๐บ๐ธ
brantknudson.org
2026-09-01 16:08:37
(1 minute ago)
Incorrect Host header
Web App Attack
Brute-Force
Anonymous
2026-09-01 16:02:42
(7 minutes ago)
tls scan
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-01 16:02:20
(7 minutes ago)
(mod_security) mod_security (id:210350) triggered by 84.32.32.40 (ip-84-32-32-40.009.ptr.cherryserve ...
show more
(mod_security) mod_security (id:210350) triggered by 84.32.32.40 (ip-84-32-32-40.009.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 12:02:16.807008 2026] [security2:error] [pid 12627:tid 12627] [client 84.32.32.40:41352] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||192.64.150.198:443|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "192.64.150.198"] [uri "/"] [unique_id "apb3CAyC1h9nrga9PYDi0QAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-09-01 16:02:05
(7 minutes ago)
Multiple/Conflicting Connection Header Data Found. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(? ...
show more
Multiple/Conflicting Connection Header Data Found. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. (920210-iad5-2)
show less
Hacking
๐บ๐ธ
HamSammich
2026-09-01 15:56:10
(13 minutes ago)
Automated sensor: 2 HTTPS connection/probe attempts over the last 24h (latest 2026-09-01T15:56Z).
Brute-Force
Web App Attack
๐บ๐ธ
JustMeHere
2026-09-01 15:54:00
(15 minutes ago)
[Tue Sep 01 11:53:55.086644 2026] [security2:error] [pid 823:tid 928] [client 84.32.32.40:38176] Mod ...
show more
[Tue Sep 01 11:53:55.086644 2026] [security2:error] [pid 823:tid 928] [client 84.32.32.40:38176] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 6)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "73.88.79.72"] [uri "/"] [unique_id "apb1E5flDTEphG7oalzT1wAAAEc"]
...
show less
Web App Attack
๐บ๐ธ
Kurtbaby
2026-09-01 15:50:00
(19 minutes ago)
Port Scan
Brute-Force
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 15:46:49
(23 minutes ago)
(mod_security) mod_security (id:210350) triggered by 84.32.32.40 (ip-84-32-32-40.009.ptr.cherryserve ...
show more
(mod_security) mod_security (id:210350) triggered by 84.32.32.40 (ip-84-32-32-40.009.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 11:46:45.469196 2026] [security2:error] [pid 21400:tid 21400] [client 84.32.32.40:39194] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||192.64.150.230:443|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "192.64.150.230"] [uri "/"] [unique_id "apbzZVuIgCLufEg9L737mwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ผ
taiwanfrp.me
2026-09-01 15:42:19
(27 minutes ago)
taiwanfrp NewUserConn auto-ban: reason=ip_over_target_scan_limit_60s1, conn10s=1, targets10m=1, targ ...
show more
taiwanfrp NewUserConn auto-ban: reason=ip_over_target_scan_limit_60s1, conn10s=1, targets10m=1, target=proxy:kiwicanary.MinecraftJava62osdfvgdfgrsgrg|port:-
show less
Port Scan
Hacking
๐บ๐ธ
aks4226
2026-09-01 15:39:05
(30 minutes ago)
Attacking common web applications. (n01)
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-09-01 15:38:51
(30 minutes ago)
Multiple/Conflicting Connection Header Data Found. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(? ...
show more
Multiple/Conflicting Connection Header Data Found. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. (920210-mnz6-1)
show less
Hacking
๐บ๐ธ
kosada.com
2026-09-01 15:37:13
(32 minutes ago)
Repeated requests for suspicious nonexistent URLs, for example: / (bogus vhost/SNI) (HTTP port 443)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 15:31:11
(38 minutes ago)
(mod_security) mod_security (id:210350) triggered by 84.32.32.40 (ip-84-32-32-40.009.ptr.cherryserve ...
show more
(mod_security) mod_security (id:210350) triggered by 84.32.32.40 (ip-84-32-32-40.009.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 11:31:03.435867 2026] [security2:error] [pid 16836:tid 16836] [client 84.32.32.40:58544] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||192.64.150.244:443|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "192.64.150.244"] [uri "/"] [unique_id "apbvt4YKWQWH0sFZ2GXUYQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
LiftUp Hosting
2026-09-01 15:22:55
(46 minutes ago)
Honeypot hit: Unauthorized traffic (231 bytes of payload); 7443 [1], 4443 [1] TCP
Port Scan
๐บ๐ธ
NetVexor
2026-09-01 15:22:50
(46 minutes ago)
Attack source identified and submitted via NetVexor BGP Blackhole Network
Port Scan
Hacking
Brute-Force