๐ณ๐ฑ
e.fierstra
2026-08-07 09:16:32
(2 weeks ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 08:33:07
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh. ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 04:32:59.931519 2026] [security2:error] [pid 2665790:tid 2665790] [client 2001:41d0:305:2100::4451:37378] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||debhill.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "debhill.com"] [uri "/"] [unique_id "anWYO3IEMG9URj-D6PUNBwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 08:10:00
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh. ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 04:09:54.700115 2026] [security2:error] [pid 2427311:tid 2427334] [client 2001:41d0:305:2100::4451:57470] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||abney.info|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "abney.info"] [uri "/"] [unique_id "anWS0rLoGT64r4ZEsXY6ogAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 07:17:51
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh. ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 03:17:44.987894 2026] [security2:error] [pid 29921:tid 29921] [client 2001:41d0:305:2100::4451:48340] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||corstratinc.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "corstratinc.com"] [uri "/"] [unique_id "anWGmJfbuIrcnlIggBfrfQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-08-07 06:23:24
(2 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
Anonymous
2026-08-07 06:08:59
(2 weeks ago)
http scanning for .env files
...
Hacking
Web App Attack
๐ง๐ช
cmbplf
2026-08-07 05:28:26
(2 weeks ago)
2.197 requests with url.path *.env
Brute-Force
Bad Web Bot
๐ฉ๐ช
ghostwarriors
2026-08-07 05:20:16
(2 weeks ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 04:33:03
(2 weeks ago)
(mod_security) mod_security (id:949110) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh. ...
show more
(mod_security) mod_security (id:949110) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 00:32:55.082564 2026] [security2:error] [pid 1487661:tid 1487661] [client 2001:41d0:305:2100::4451:46404] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 8)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "letahitibookings.com"] [uri "/.env"] [unique_id "anVf93Pic1urISqc2_NG6wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 03:46:03
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh. ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 23:45:55.218378 2026] [security2:error] [pid 1632135:tid 1632135] [client 2001:41d0:305:2100::4451:54656] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||dealconsultingllc.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "dealconsultingllc.com"] [uri "/"] [unique_id "anVU81DxyBQdc12D2gYHUAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 03:21:39
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh. ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 23:21:33.089166 2026] [security2:error] [pid 1727432:tid 1727432] [client 2001:41d0:305:2100::4451:45480] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.tttns.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.tttns.com"] [uri "/about-jason/"] [unique_id "anVPPRuqSGfKU6PXNV2sywAAAAY"], referer: http://jasonrankin.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 02:45:40
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh. ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 22:45:33.853803 2026] [security2:error] [pid 2798788:tid 2798788] [client 2001:41d0:305:2100::4451:43040] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||medusakenya.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "medusakenya.com"] [uri "/"] [unique_id "anVGzb8qpeoNSIjmGQ_k6gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 02:29:16
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh. ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 22:29:12.465254 2026] [security2:error] [pid 884591:tid 884613] [client 2001:41d0:305:2100::4451:49756] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||richardleeweatherman.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "richardleeweatherman.com"] [uri "/"] [unique_id "anVC-Jaa5qD-oT5kZulOIgAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 02:10:46
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh. ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 22:10:43.484617 2026] [security2:error] [pid 1486030:tid 1486030] [client 2001:41d0:305:2100::4451:53198] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||dolapdere.click|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "dolapdere.click"] [uri "/"] [unique_id "anU-o0F3m_70vimoSaUf5AAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
alferez
2026-08-07 02:09:24
(2 weeks ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack