🇺🇸
TPI-Abuse
2026-09-11 03:52:19
(1 day ago)
(mod_security) mod_security (id:217210) triggered by 91.103.120.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:217210) triggered by 91.103.120.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 23:52:11.017037 2026] [security2:error] [pid 15548:tid 15548] [client 91.103.120.59:5173] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||antech.net:443|F|4"] [data "CONNECT antech.net:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "antech.net"] [uri "/"] [unique_id "aqN66_WsScGas9FyT9mCEQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 21:19:32
(1 day ago)
(mod_security) mod_security (id:217210) triggered by 91.103.120.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:217210) triggered by 91.103.120.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 17:19:23.734630 2026] [security2:error] [pid 27283:tid 27283] [client 91.103.120.59:52447] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||www.graymatterofdc.com:443|F|4"] [data "CONNECT www.graymatterofdc.com:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.graymatterofdc.com"] [uri "/"] [unique_id "aqMe2yIZS1RwhavOYJrGlQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 16:16:54
(1 day ago)
(mod_security) mod_security (id:217210) triggered by 91.103.120.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:217210) triggered by 91.103.120.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 12:16:46.647974 2026] [security2:error] [pid 7895:tid 7895] [client 91.103.120.59:63395] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||www.boblog111.com:443|F|4"] [data "CONNECT www.boblog111.com:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.boblog111.com"] [uri "/"] [unique_id "aqLX7ns-jzapvBMS2TnSbQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
aranguren.org
2026-09-10 11:52:42
(1 day ago)
[Thu Sep 10 21:28:42.217166 2026] [authz_core:error] [pid 3202671:tid 3202715] [client 91.103.120.59 ...
show more
[Thu Sep 10 21:28:42.217166 2026] [authz_core:error] [pid 3202671:tid 3202715] [client 91.103.120.59:31283] AH01630: client denied by server configuration: /srv/http/
[Thu Sep 10 21:52:05.021903 2026] [authz_core:error] [pid 3202671:tid 3202732] [client 91.103.120.59:59343] AH01630: client denied by server configuration: /srv/http/
[Thu Sep 10 21:52:42.060723 2026] [authz_core:error] [pid 3202671:tid 3202723] [client 91.103.120.59:7507] AH01630: client denied by server configuration: /srv/http/
...
show less
Brute-Force
Web App Attack
🇫🇷
LRob
2026-09-10 01:38:02
(2 days ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: http://webmonit.net/ | ua: Mozilla/5.0 (Fedora; Linux x86_64; rv:122.0) Gecko/20100101 Firefox/122.0 | 2026-09-10 01:38 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 10:23:55
(3 days ago)
(mod_security) mod_security (id:210740) triggered by 91.103.120.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210740) triggered by 91.103.120.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:23:48.037055 2026] [security2:error] [pid 17791:tid 17791] [client 91.103.120.59:14815] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||camasmarket.com:443|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "camasmarket.com"] [uri "/"] [unique_id "ap_iNMdVEO4-SFv1iuSwpwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 17:22:39
(1 week ago)
IP matched detection query saxova.cz.
Brute-Force
Anonymous
2026-09-03 16:34:04
(1 week ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇳🇱
exxos
2025-07-27 22:20:37
(1 year ago)
http-no-verb
Hacking
🇳🇱
exxos
2025-07-27 22:18:18
(1 year ago)
http-no-verb
Hacking
🇳🇱
exxos
2025-07-27 22:13:22
(1 year ago)
http-no-verb
Hacking
🇺🇸
TPI-Abuse
2025-06-21 02:07:00
(1 year ago)
(mod_security) mod_security (id:217210) triggered by 91.103.120.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:217210) triggered by 91.103.120.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 20 22:06:55.894161 2025] [security2:error] [pid 3043282:tid 3043282] [client 91.103.120.59:35949] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||james.ahlstrom.name:443|F|4"] [data "CONNECT james.ahlstrom.name:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "james.ahlstrom.name"] [uri "/"] [unique_id "aFYTvxzvGswuW2SPA3mFlwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
paissangroup
2025-06-20 08:59:31
(1 year ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2025-06-18 18:01:00
(1 year ago)
(mod_security) mod_security (id:217210) triggered by 91.103.120.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:217210) triggered by 91.103.120.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 18 14:00:52.379107 2025] [security2:error] [pid 1851735:tid 1851735] [client 91.103.120.59:14003] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||www.onlinesoldier.com:443|F|4"] [data "CONNECT www.onlinesoldier.com:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.onlinesoldier.com"] [uri "/"] [unique_id "aFL-1A217-NhZW_634S-OQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇩
ipkindonesia-csirt
2025-06-16 02:10:42
(1 year ago)
Brute-force PHP Unit Eval
Brute-Force
Web App Attack