Anonymous
2026-08-09 04:33:15
(2 weeks ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ณ๐ฑ
homeshowdomain.nl
2026-08-07 21:59:53
(2 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-06.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-07 14:34:38
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:701:1100::35ef (vps-5cdfe64e.vps.ovh. ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:701:1100::35ef (vps-5cdfe64e.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 10:34:33.407208 2026] [security2:error] [pid 2877586:tid 2877586] [client 2001:41d0:701:1100::35ef:44172] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||jpfamilyllc.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "jpfamilyllc.com"] [uri "/"] [unique_id "anXs-X-DQiQhJk0PMDyJigAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
nfsec.pl
2026-08-07 14:25:59
(2 weeks ago)
2001:41d0:701:1100::35ef - - [07/Aug/2026:14:25:58 +0000] "GET / HTTP/1.1" 403 376 "-" "Mozilla/5.0 ...
show more
2001:41d0:701:1100::35ef - - [07/Aug/2026:14:25:58 +0000] "GET / HTTP/1.1" 403 376 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"
2001:41d0:701:1100::35ef - - [07/Aug/2026:14:25:58 +0000] "GET / HTTP/1.1" 403 8016 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"
2001:41d0:701:1100::35ef - - [07/Aug/2026:14:25:58 +0000] "GET /.env HTTP/1.1" 403 376 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"
2001:41d0:701:1100::35ef - - [07/Aug/2026:14:25:58 +0000] "GET /env/.env HTTP/1.1" 403 376 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"
2001:41d0:701:1100::35ef - - [07/Aug/2026:14:25:58 +0000] "GET /app/.env HTTP/1.1" 403 376 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"
...
show less
Web App Attack
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-08-07 13:40:55
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:701:1100::35ef (vps-5cdfe64e.vps.ovh. ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:701:1100::35ef (vps-5cdfe64e.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 09:40:47.962259 2026] [security2:error] [pid 2556291:tid 2556291] [client 2001:41d0:701:1100::35ef:49532] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||mnalabama.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "mnalabama.com"] [uri "/"] [unique_id "anXgX8ij9rKu6N3B3r3lIAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-07 10:55:44
(2 weeks ago)
2001:41d0:701:1100::35ef - - [07/Aug/2026:10:55:43 +0000] "GET /.env HTTP/1.1" 302 585 "-" "Mozilla/ ...
show more
2001:41d0:701:1100::35ef - - [07/Aug/2026:10:55:43 +0000] "GET /.env HTTP/1.1" 302 585 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 10:34:35
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:701:1100::35ef (vps-5cdfe64e.vps.ovh. ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:701:1100::35ef (vps-5cdfe64e.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 06:34:28.215809 2026] [security2:error] [pid 3871119:tid 3871119] [client 2001:41d0:701:1100::35ef:55460] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||nextngnr.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "nextngnr.com"] [uri "/"] [unique_id "anW0tOMaNacaNorctPlzegAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-07 10:12:29
(2 weeks ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 09:51:40
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:701:1100::35ef (vps-5cdfe64e.vps.ovh. ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:701:1100::35ef (vps-5cdfe64e.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 05:51:33.728874 2026] [security2:error] [pid 3453807:tid 3453807] [client 2001:41d0:701:1100::35ef:32990] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||oligofoundry.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "oligofoundry.com"] [uri "/"] [unique_id "anWqpULVq_WaNrMh6zIkZAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-08-07 08:55:45
(2 weeks ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐บ๐ธ
WellSpring
2026-08-07 07:36:34
(2 weeks ago)
env leak on 865.today/src/.env โ WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 07:03:13
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:701:1100::35ef (vps-5cdfe64e.vps.ovh. ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:701:1100::35ef (vps-5cdfe64e.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 03:03:04.867150 2026] [security2:error] [pid 1402298:tid 1402298] [client 2001:41d0:701:1100::35ef:42234] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||newlifecommunitycare.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "newlifecommunitycare.org"] [uri "/"] [unique_id "anWDKEVZ5AhVGlyMzNp64AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 06:05:12
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:701:1100::35ef (vps-5cdfe64e.vps.ovh. ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:701:1100::35ef (vps-5cdfe64e.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 02:05:04.487091 2026] [security2:error] [pid 1416105:tid 1416105] [client 2001:41d0:701:1100::35ef:55752] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||kochcreative.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "kochcreative.com"] [uri "/"] [unique_id "anV1kLBQQirOHmmOpTwNtQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 05:30:13
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2001:41d0:701:1100::35ef (vps-5cdfe64e.vps.ovh. ...
show more
(mod_security) mod_security (id:210350) triggered by 2001:41d0:701:1100::35ef (vps-5cdfe64e.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 01:30:06.489115 2026] [security2:error] [pid 1349647:tid 1349647] [client 2001:41d0:701:1100::35ef:41294] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||oaklands1.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "oaklands1.com"] [uri "/"] [unique_id "anVtXtt1FLrgc76CIw9blgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-08-07 05:15:19
(2 weeks ago)
12 attacks on env grabbing URLs:
GET /storage/.env HTTP/1.1
Hacking