Anonymous
2026-08-24 05:22:22
(2 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-07 22:00:19
(2 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-06.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-07 14:23:06
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2603:3:6101:7d30:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210350) triggered by 2603:3:6101:7d30:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 10:22:57.976835 2026] [security2:error] [pid 3140516:tid 3140516] [client 2603:3:6101:7d30:::58906] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||paintriver.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "paintriver.com"] [uri "/"] [unique_id "anXqQXUCy6S8CFAxRYU_UwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 13:23:18
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2603:3:6101:7d30:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210350) triggered by 2603:3:6101:7d30:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 09:23:12.761535 2026] [security2:error] [pid 906932:tid 906932] [client 2603:3:6101:7d30:::43700] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||jenricker.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "jenricker.com"] [uri "/"] [unique_id "anXcQAQHfcpJONC8YohchQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 11:24:48
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2603:3:6101:7d30:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210350) triggered by 2603:3:6101:7d30:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 07:24:42.940749 2026] [security2:error] [pid 1859706:tid 1859706] [client 2603:3:6101:7d30:::32842] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||kittensquid.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "kittensquid.com"] [uri "/"] [unique_id "anXAembxPDwoFza-umpQdgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 10:06:08
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2603:3:6101:7d30:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210350) triggered by 2603:3:6101:7d30:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 06:06:04.379013 2026] [security2:error] [pid 1350244:tid 1350244] [client 2603:3:6101:7d30:::44070] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||grhall.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "grhall.com"] [uri "/"] [unique_id "anWuDN8-aOxoqKX1TKBkUQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 08:57:53
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2603:3:6101:7d30:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210350) triggered by 2603:3:6101:7d30:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 04:57:47.999784 2026] [security2:error] [pid 3995382:tid 3995382] [client 2603:3:6101:7d30:::42512] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||itecsis.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "itecsis.com"] [uri "/"] [unique_id "anWeC90EDcHMAYN2ndt_AwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-08-07 08:28:22
(2 weeks ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-08-07 08:25:59
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2603:3:6101:7d30:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210350) triggered by 2603:3:6101:7d30:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 04:25:54.866274 2026] [security2:error] [pid 1848694:tid 1848694] [client 2603:3:6101:7d30:::55676] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||myappliancehero.pro|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "myappliancehero.pro"] [uri "/"] [unique_id "anWWkvFl57oWCDSv6atd7QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 07:22:34
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2603:3:6101:7d30:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210350) triggered by 2603:3:6101:7d30:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 03:22:28.754732 2026] [security2:error] [pid 3879559:tid 3879559] [client 2603:3:6101:7d30:::41186] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||oakleighfarm.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "oakleighfarm.com"] [uri "/"] [unique_id "anWHtKixNVq5cCdoG_jCowAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 05:12:27
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2603:3:6101:7d30:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210350) triggered by 2603:3:6101:7d30:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 01:12:21.722781 2026] [security2:error] [pid 2731:tid 2731] [client 2603:3:6101:7d30:::46344] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||3-6trucking.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "3-6trucking.com"] [uri "/"] [unique_id "anVpNfti4dISKDrYlwtPAgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 04:02:35
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2603:3:6101:7d30:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210350) triggered by 2603:3:6101:7d30:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 00:02:28.291127 2026] [security2:error] [pid 2006271:tid 2006271] [client 2603:3:6101:7d30:::52096] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||expertprofessionalcleaners.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "expertprofessionalcleaners.com"] [uri "/"] [unique_id "anVY1OPtjnmyx8_1imo3PwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
alferez
2026-08-07 02:53:24
(2 weeks ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 02:49:53
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2603:3:6101:7d30:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210350) triggered by 2603:3:6101:7d30:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 22:49:44.893817 2026] [security2:error] [pid 3845106:tid 3845106] [client 2603:3:6101:7d30:::46014] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||parastesh.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "parastesh.org"] [uri "/"] [unique_id "anVHyGvUr3tQMA451FUPiQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
6kilowatti
2026-08-06 17:21:28
(2 weeks ago)
2603:3:6101:7d30:: - - [06/Aug/2026:20:21:27 +0300] "GET /.env HTTP/1.1" 404 60 "-" "Mozilla/5.0 (Wi ...
show more
2603:3:6101:7d30:: - - [06/Aug/2026:20:21:27 +0300] "GET /.env HTTP/1.1" 404 60 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"
...
show less
Web App Attack