Anonymous
2026-08-09 04:33:22
(1 month ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
🇬🇧
openstrike.co.uk
2026-08-08 05:14:16
(1 month ago)
24 attacks on env grabbing URLs:
GET /storage/.env HTTP/1.1
Hacking
🇳🇱
homeshowdomain.nl
2026-08-07 21:59:58
(1 month ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-06.
show less
Web App Attack
SSH
Hacking
🇺🇸
SLSLLC
2026-08-07 12:06:17
(1 month ago)
2001:41d0:20a:900::1a73 - - [07/Aug/2026:12:06:16 +0000] "GET /.env HTTP/2.0" 403 1927 "-" "Mozilla/ ...
show more
2001:41d0:20a:900::1a73 - - [07/Aug/2026:12:06:16 +0000] "GET /.env HTTP/2.0" 403 1927 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"
...
show less
Brute-Force
Web App Attack
🇬🇧
gurnip
2026-08-07 12:04:33
(1 month ago)
Vulnerability probe of page /.env, not found on server.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-07 11:38:30
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:20a:900::1a73 (vps-d1ce60ae.vps.ovh.n ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:20a:900::1a73 (vps-d1ce60ae.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 07:38:22.960723 2026] [security2:error] [pid 18222:tid 18238] [client 2001:41d0:20a:900::1a73:35698] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||keithfamily.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "keithfamily.net"] [uri "/"] [unique_id "anXDrmuhmfF-JczVyxADJAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-07 11:18:51
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:20a:900::1a73 (vps-d1ce60ae.vps.ovh.n ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:20a:900::1a73 (vps-d1ce60ae.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 07:18:47.611773 2026] [security2:error] [pid 20920:tid 20920] [client 2001:41d0:20a:900::1a73:47598] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||investorsfundingusa.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "investorsfundingusa.com"] [uri "/"] [unique_id "anW_F7nm5zzgoybIu7XDcgAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-07 09:55:40
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:20a:900::1a73 (vps-d1ce60ae.vps.ovh.n ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:20a:900::1a73 (vps-d1ce60ae.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 05:55:36.366833 2026] [security2:error] [pid 3824549:tid 3824549] [client 2001:41d0:20a:900::1a73:59254] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||2massociatesllc.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "2massociatesllc.com"] [uri "/"] [unique_id "anWrmECSiN_7us5cxjJbowAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-07 09:54:02
(1 month ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
🇺🇸
TPI-Abuse
2026-08-07 09:12:51
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:20a:900::1a73 (vps-d1ce60ae.vps.ovh.n ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:20a:900::1a73 (vps-d1ce60ae.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 05:12:48.029922 2026] [security2:error] [pid 1210934:tid 1210934] [client 2001:41d0:20a:900::1a73:39562] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||merrilymovie.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "merrilymovie.com"] [uri "/"] [unique_id "anWhkMjLJ4jGlaXUzureFQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
WellSpring
2026-08-07 08:56:40
(1 month ago)
env leak on 580.today/admin/.env — WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
🇺🇸
interbiznw.com
2026-08-07 08:16:00
(1 month ago)
fail2ban-ban
Hacking
Brute-Force
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-08-07 07:55:59
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:20a:900::1a73 (vps-d1ce60ae.vps.ovh.n ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:20a:900::1a73 (vps-d1ce60ae.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 03:55:55.079611 2026] [security2:error] [pid 1515774:tid 1515774] [client 2001:41d0:20a:900::1a73:56256] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||jafgcreates.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "jafgcreates.com"] [uri "/"] [unique_id "anWPi21pik4rJicUulKwVgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-07 07:13:29
(1 month ago)
(mod_security) mod_security (id:949110) triggered by 2001:41d0:20a:900::1a73 (vps-d1ce60ae.vps.ovh.n ...
show more
(mod_security) mod_security (id:949110) triggered by 2001:41d0:20a:900::1a73 (vps-d1ce60ae.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 03:13:26.028762 2026] [security2:error] [pid 1632798:tid 1632798] [client 2001:41d0:20a:900::1a73:59652] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 8)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "letahaabooking.com"] [uri "/.env"] [unique_id "anWFlkzr4EGBZyLaLyAwGAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-07 06:24:00
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:20a:900::1a73 (vps-d1ce60ae.vps.ovh.n ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:20a:900::1a73 (vps-d1ce60ae.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 02:23:52.648889 2026] [security2:error] [pid 2561145:tid 2561145] [client 2001:41d0:20a:900::1a73:58814] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||lfrmtmorris.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "lfrmtmorris.com"] [uri "/"] [unique_id "anV5-M1RbX8LjgUUCpOMNAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack