๐บ๐ธ
TPI-Abuse
2026-08-06 15:18:51
(1 week ago)
(mod_security) mod_security (id:210740) triggered by 138.252.26.4 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210740) triggered by 138.252.26.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 11:18:45.516460 2026] [security2:error] [pid 2453359:tid 2453359] [client 138.252.26.4:48064] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||esquema-arch.com|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "esquema-arch.com"] [uri "/about-us"] [unique_id "anSl1U8Ce-HYdxB8xQrAsQAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-08-05 14:07:38
(2 weeks ago)
Bogus Useragent: 138.252.26.4 - - [05/Aug/2026:16:07:37 +0200] "GET /protocol?id=bw_17_85¶graph= ...
show more
Bogus Useragent: 138.252.26.4 - - [05/Aug/2026:16:07:37 +0200] "GET /protocol?id=bw_17_85¶graph=2899584&seq=477 HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; MSIE 5.0; Windows NT 4.0; Trident/3.0)" asn=154287 org="R-Connect" country=PH
...
show less
Bad Web Bot
๐บ๐ธ
kosada.com
2026-08-01 04:27:45
(2 weeks ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
Anonymous
2026-07-29 18:00:12
(2 weeks ago)
Large-scale coordinated botnet (1M+ IPs). Ordered by Alexander Pen'kov (alexander-pen-kov-7b41aa6a/S ...
show more
Large-scale coordinated botnet (1M+ IPs). Ordered by Alexander Pen'kov (alexander-pen-kov-7b41aa6a/Shursky); Attacker: Mikhail Smirnov (mikhail-smirnov-79830323/Aidan) employed by Angara Technologies Group | Attack Signature Blocked: /wishlist/index/add/product/11823/form_key/lttElgzJHvyuc50C/ | UA: Mozilla/5.0 (Macintosh; U; PPC Mac OS X 10_8_8 rv:3.0; mi-NZ) AppleWebKit/533.15.5 (KHTML, like Gecko) Version/5.1 Safari/533.15.5 | (Magento Site)
show less
Hacking
Bad Web Bot
Web App Attack
๐ซ๐ท
security.rdmc.fr
2026-01-12 07:11:42
(7 months ago)
IP in Malicious Database
Web App Attack
Anonymous
2026-01-11 17:00:17
(7 months ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
๐จ๐ณ
ThreatBook.io
2026-01-10 01:46:03
(7 months ago)
ThreatBook Intelligence: Zombie,Dynamic IP more details on https://threatbook.io/ip/138.252.26.4
SSH
๐จ๐ณ
ThreatBook.io
2026-01-09 01:20:44
(7 months ago)
ThreatBook Intelligence: Zombie,Dynamic IP more details on https://threatbook.io/ip/138.252.26.4
SSH
๐บ๐ธ
TPI-Abuse
2025-12-26 06:12:29
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 138.252.26.4 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 138.252.26.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 26 01:12:14.478767 2025] [security2:error] [pid 11431:tid 11431] [client 138.252.26.4:60210] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||cmcnow.cmcnow.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "cmcnow.cmcnow.net"] [uri "/"] [unique_id "aU4nPrjFf7NpEy6V90TMSQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack