Anonymous
2026-08-13 14:43:27
(3 weeks ago)
2001:41d0:305:2100::4451 - - [13/Aug/2026:22:43:27 +0800] "GET / HTTP/1.1" 200 30679 "-" "wp2shell"
...
show more
2001:41d0:305:2100::4451 - - [13/Aug/2026:22:43:27 +0800] "GET / HTTP/1.1" 200 30679 "-" "wp2shell"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
Penny Packer
2026-08-12 21:02:07
(3 weeks ago)
Fail2Ban apache-tripwires
Web App Attack
Anonymous
2026-08-09 04:33:26
(3 weeks ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
🇬🇧
openstrike.co.uk
2026-08-08 05:13:52
(3 weeks ago)
48 attacks on env grabbing URLs:
GET /storage/.env HTTP/1.1
Hacking
🇳🇱
homeshowdomain.nl
2026-08-07 21:59:54
(3 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-06.
show less
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-08-07 14:45:04
(3 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh. ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 10:44:56.634252 2026] [security2:error] [pid 11157:tid 11157] [client 2001:41d0:305:2100::4451:41312] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||ashleycroft.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "ashleycroft.com"] [uri "/"] [unique_id "anXvaLOlIAJYtjDt2VfKlAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
Erpelstolz
2026-08-07 13:22:04
(4 weeks ago)
external host: 2001:41d0:305:2100::4451 - - [07/Aug/2026:15:22:04 +0200] "GET /backend/.env HTTP/1.1 ...
show more
external host: 2001:41d0:305:2100::4451 - - [07/Aug/2026:15:22:04 +0200] "GET /backend/.env HTTP/1.1" 404 5663 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0" CF-Ray:- CF-IP:-
show less
Web App Attack
🇫🇷
dynamix
2026-08-07 12:34:55
(4 weeks ago)
Multiple WAF Violations
Web App Attack
🇪🇸
antivoid.xyz
2026-08-07 12:17:36
(4 weeks ago)
Brute-Force
Web App Attack
🇫🇷
Baking333
2026-08-07 11:55:16
(4 weeks ago)
[redacted] 2001:41d0:305:2100::4451 - - [07/Aug/2026:12:55:14 +0100] "GET /.env HTTP/1.1" 302 6753 0 ...
show more
[redacted] 2001:41d0:305:2100::4451 - - [07/Aug/2026:12:55:14 +0100] "GET /.env HTTP/1.1" 302 6753 0/63027 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0" [redacted] 2001:41d0:305:2100::4451 - - [07/Aug/2026:12:55:14 +0100] "GET / HTTP/1.1" 200 14334 0/64948 "https://[redacted]/.env" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-07 11:50:06
(4 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh. ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 07:49:58.966713 2026] [security2:error] [pid 189541:tid 189541] [client 2001:41d0:305:2100::4451:52350] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||j3pr.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "j3pr.com"] [uri "/"] [unique_id "anXGZhFXbVYqROtCbGMlMQAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-07 11:25:22
(4 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh. ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 07:25:17.138106 2026] [security2:error] [pid 2625291:tid 2625444] [client 2001:41d0:305:2100::4451:48508] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||bluetigertees.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "bluetigertees.com"] [uri "/"] [unique_id "anXAnec7-tZv7sq2kKPHQQAAANY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-07 10:02:32
(4 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh. ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 06:02:26.861502 2026] [security2:error] [pid 1655933:tid 1655933] [client 2001:41d0:305:2100::4451:33616] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||bosozuki.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "bosozuki.com"] [uri "/"] [unique_id "anWtMiK1chEDLR7Zuncb3wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
BlueWire Hosting
2026-08-07 09:48:51
(4 weeks ago)
Probing websites for vulnerabilities
Web App Attack
🇺🇸
TPI-Abuse
2026-08-07 09:42:46
(4 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh. ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 05:42:42.135670 2026] [security2:error] [pid 1589832:tid 1589832] [client 2001:41d0:305:2100::4451:48944] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||consolidatedoperationsgroup.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "consolidatedoperationsgroup.com"] [uri "/"] [unique_id "anWokpLLUxwp4NEEtIHnvAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack