๐บ๐ธ
xmission.com
2026-09-03 09:54:26
(10 hours ago)
206.245.131.160 - - [02/Sep/2026:23:46:58 -0600] "CONNECT dooce.com:443 HTTP/1.1" 400 150 "-" "-"
20 ...
show more
206.245.131.160 - - [02/Sep/2026:23:46:58 -0600] "CONNECT dooce.com:443 HTTP/1.1" 400 150 "-" "-"
206.245.131.160 - - [03/Sep/2026:00:27:33 -0600] "CONNECT dooce.com:443 HTTP/1.1" 400 150 "-" "-"
206.245.131.160 - - [03/Sep/2026:01:28:17 -0600] "CONNECT dooce.com:443 HTTP/1.1" 400 150 "-" "-"
206.245.131.160 - - [03/Sep/2026:03:48:25 -0600] "CONNECT dooce.com:443 HTTP/1.1" 400 150 "-" "-"
206.245.131.160 - - [03/Sep/2026:03:54:25 -0600] "CONNECT dooce.com:443 HTTP/1.1" 400 150 "-" "-"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 06:23:07
(14 hours ago)
(mod_security) mod_security (id:217210) triggered by 206.245.131.160 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:217210) triggered by 206.245.131.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 02:23:01.285172 2026] [security2:error] [pid 13345:tid 13345] [client 206.245.131.160:37332] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||bennecelli.com:443|F|4"] [data "CONNECT bennecelli.com:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "bennecelli.com"] [uri "/"] [unique_id "apkSRUjs2zwJa0iqibPVFQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 04:26:39
(16 hours ago)
(mod_security) mod_security (id:217210) triggered by 206.245.131.160 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:217210) triggered by 206.245.131.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 00:26:31.817117 2026] [security2:error] [pid 8423:tid 8423] [client 206.245.131.160:41200] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||web.cruisingforsex.com:443|F|4"] [data "CONNECT web.cruisingforsex.com:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "web.cruisingforsex.com"] [uri "/"] [unique_id "apj299Nrh-OE073vFD7YZwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 12:17:35
(1 day ago)
(mod_security) mod_security (id:217210) triggered by 206.245.131.160 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:217210) triggered by 206.245.131.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 08:17:29.547450 2026] [security2:error] [pid 2604:tid 2604] [client 206.245.131.160:50718] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||salernospizza.com:443|F|4"] [data "CONNECT salernospizza.com:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "salernospizza.com"] [uri "/"] [unique_id "apgT2T7kLEMX0G1q6VeGcwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
aranguren.org
2026-09-01 11:22:33
(2 days ago)
[Tue Sep 01 21:22:22.528260 2026] [authz_core:error] [pid 2371410:tid 2371469] [client 206.245.131.1 ...
show more
[Tue Sep 01 21:22:22.528260 2026] [authz_core:error] [pid 2371410:tid 2371469] [client 206.245.131.160:49742] AH01630: client denied by server configuration: /srv/http/
[Tue Sep 01 21:22:27.754380 2026] [authz_core:error] [pid 2371410:tid 2371450] [client 206.245.131.160:49744] AH01630: client denied by server configuration: /srv/http/
[Tue Sep 01 21:22:32.954434 2026] [authz_core:error] [pid 2371410:tid 2371443] [client 206.245.131.160:49830] AH01630: client denied by server configuration: /srv/http/
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
antlac1
2026-08-31 09:09:51
(3 days ago)
crowdsecurity/http-open-proxy
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 00:22:06
(3 days ago)
(mod_security) mod_security (id:217210) triggered by 206.245.131.160 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:217210) triggered by 206.245.131.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 20:21:57.863643 2026] [security2:error] [pid 8954:tid 8954] [client 206.245.131.160:37788] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||www.kitebeach.com:443|F|4"] [data "CONNECT www.kitebeach.com:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.kitebeach.com"] [uri "/"] [unique_id "apTJJWxMZlUxD4wfQ4_ZHgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 18:42:42
(5 days ago)
(mod_security) mod_security (id:217210) triggered by 206.245.131.160 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:217210) triggered by 206.245.131.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 14:42:34.136401 2026] [security2:error] [pid 32171:tid 32246] [client 206.245.131.160:57760] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||www.myrtlebeachdiet.com:443|F|4"] [data "CONNECT www.myrtlebeachdiet.com:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.myrtlebeachdiet.com"] [uri "/"] [unique_id "apMoGoxx2nDuXBTwmDCPKwAAAM0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 15:13:37
(1 week ago)
(mod_security) mod_security (id:217210) triggered by 206.245.131.160 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:217210) triggered by 206.245.131.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 11:13:30.737389 2026] [security2:error] [pid 17005:tid 17005] [client 206.245.131.160:59286] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||vitalitywebb.com:443|F|4"] [data "CONNECT vitalitywebb.com:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "vitalitywebb.com"] [uri "/"] [unique_id "apBUGhgwxv5838bivQSiMwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 23:54:33
(1 week ago)
(mod_security) mod_security (id:217210) triggered by 206.245.131.160 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:217210) triggered by 206.245.131.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 19:54:28.024289 2026] [security2:error] [pid 15899:tid 15899] [client 206.245.131.160:49918] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||www.graymatterofdc.com:443|F|4"] [data "CONNECT www.graymatterofdc.com:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.graymatterofdc.com"] [uri "/"] [unique_id "ao98tI6XuEI77PDl6BwnyAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-24 17:55:29
(1 week ago)
Web App Attack
๐บ๐ธ
EvilTurkey
2026-08-24 13:30:20
(1 week ago)
Web app attack against financial institution website.
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-21 00:25:18
(1 week ago)
(mod_security) mod_security (id:210740) triggered by 206.245.131.160 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210740) triggered by 206.245.131.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 20:25:11.616549 2026] [security2:error] [pid 26494:tid 26494] [client 206.245.131.160:59186] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||wmodradio.com:443|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "wmodradio.com"] [uri "/"] [unique_id "aoea5xcoFhE0jzlPcGWRnwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-08-15 13:55:54
(2 weeks ago)
206.245.131.160 - - [15/Aug/2026:06:29:53 -0600] "CONNECT dooce.com:443 HTTP/1.1" 400 150 "-" "-"
20 ...
show more
206.245.131.160 - - [15/Aug/2026:06:29:53 -0600] "CONNECT dooce.com:443 HTTP/1.1" 400 150 "-" "-"
206.245.131.160 - - [15/Aug/2026:06:57:55 -0600] "CONNECT dooce.com:443 HTTP/1.1" 400 150 "-" "-"
206.245.131.160 - - [15/Aug/2026:07:18:34 -0600] "CONNECT dooce.com:443 HTTP/1.1" 400 150 "-" "-"
206.245.131.160 - - [15/Aug/2026:07:53:01 -0600] "CONNECT dooce.com:443 HTTP/1.1" 400 150 "-" "-"
206.245.131.160 - - [15/Aug/2026:07:55:53 -0600] "CONNECT dooce.com:443 HTTP/1.1" 400 150 "-" "-"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-14 11:58:20
(2 weeks ago)
(mod_security) mod_security (id:217210) triggered by 206.245.131.160 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:217210) triggered by 206.245.131.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 07:58:11.820986 2026] [security2:error] [pid 10679:tid 10679] [client 206.245.131.160:42024] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||socialstudiesforkids.com:443|F|4"] [data "CONNECT socialstudiesforkids.com:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "socialstudiesforkids.com"] [uri "/"] [unique_id "an8C08_Tgz6mUY0MaxMSwQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack