🇭🇺
bcsaba
2026-08-13 03:37:57
(2 weeks ago)
Joomla spam
5.181.131.117 - - [13/Aug/2026:05:37:55 +0200] "GET /index.php?option=com_easyblog&view= ...
show more
Joomla spam
5.181.131.117 - - [13/Aug/2026:05:37:55 +0200] "GET /index.php?option=com_easyblog&view=dashboard&layout=write HTTP/1.1" 404 789 "https://*REDACTED*/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-12 23:48:04
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 5.181.131.117 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 5.181.131.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 19:47:57.039753 2026] [security2:error] [pid 2381683:tid 2381683] [client 5.181.131.117:38075] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||etudesoftware.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "etudesoftware.com"] [uri "/"] [unique_id "an0GLa9mZa31xFG6IzhPIwAAAAg"], referer: http://etudesoftware.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-08-11 12:43:24
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 247
Exploited Host
Web App Attack
🇩🇪
FeG Deutschland
2026-08-09 22:37:45
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 247
Exploited Host
Web App Attack
🇩🇪
Viveronese
2026-08-06 08:06:04
(3 weeks ago)
HTTP vulnerability scanning
Web App Attack
🇺🇸
TPI-Abuse
2026-07-30 06:57:16
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 5.181.131.117 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 5.181.131.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 02:57:06.952753 2026] [security2:error] [pid 3135580:tid 3135580] [client 5.181.131.117:58285] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||med-engineering.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "med-engineering.com"] [uri "/index.php/component/users/"] [unique_id "amr1wkcXV8_Dipy-fnsJ0QAAAC4"], referer: https://med-engineering.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-13 10:44:37
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 5.181.131.117 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 5.181.131.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 13 06:44:30.174488 2026] [security2:error] [pid 2510:tid 2510] [client 5.181.131.117:48179] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.circleofsound.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.circleofsound.org"] [uri "/"] [unique_id "alTBjjfit7kilf7pZXnTegAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Oakley
2026-06-30 19:38:44
(1 month ago)
(confirmed_bot_sig) Confirmed bot
Hacking
🇺🇸
TPI-Abuse
2026-06-29 06:24:42
(2 months ago)
(mod_security) mod_security (id:210350) triggered by 5.181.131.117 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 5.181.131.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 02:24:33.029099 2026] [security2:error] [pid 3123:tid 3145] [client 5.181.131.117:33197] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.ahsdistance.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.ahsdistance.org"] [uri "/"] [unique_id "akIPoZi93YQeiq3BMmKLIgAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-25 11:44:18
(2 months ago)
(mod_security) mod_security (id:210350) triggered by 5.181.131.117 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 5.181.131.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 07:44:08.875848 2026] [security2:error] [pid 26334:tid 26334] [client 5.181.131.117:31425] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.cchockeyhistory.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.cchockeyhistory.org"] [uri "/CCIceRinks.htm"] [unique_id "aj0UiPBLSput71BuoLqSaQAAAAQ"], referer: http://www.cchockeyhistory.org/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
ipblock.com
2026-06-03 05:03:00
(2 months ago)
IPBlock protected site ID [4055-d][s=07].
Persistent 404, vulnerability scanner
Hacking
Bad Web Bot
Web App Attack
🇺🇸
ipblock.com
2026-06-01 08:57:00
(2 months ago)
IPBlock protected site ID [4055-d][s=07].
Persistent 404, vulnerability scanner
Hacking
Bad Web Bot
Web App Attack
🇺🇸
ipblock.com
2026-05-29 15:52:00
(3 months ago)
IPBlock protected site ID [4055-d][s=07].
Persistent 404, vulnerability scanner
Hacking
Bad Web Bot
Web App Attack
🇺🇸
ipblock.com
2026-05-27 20:42:00
(3 months ago)
IPBlock protected site ID [4055-d][s=07].
Persistent 404, vulnerability scanner
Hacking
Bad Web Bot
Web App Attack
🇺🇸
ipblock.com
2026-05-26 01:12:00
(3 months ago)
IPBlock protected site ID [4055-d][s=07].
Persistent 404, vulnerability scanner
Hacking
Bad Web Bot
Web App Attack