๐บ๐ธ
TPI-Abuse
2026-08-11 06:28:24
(1 day ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 02:28:20.168486 2026] [security2:error] [pid 2668899:tid 2668899] [client 42.201.192.53:59191] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||chrisbilder.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "chrisbilder.com"] [uri "/grouptesting/JSM_2005_poster.pdf"] [unique_id "anrBBC4rDCmMyaqtAfyJXAAAAAc"], referer: http://chrisbilder.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-10 14:35:53
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 10:35:46.709786 2026] [security2:error] [pid 1187114:tid 1187114] [client 42.201.192.53:55503] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||timetemple.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "timetemple.org"] [uri "/delivery-info"] [unique_id "annhwhTMSbaCMlhmp-loAQAAABU"], referer: https://timetemple.org/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-09 06:25:20
(3 days ago)
[09/Aug/2026:09:25:20 +0300] -- 42.201.192.53 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-c ...
show more
[09/Aug/2026:09:25:20 +0300] -- 42.201.192.53 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-content/uploads/sites/58/2016/12/29-40.pdf HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐จ๐ฆ
1gz
2026-08-08 02:56:49
(4 days ago)
Triggered Cloudflare WAF (firewallCustom) from HK.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from HK.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /kosove/abdixhiku-mbetet-ne-krye-te-ldk-se-analistet-e-cilesojne-si-te-keqen-me-te-vogel/955000
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-06 08:15:58
(6 days ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 04:15:52.251017 2026] [security2:error] [pid 510495:tid 510577] [client 42.201.192.53:37196] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||certifiedebusinessconsultant.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "certifiedebusinessconsultant.com"] [uri "/crop/controls"] [unique_id "anRCuEso4BMDKtEO16ym6AAAAlM"], referer: https://certifiedebusinessconsultant.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-03 20:58:30
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 16:58:26.424521 2026] [security2:error] [pid 1154284:tid 1154284] [client 42.201.192.53:62622] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||fgrotary.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "fgrotary.org"] [uri "/2019/page/2"] [unique_id "anEA8v6FjrnwVedkC4O6KwAAAAA"], referer: https://fgrotary.org/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-02 16:53:46
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 02 12:53:42.636669 2026] [security2:error] [pid 3769217:tid 3769217] [client 42.201.192.53:30286] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||realtorpaul.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "realtorpaul.com"] [uri "/cgi-bin"] [unique_id "am92FuC4ekTEkDswSQm0OwAAABA"], referer: https://realtorpaul.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-02 12:53:20
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 02 08:53:13.708574 2026] [security2:error] [pid 3273901:tid 3273901] [client 42.201.192.53:33982] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||billwegener.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "billwegener.net"] [uri "/"] [unique_id "am89uS7mi5QMfoGihdlvjgAAAAo"], referer: https://billwegener.net/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:02:42
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:02:36.315719 2026] [security2:error] [pid 135777:tid 135777] [client 42.201.192.53:17077] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||ohioaci.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "ohioaci.org"] [uri "/"] [unique_id "am4KjMilEG25fDkMSK_5zAAAABM"], referer: https://ohioaci.org/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
conseilgouz
2026-07-31 11:43:13
(1 week ago)
saw-Joomla User : try to access forms...
Hacking
๐จ๐ฆ
1gz
2026-07-31 01:11:44
(1 week ago)
Triggered Cloudflare WAF (firewallCustom) from HK.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from HK.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /english/the-era-of-disorder-and-oligarchy-has-come-to-an-end-gacaferi-hits-back-at-the-opposition-over-the-inspectorate/909131
UA: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:124.0) Gecko/20100101 Firefox/124.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-30 18:27:02
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 14:26:54.118719 2026] [security2:error] [pid 31165:tid 31165] [client 42.201.192.53:21935] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||celebritybikinigossip.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "celebritybikinigossip.com"] [uri "/category/celebrities/meryl-davis"] [unique_id "amuXbsuALqy6rlnlgCC15AAAAEM"], referer: https://celebritybikinigossip.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 11:38:12
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 07:38:06.570954 2026] [security2:error] [pid 3834265:tid 3834265] [client 42.201.192.53:60584] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.495metro.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.495metro.com"] [uri "/wp-admin/"] [unique_id "ams3nv1na8kC1y9ZciF0xwAAAAQ"], referer: https://495metro.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 19:37:24
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 15:37:19.555295 2026] [security2:error] [pid 2999563:tid 2999563] [client 42.201.192.53:13825] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||renjunews.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "renjunews.com"] [uri "/"] [unique_id "ampWb_EHzr8-98-q12xIkAAAAAI"], referer: https://renjunews.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
1gz
2026-07-29 17:29:20
(2 weeks ago)
Triggered Cloudflare WAF (firewallCustom) from HK.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from HK.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /maqedoni/bujqit-e-pollogut-ne-kolaps-financiar-shpenzimet-e-prodhimit-tejkalojne-cmimin-e-grurit/933845
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.6723.70 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot