you ...
show more
(mod_security) mod_security (id:210740) triggered by 65.21.158.206 (static.206.158.21.65.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 07 01:09:23.866216 2025] [security2:error] [pid 21382:tid 21382] [client 65.21.158.206:57990] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||www.aares2026.net|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "www.aares2026.net"] [uri "/keynote-speaker.html"] [unique_id "aOSgg0JD9btp2ZPzPbcw7QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
jjnxpct
2025-09-28 03:45:05
(1 year ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /component/gripdagopening/ (Rule ID: 210740) - COMODO WAF: HTTP header is restricted by policy||www.grip-dagopening.nl|F|4
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-20 10:53:42
(1 year ago)
(mod_security) mod_security (id:210740) triggered by 65.21.158.206 (static.206.158.21.65.clients.you ...
show more
(mod_security) mod_security (id:210740) triggered by 65.21.158.206 (static.206.158.21.65.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 20 06:53:37.650649 2025] [security2:error] [pid 19890:tid 19890] [client 65.21.158.206:49064] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||www.ofertasdetrabajosyempleos.com.creartest.com|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ofertasdetrabajosyempleos.com.creartest.com"] [uri "/nicaragua/buscador-gerente_tienda_maxi_pali_rivas_walmart_mexico_centroamerica-.php"] [unique_id "aM6Hsddwe4y5a3gyf2I8-AAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-03 02:52:13
(1 year ago)
(mod_security) mod_security (id:210740) triggered by 65.21.158.206 (static.206.158.21.65.clients.you ...
show more
(mod_security) mod_security (id:210740) triggered by 65.21.158.206 (static.206.158.21.65.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 02 22:52:09.292132 2025] [security2:error] [pid 30769:tid 30782] [client 65.21.158.206:36852] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||globalacademyoffinanceandmanagement.com|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "globalacademyoffinanceandmanagement.com"] [uri "/board.html"] [unique_id "aLetWZGwGqQw81WNc_moIAAAAMo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
Global Cyber Police
2025-08-20 06:52:26
(1 year ago)
Part of botnet that all have no referrer and always use the exact spoofed agent: Mozilla/5.0 (compat ...
show more
Part of botnet that all have no referrer and always use the exact spoofed agent: Mozilla/5.0 (compatible; crawler)
show less
Hacking
SQL Injection
Spoofing
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-09 01:53:44
(1 year ago)
(mod_security) mod_security (id:210740) triggered by 65.21.158.206 (static.206.158.21.65.clients.you ...
show more
(mod_security) mod_security (id:210740) triggered by 65.21.158.206 (static.206.158.21.65.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 08 21:53:37.642621 2025] [security2:error] [pid 14967:tid 14967] [client 65.21.158.206:36902] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||www.renju.net|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "www.renju.net"] [uri "/tournament/3447/"] [unique_id "aJaqIQbdNevDC9DoS61gTAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-22 08:26:28
(1 year ago)
(mod_security) mod_security (id:210740) triggered by 65.21.158.206 (static.206.158.21.65.clients.you ...
show more
(mod_security) mod_security (id:210740) triggered by 65.21.158.206 (static.206.158.21.65.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 22 04:26:24.013300 2025] [security2:error] [pid 20009:tid 20079] [client 65.21.158.206:47036] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||www.fishrapper.com|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "www.fishrapper.com"] [uri "/Fishing-report-minnesota-july-2025.html"] [unique_id "aH9LMOHqwe0YFWXKosXs3QAAAQo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-07-18 16:30:22
(1 year ago)
Failed login attempt detected by Fail2Ban in recidive jail
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-06-09 23:55:12
(1 year ago)
(mod_security) mod_security (id:210740) triggered by 65.21.158.206 (static.206.158.21.65.clients.you ...
show more
(mod_security) mod_security (id:210740) triggered by 65.21.158.206 (static.206.158.21.65.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 09 19:55:06.893947 2025] [security2:error] [pid 1208787:tid 1208787] [client 65.21.158.206:48794] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||www.player-care.com|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "www.player-care.com"] [uri "/"] [unique_id "aEd0WuSoRyBJc3tH6zQHvgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-11 22:29:46
(1 year ago)
(mod_security) mod_security (id:210740) triggered by 65.21.158.206 (static.206.158.21.65.clients.you ...
show more
(mod_security) mod_security (id:210740) triggered by 65.21.158.206 (static.206.158.21.65.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 11 18:29:39.988753 2025] [security2:error] [pid 103749:tid 103749] [client 65.21.158.206:47336] [client 65.21.158.206] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||sub-sea9.com|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "sub-sea9.com"] [uri "/index.php/our-business/retail-marketing"] [unique_id "aCEk0zSxUQz8lqtALe0UOQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-28 12:29:44
(1 year ago)
(mod_security) mod_security (id:210740) triggered by 65.21.158.206 (static.206.158.21.65.clients.you ...
show more
(mod_security) mod_security (id:210740) triggered by 65.21.158.206 (static.206.158.21.65.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 28 08:29:41.257238 2025] [security2:error] [pid 16062:tid 16062] [client 65.21.158.206:42542] [client 65.21.158.206] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||cressyvideo.com|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "cressyvideo.com"] [uri "/clients.htm"] [unique_id "aA90tSN2Yql3eNYHsXcUBgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-18 22:47:15
(1 year ago)
(mod_security) mod_security (id:210740) triggered by 65.21.158.206 (static.206.158.21.65.clients.you ...
show more
(mod_security) mod_security (id:210740) triggered by 65.21.158.206 (static.206.158.21.65.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 18 18:47:06.781736 2025] [security2:error] [pid 21855:tid 21855] [client 65.21.158.206:59146] [client 65.21.158.206] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||www.ofertasdetrabajosyempleos.com|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ofertasdetrabajosyempleos.com"] [uri "/costa_rica/buscador-ejecutivo_ventas_guanacaste_liberia_kleeglobal-.php"] [unique_id "aALWamHmvoln1GEVyCFBiwAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack