πΊπΈ
TPI-Abuse
2026-08-12 08:40:22
(16 hours ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 04:40:17.137851 2026] [security2:error] [pid 291362:tid 291362] [client 42.201.192.7:35670] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||nhgrange.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "nhgrange.org"] [uri "/Documents/Wingold_supper_2019.pdf"] [unique_id "anwxcYB9aTmeSTOE3r91AwAAABM"], referer: http://nhgrange.org/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-10 10:41:02
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 06:40:57.237526 2026] [security2:error] [pid 1754406:tid 1754406] [client 42.201.192.7:60523] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||kadinisi.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "kadinisi.org"] [uri "/"] [unique_id "anmquaWgqIpwPEaIk6oP6AAAAAg"], referer: https://kadinisi.org/
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π¦
1gz
2026-08-09 00:27:08
(4 days ago)
Triggered Cloudflare WAF (firewallCustom) from HK.
Action taken: BLOCK
Protocol: HTTP/2 (GET method) ...
show more
Triggered Cloudflare WAF (firewallCustom) from HK.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /english/former-investigator-agim-rexhepi-warns-over-the-rise-in-killings-in-kosovo-a-coordinated-crackdown-on-the-illegal-weapons-market-is-needed/910274
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π¨π¦
1gz
2026-08-07 00:11:01
(6 days ago)
Triggered Cloudflare WAF (firewallCustom) from HK.
Action taken: BLOCK
Protocol: HTTP/2 (GET method) ...
show more
Triggered Cloudflare WAF (firewallCustom) from HK.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /sport/vozinha-shkruan-historine-ne-kili-rregullorja-ndryshohet-posacerisht-per-te/960830
UA: Mozilla/5.0 (iPhone; CPU iPhone OS 17_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Mobile/15E148 Safari/604.1
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-08-06 09:09:00
(6 days ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 05:08:54.112285 2026] [security2:error] [pid 2440989:tid 2440989] [client 42.201.192.7:40403] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||agingworkforcenews.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "agingworkforcenews.com"] [uri "/2006/01/manpower-inc-ceo-on-future-of-global.html"] [unique_id "anRPJgJkCaxIYeEcr5liZwAAAAs"], referer: https://agingworkforcenews.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-04 08:26:11
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 04 04:26:04.203983 2026] [security2:error] [pid 3932826:tid 3932826] [client 42.201.192.7:60617] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||gracebaptisthartsville.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "gracebaptisthartsville.com"] [uri "/sermons"] [unique_id "anGiHNd85m1YfM3RWcnRMgAAAAY"], referer: https://gracebaptisthartsville.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π¦
1gz
2026-08-03 00:16:20
(1 week ago)
Triggered Cloudflare WAF (firewallCustom) from HK.
Action taken: BLOCK
Protocol: HTTP/2 (GET method) ...
show more
Triggered Cloudflare WAF (firewallCustom) from HK.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /sport/sturm-graz-futet-ne-gare-per-nelson-weiper-sulmuesi-i-kerkuar-edhe-nga-shqiperia-mund-te-lere-mainz/921607
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.6099.216 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-08-02 17:51:29
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 02 13:51:20.572029 2026] [security2:error] [pid 1581361:tid 1581361] [client 42.201.192.7:18515] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||mosheimlib.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "mosheimlib.org"] [uri "/about"] [unique_id "am-DmIOVjNouWYt_Ste85AAAAAk"], referer: https://mosheimlib.org/
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
conseilgouz
2026-08-02 05:29:31
(1 week ago)
vew-Joomla User : try to access forms...
Hacking
πΊπΈ
TPI-Abuse
2026-08-01 20:39:44
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 16:39:39.837843 2026] [security2:error] [pid 2865366:tid 2865366] [client 42.201.192.7:30458] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||aimer.es|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "aimer.es"] [uri "/"] [unique_id "am5Zi82XgSY72ei6_8r8CQAAACE"], referer: https://aimer.es/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-31 19:32:59
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 15:32:52.406624 2026] [security2:error] [pid 26286:tid 26286] [client 42.201.192.7:33825] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||akronpartybuses.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "akronpartybuses.com"] [uri "/"] [unique_id "amz4ZItwl8FdPwq_-DGI9AAAAAc"], referer: https://akronpartybuses.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π¦
1gz
2026-07-31 04:55:34
(1 week ago)
Triggered Cloudflare WAF (firewallCustom) from HK.
Action taken: BLOCK
Protocol: HTTP/2 (GET method) ...
show more
Triggered Cloudflare WAF (firewallCustom) from HK.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /lajme/selin
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-07-30 23:07:58
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 19:07:55.173090 2026] [security2:error] [pid 1998124:tid 1998124] [client 42.201.192.7:47338] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||fusionrep.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "fusionrep.com"] [uri "/"] [unique_id "amvZSzsFNPjyqkQLwgNGEAAAAAY"], referer: https://fusionrep.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-30 11:21:07
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 07:21:01.107524 2026] [security2:error] [pid 2976388:tid 2976413] [client 42.201.192.7:15161] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||spectresails.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "spectresails.com"] [uri "/spectre_sails_004.htm"] [unique_id "amszncqWTIhF_iP0-CN07gAAANc"], referer: https://spectresails.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-30 09:38:48
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 42.201.192.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 42.201.192.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 05:38:42.409990 2026] [security2:error] [pid 1996360:tid 1996360] [client 42.201.192.7:37092] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||adrienberthaud.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "adrienberthaud.com"] [uri "/guy_durosier"] [unique_id "amsbokEO7hGxWR1VdkyH8wAAAA0"], referer: https://adrienberthaud.com/
show less
Brute-Force
Bad Web Bot
Web App Attack