๐บ๐ธ
TPI-Abuse
2026-08-07 02:10:46
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh. ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 22:10:43.484617 2026] [security2:error] [pid 1486030:tid 1486030] [client 2001:41d0:305:2100::4451:53198] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||dolapdere.click|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "dolapdere.click"] [uri "/"] [unique_id "anU-o0F3m_70vimoSaUf5AAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
alferez
2026-08-07 02:09:24
(1 month ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-07 01:59:28
(1 month ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-07 01:53:03
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh. ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 21:52:55.466890 2026] [security2:error] [pid 7941:tid 7941] [client 2001:41d0:305:2100::4451:47072] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||divineadventures.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "divineadventures.org"] [uri "/"] [unique_id "anU6d0MnRvwVyQrbE7hJ7wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-06 23:48:03
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh. ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 19:47:58.437071 2026] [security2:error] [pid 4084600:tid 4084600] [client 2001:41d0:305:2100::4451:37774] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||pkmachine.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "pkmachine.com"] [uri "/"] [unique_id "anUdLsSJgG9PM6UX5IjR0wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-06 23:22:19
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh. ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 19:22:14.005641 2026] [security2:error] [pid 2741748:tid 2741748] [client 2001:41d0:305:2100::4451:33330] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||billymitchell.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "billymitchell.com"] [uri "/"] [unique_id "anUXJq2bm0Hpro3wgansXwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-08-06 20:15:52
(1 month ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-06 18:45:18
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh. ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 14:45:13.942514 2026] [security2:error] [pid 832573:tid 832573] [client 2001:41d0:305:2100::4451:60858] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||saynotoofland.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "saynotoofland.org"] [uri "/"] [unique_id "anTWOWoLylW-zgj_7J1fIgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-08-06 18:20:03
(1 month ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-06 17:54:16
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh. ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 13:54:10.388108 2026] [security2:error] [pid 3361907:tid 3361907] [client 2001:41d0:305:2100::4451:54892] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||al-bukhari.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "al-bukhari.org"] [uri "/"] [unique_id "anTKQoHLfCnl9lvYJ3agdwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-06 17:25:06
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh. ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:305:2100::4451 (vps-7723807a.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 13:25:01.204400 2026] [security2:error] [pid 3799984:tid 3799984] [client 2001:41d0:305:2100::4451:58146] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||acarsubscription.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "acarsubscription.com"] [uri "/"] [unique_id "anTDbWPE1g_u32r5qqL4GgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack