๐บ๐ธ
ipblock.com
2026-05-28 15:40:00
(1 month ago)
IPBlock protected site ID [4055-d][s=02].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐ท๐ธ
gabus
2026-03-02 11:00:00
(4 months ago)
Carding / fraud orders against WHMCS checkout.
Email Spam
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-03 00:20:15
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 89.19.33.12 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210350) triggered by 89.19.33.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 19:20:08.849440 2025] [security2:error] [pid 22108:tid 22108] [client 89.19.33.12:59091] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.cayman-islands-real-estate.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.cayman-islands-real-estate.com"] [uri "/property/watercolours-beachfront-residence"] [unique_id "aS-COOVIp_2I85jN5KNXfgAAABY"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-31 09:32:27
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 89.19.33.12 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210350) triggered by 89.19.33.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 31 05:32:05.501847 2025] [security2:error] [pid 15612:tid 15612] [client 89.19.33.12:28889] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.studiopilates.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.studiopilates.net"] [uri "/about/"] [unique_id "aQSCFVQUsQke9PJoFtIcrwAAABM"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-07-02 03:36:06
(1 year ago)
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-03-10 10:47:15
(1 year ago)
(mod_security) mod_security (id:210350) triggered by 89.19.33.12 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210350) triggered by 89.19.33.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 10 06:47:11.852963 2025] [security2:error] [pid 11831:tid 11831] [client 89.19.33.12:51537] [client 89.19.33.12] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.fuentevictoria.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.fuentevictoria.com"] [uri "/inmuebles/index.php"] [unique_id "Z87DL3JdryYdm_Da91bxGQAAAAw"], referer: http://www.fuentevictoria.com/inmuebles/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-07 12:23:01
(1 year ago)
(mod_security) mod_security (id:210350) triggered by 89.19.33.12 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210350) triggered by 89.19.33.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 07 07:22:55.898438 2025] [security2:error] [pid 3359:tid 3359] [client 89.19.33.12:31043] [client 89.19.33.12] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||kemela.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "kemela.com"] [uri "/store/Wilson-Benesch-Torus.html"] [unique_id "Z8rlH3YeK-AHjDPGzFRtOwAAAAg"], referer: https://kemela.com/store/Wilson-Benesch-Torus.html
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
botreporter
2025-03-05 12:52:54
(1 year ago)
bot wiki account creation attempts
Web Spam
Bad Web Bot
๐ฉ๐ช
botreporter
2025-02-28 14:21:13
(1 year ago)
bot wiki account creation attempts
Web Spam
Bad Web Bot
๐บ๐ธ
oncord
2025-02-23 04:38:25
(1 year ago)
Form spam
Web Spam
๐ช๐ธ
el-brujo
2025-02-21 01:57:11
(1 year ago)
Cloudflare WAF: Request Path: /xmlrpc.php Request Query: ?rsd Host: hwagm.elhacker.net userAgent: Mo ...
show more
Cloudflare WAF: Request Path: /xmlrpc.php Request Query: ?rsd Host: hwagm.elhacker.net userAgent: Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36 Action: managed_challenge Source: firewallManaged ASN Description: WSTELECOM_CUSTOMERS Country: DE Method: GET Timestamp: 2025-02-21T01:57:11Z ruleId: 5de7edfa648c4d6891dc3e7f84534ffa. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐ฉ๐ช
botreporter
2025-02-20 19:19:16
(1 year ago)
bot wiki account creation attempts
Web Spam
Bad Web Bot
๐ฉ๐ช
dot.mg
2025-02-20 18:02:37
(1 year ago)
porn spam
Web Spam
Blog Spam
๐ฉ๐ช
london2038.com
2025-02-19 11:16:47
(1 year ago)
Detected by WP fail2ban
2025-02-19T12:16:46.335665+01:00 wordpress: Authentication attempt from 89.1 ...
show more
Detected by WP fail2ban
2025-02-19T12:16:46.335665+01:00 wordpress: Authentication attempt from 89.19.33.12
show less
Brute-Force
Web App Attack
Anonymous
2025-02-19 03:41:04
(1 year ago)
wordpress-trap
Web App Attack