🇺🇸
TPI-Abuse
2026-09-05 23:47:40
(4 days ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:47:32.505962 2026] [security2:error] [pid 20454:tid 20454] [client 42.201.192.6:55781] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.creartest.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.creartest.com"] [uri "/403.shtml"] [unique_id "apyqFBBC0k9m-B8f2-1z_QAAABY"], referer: https://creartest.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 12:22:54
(4 days ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 08:22:49.060412 2026] [security2:error] [pid 26959:tid 26959] [client 42.201.192.6:35264] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||nwtree.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "nwtree.com"] [uri "/blog/best-fruit-trees-to-plant-portland"] [unique_id "apwJmW0ZPVo-k1kpPyyDmQAAABA"], referer: https://nwtree.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-31 20:15:34
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 16:15:25.688985 2026] [security2:error] [pid 30023:tid 30023] [client 42.201.192.6:35705] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||virginiatouchatruck.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "virginiatouchatruck.com"] [uri "/touch-a-truck.html"] [unique_id "apXg3Wlm4Xa1_Eq-6-Vx8wAAAAs"], referer: https://virginiatouchatruck.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-30 14:03:34
(1 week ago)
Web attack
Bad Web Bot
Web App Attack
🇫🇷
bigorre.org
2026-08-29 16:51:06
(1 week ago)
unidentified crawl, no bot reference in user agent
Bad Web Bot
🇺🇸
TPI-Abuse
2026-08-29 03:53:36
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:53:31.302479 2026] [security2:error] [pid 11586:tid 11586] [client 42.201.192.6:50876] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||pghsea.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "pghsea.com"] [uri "/images"] [unique_id "apJXu1dU3pGkPcbsybnR4QAAAAE"], referer: https://pghsea.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 16:10:12
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 12:10:06.886792 2026] [security2:error] [pid 13111:tid 13111] [client 42.201.192.6:33978] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||jimgrenier.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "jimgrenier.com"] [uri "/"] [unique_id "apGy3iix7Vyi5G3AfJ_e3gAAAAM"], referer: https://stellwagenmusic.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 15:28:43
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 11:28:36.250924 2026] [security2:error] [pid 19992:tid 19992] [client 42.201.192.6:13845] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||rame-int.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "rame-int.com"] [uri "/iso90012015"] [unique_id "apGpJL7TBSdisPfa1jTRywAAAAo"], referer: https://rame-int.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 09:02:34
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 05:02:28.097719 2026] [security2:error] [pid 29090:tid 29090] [client 42.201.192.6:10051] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||barbaraehill.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "barbaraehill.com"] [uri "/"] [unique_id "apFOpOBw3vhunOHgYO-3UgAAAAA"], referer: https://kacsffs.blogspot.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 09:21:45
(1 week ago)
42.201.192.6 - sliver85.eu - [27/Aug/2026:11:21:37 +0200] "GET / HTTP/2.0" 444 "Mozilla/5.0 (Macinto ...
show more
42.201.192.6 - sliver85.eu - [27/Aug/2026:11:21:37 +0200] "GET / HTTP/2.0" 444 "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 Edg/120.0.0.0"
42.201.192.6 - sliver85.eu - [27/Aug/2026:11:21:40 +0200] "GET / HTTP/2.0" 444 "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 Edg/120.0.0.0"
42.201.192.6 - sliver85.eu - [27/Aug/2026:11:21:45 +0200] "GET / HTTP/2.0" 444 "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 Edg/120.0.0.0"
...
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 03:21:41
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 23:21:36.948364 2026] [security2:error] [pid 1411:tid 1411] [client 42.201.192.6:48833] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||kennythompson.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "kennythompson.com"] [uri "/photos.htm"] [unique_id "ao-tQBwvsPbiJQd9q_qkfgAAAAs"], referer: https://kennythompson.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Jochen Pretli
2026-08-27 00:41:58
(2 weeks ago)
connection to honeypot
Email Spam
Port Scan
🇺🇸
TPI-Abuse
2026-08-26 18:36:57
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 14:36:49.686614 2026] [security2:error] [pid 19806:tid 19806] [client 42.201.192.6:22038] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||zenmonkeyproject.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "zenmonkeyproject.com"] [uri "/"] [unique_id "ao8yQYNUL8P0VJHtiqXTwQAAABc"], referer: https://movementartisans.net/kira-kirsch
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
soverin
2026-08-26 15:38:28
(2 weeks ago)
Network scan on port 443
Email Spam
🇺🇸
TPI-Abuse
2026-08-26 13:04:30
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 09:04:26.123636 2026] [security2:error] [pid 84423:tid 84434] [client 42.201.192.6:62160] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||wpe.uk.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "wpe.uk.com"] [uri "/index.php"] [unique_id "ao7kWoia_pCg3DDvs79pMAAAAAk"], referer: https://wpe.uk.com/clients.php
show less
Brute-Force
Bad Web Bot
Web App Attack