๐ณ๐ฑ
homeshowdomain.nl
2026-08-07 21:59:36
(2 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-06.
show less
Web App Attack
SSH
Hacking
๐ฆ๐บ
2000cn.com.au
2026-08-07 14:34:11
(2 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
Anonymous
2026-08-07 14:27:14
(2 weeks ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-08-07 12:48:36
(2 weeks ago)
Try to access /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 11:38:10
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:404:200::8dcd (vps-a7d99dfd.vps.ovh.n ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:404:200::8dcd (vps-a7d99dfd.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 07:38:01.853129 2026] [security2:error] [pid 2690961:tid 2690961] [client 2001:41d0:404:200::8dcd:49966] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||cerrovictoria.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "cerrovictoria.com"] [uri "/"] [unique_id "anXDmcsN3w-gqcvhFFjY7wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SCHAPPY
2026-08-07 10:30:14
(2 weeks ago)
Brute-force attack to non-existent web resources, HTTP code 404.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 10:03:39
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:404:200::8dcd (vps-a7d99dfd.vps.ovh.n ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:404:200::8dcd (vps-a7d99dfd.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 06:03:36.431424 2026] [security2:error] [pid 4060895:tid 4060895] [client 2001:41d0:404:200::8dcd:54298] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||allseniorsolutions.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "allseniorsolutions.net"] [uri "/"] [unique_id "anWtePsS0wAmuyVNbIKApwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
ciccio diddo
2026-08-07 10:01:41
(2 weeks ago)
High Burst multiple 40X port:Tcp/80,443
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-08-07 09:41:43
(2 weeks ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-08-07 09:14:06
(2 weeks ago)
2026/08/07 10:14:05 [error] 1078939#1078939: *1425208 access forbidden by rule, client: 2001:41d0:40 ...
show more
2026/08/07 10:14:05 [error] 1078939#1078939: *1425208 access forbidden by rule, client: 2001:41d0:404:200::8dcd, server: feminina.eu, request: "GET /.env HTTP/2.0", host: "feminina.eu"
2026/08/07 10:14:05 [error] 1078939#1078939: *1425209 access forbidden by rule, client: 2001:41d0:404:200::8dcd, server: feminina.eu, request: "GET /env/.env HTTP/2.0", host: "feminina.eu"
2026/08/07 10:14:05 [error] 1078939#1078939: *1425210 access forbidden by rule, client: 2001:41d0:404:200::8dcd, server: feminina.eu, request: "GET /app/.env HTTP/2.0", host: "feminina.eu"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 08:55:32
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:404:200::8dcd (vps-a7d99dfd.vps.ovh.n ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:404:200::8dcd (vps-a7d99dfd.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 04:55:27.522236 2026] [security2:error] [pid 4064573:tid 4064573] [client 2001:41d0:404:200::8dcd:59686] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||agrizel.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "agrizel.com"] [uri "/"] [unique_id "anWdf1fPmsQww0AAvn0kywAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
macrob
2026-08-07 08:54:11
(2 weeks ago)
2026/08/07 08:54:09 [error] 3981543#3981543: *454559313 access forbidden by rule, client: 2001:41d0: ...
show more
2026/08/07 08:54:09 [error] 3981543#3981543: *454559313 access forbidden by rule, client: 2001:41d0:404:200::8dcd, server: behemoti.com, request: "GET /.env HTTP/2.0", host: "behemoti.com"
2026/08/07 08:54:10 [error] 3981543#3981543: *454559319 access forbidden by rule, client: 2001:41d0:404:200::8dcd, server: behemoti.com, request: "GET /env/.env HTTP/2.0", host: "behemoti.com"
2026/08/07 08:54:10 [error] 3981543#3981543: *454559319 access forbidden by rule, client: 2001:41d0:404:200::8dcd, server: behemoti.com, request: "GET /app/.env HTTP/2.0", host: "behemoti.com"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 07:12:12
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:404:200::8dcd (vps-a7d99dfd.vps.ovh.n ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:404:200::8dcd (vps-a7d99dfd.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 03:12:08.490955 2026] [security2:error] [pid 1857841:tid 1857841] [client 2001:41d0:404:200::8dcd:60100] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||ggisoftware.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "ggisoftware.com"] [uri "/"] [unique_id "anWFSCMw7xEv1MSbdnJTfwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 06:41:08
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:404:200::8dcd (vps-a7d99dfd.vps.ovh.n ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:404:200::8dcd (vps-a7d99dfd.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 02:41:00.457412 2026] [security2:error] [pid 273169:tid 273169] [client 2001:41d0:404:200::8dcd:34278] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||photoboothtogo.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "photoboothtogo.com"] [uri "/"] [unique_id "anV9_BpHjof_AzwqeKjY-gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-08-07 06:25:09
(2 weeks ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack