๐บ๐ธ
TPI-Abuse
2026-05-31 17:41:12
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 69.16.157.191 (69-16-157-191.lin.as62651.net): ...
show more
(mod_security) mod_security (id:210730) triggered by 69.16.157.191 (69-16-157-191.lin.as62651.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 13:41:07.802050 2026] [security2:error] [pid 14697:tid 14697] [client 69.16.157.191:56588] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.leothecolorman.com|F|2"] [data ".grovewood.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.leothecolorman.com"] [uri "/tag/cat-on-carousel/www.grovewood.com"] [unique_id "ahxysxFmW_Raf6YchtKRjgAAAAQ"], referer: https://www.leothecolorman.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
INTEQ
2026-05-25 14:02:10
(2 weeks ago)
Web attack from 69.16.157.191
Web App Attack
๐ฉ๐ช
HandyTreff.de
2026-05-04 16:26:08
(1 month ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -31.319 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -31.319 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (X11; Linux x86_64; rv:136.0) Gecko/20100101 Firefox/136.0
show less
Web App Attack
Bad Web Bot
๐ณ๐ฑ
melroy89
2026-04-01 20:24:12
(2 months ago)
69.16.157.191 - - [01/Apr/2026:22:06:35 +0200] "GET /m/[email protected] /t/197109/What-do-you-think ...
show more
69.16.157.191 - - [01/Apr/2026:22:06:35 +0200] "GET /m/[email protected] /t/197109/What-do-you-think-most-dinosaurs-sounded-like/comment/1765082 HTTP/1.1" 302 282 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.5112.81 Safari/537.36" "kbin.melroy.org" 0.020
...
show less
DDoS Attack
๐บ๐ธ
quilla
2026-03-30 20:13:00
(2 months ago)
Botnet infected device observed in honeypot (Vector: TCP HANDSHAKE ATTACK)
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-03-24 16:03:58
(2 months ago)
(mod_security) mod_security (id:217210) triggered by 69.16.157.191 (69-16-157-191.lin.as62651.net): ...
show more
(mod_security) mod_security (id:217210) triggered by 69.16.157.191 (69-16-157-191.lin.as62651.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 24 12:03:46.809388 2026] [security2:error] [pid 22999:tid 22999] [client 69.16.157.191:58568] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||parastesh.org|F|4"] [data "GET ?so=tdv HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "parastesh.org"] [uri "/"] [unique_id "acK14nXSpsVCbnZ5OYA0GwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2026-03-02 02:48:56
(3 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐จ๐ญ
backslash
2026-02-23 06:21:09
(3 months ago)
block ruleset SQL-Injections with typical fingerprints FD77349DE692F8D05B4EE282DE6A5198C42AB90F
SQL Injection
๐น๐ผ
kk_it_man
2026-02-15 08:06:11
(3 months ago)
hack
Hacking
๐บ๐ธ
TPI-Abuse
2025-12-25 19:15:17
(5 months ago)
(mod_security) mod_security (id:210350) triggered by 69.16.157.191 (69-16-157-191.lin.as62651.net): ...
show more
(mod_security) mod_security (id:210350) triggered by 69.16.157.191 (69-16-157-191.lin.as62651.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 25 14:15:10.229830 2025] [security2:error] [pid 3370:tid 3370] [client 69.16.157.191:38796] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||kporterdesign.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "kporterdesign.com"] [uri "/"] [unique_id "aU2NPpix07dRqOWBTotFrgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-25 09:33:14
(6 months ago)
scanning http requests from known botnet
Web App Attack
๐ฌ๐ง
hcsystems
2025-11-22 11:05:00
(6 months ago)
Remote file inclusion attempted
Hacking
SQL Injection
Anonymous
2025-11-22 06:46:16
(6 months ago)
Sendmail abuse by spoofer or bot
Email Spam
Spoofing
๐บ๐ธ
nationaleventpros.com
2025-11-22 06:37:51
(6 months ago)
web form spam (Nilsimsa: V2SzcjEXM91GUyW7VgN5UU8rYKwVS8a3aCTjPmJCGOk)
Web Spam
๐บ๐ธ
nationaleventpros.com
2025-11-22 05:42:47
(6 months ago)
web form spam (Nilsimsa: M-AzArAHMdyFSaH51sxiSW9AYL04Qdzl3IflLWJLAs8)
Web Spam