๐บ๐ธ
TPI-Abuse
2026-05-16 10:26:36
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 149.143.135.218 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 149.143.135.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 06:26:27.228550 2026] [security2:error] [pid 7172:tid 7172] [client 149.143.135.218:39525] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ctjcisenate.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ctjcisenate.org"] [uri "/backup.sql"] [unique_id "aghGUxc4PcTZMSjZwqHbPgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-16 06:40:31
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 149.143.135.218 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 149.143.135.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 02:40:26.829610 2026] [security2:error] [pid 16060:tid 16060] [client 149.143.135.218:45405] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.propertygalleria.vittariadesign.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.propertygalleria.vittariadesign.com"] [uri "/wp-content/mysql.sql"] [unique_id "aggRWg8FJ5DlViys-PzOGQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-16 05:20:47
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.218 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 01:20:37.274611 2026] [security2:error] [pid 14323:tid 14323] [client 149.143.135.218:53787] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gelatouno.com.salernospizza.com"] [uri "/.htpasswd"] [unique_id "agf-pQWS74s-WqhMoP7GWgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 08:59:56
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.218 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:59:09.558937 2026] [security2:error] [pid 11972:tid 11972] [client 149.143.135.218:33077] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brookspowell.com"] [uri "/.git/config"] [unique_id "agbgXVEi9jpkGlGRKkvDKQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 08:42:19
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.218 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:41:45.618508 2026] [security2:error] [pid 17847:tid 17865] [client 149.143.135.218:53405] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thebiglies.org"] [uri "/.env.testing"] [unique_id "agbcSUUzPAqlg5pCjSPswwAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 08:24:47
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.218 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:24:32.189376 2026] [security2:error] [pid 22899:tid 22899] [client 149.143.135.218:56961] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crestrong.com"] [uri "/.env~"] [unique_id "agbYQBZ5SjzSTakt-L-7KwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 07:29:59
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.218 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 03:29:34.374483 2026] [security2:error] [pid 14394:tid 14394] [client 149.143.135.218:40571] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.spittingimagegallery.kathrynmcbride.com"] [uri "/.htpasswd"] [unique_id "agbLXnV_iglhEi36tzQsvgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 06:42:11
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 149.143.135.218 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 149.143.135.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 02:41:16.594651 2026] [security2:error] [pid 23207:tid 23207] [client 149.143.135.218:34427] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gods-law.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gods-law.com"] [uri "/db.sql"] [unique_id "agbADPxIsV04lRbOZnB7YAAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 06:20:49
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.218 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 02:20:20.296560 2026] [security2:error] [pid 30012:tid 30012] [client 149.143.135.218:53933] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aden.us"] [uri "/.git/config"] [unique_id "aga7JFBVgrNayhqm5agHMgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Holger
2026-05-12 23:49:07
(4 months ago)
Bruteforce WebAttack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-12 20:37:58
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.218 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 16:37:29.556922 2026] [security2:error] [pid 14390:tid 14390] [client 149.143.135.218:52969] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "urie.to.daveewalker.bz"] [uri "/.git/config"] [unique_id "agOPiWYV3JS_rG4PCRmVxAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-12 13:53:09
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.218 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 09:52:21.367221 2026] [security2:error] [pid 12736:tid 12736] [client 149.143.135.218:48633] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "peanutcarvings.com"] [uri "/.env.yaml"] [unique_id "agMwld1-3qR5urO6d-qYPAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-12 13:31:43
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.218 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 09:31:00.617253 2026] [security2:error] [pid 9318:tid 9318] [client 149.143.135.218:48517] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lawrencehale.com"] [uri "/.env.production.local"] [unique_id "agMrlHS3J5SYMHxYlke8KQAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Holger
2026-05-11 09:49:54
(4 months ago)
Bruteforce WebAttack
Brute-Force
Web App Attack
Anonymous
2026-05-10 14:19:12
(4 months ago)
(caddyscan) Scanner path probe from 149.143.135.218 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 149.143.135.218 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 149.143.135.218 - - [10/May/2026:14:17:50 +0000] "GET /.git/HEAD HTTP/1.1"
[REDACTED] 200 2627 149.143.135.218 - - [10/May/2026:14:18:49 +0000] "GET /.env.dist HTTP/1.1"
[REDACTED] 200 2627 149.143.135.218 - - [10/May/2026:14:19:03 +0000] "GET /.env.test HTTP/1.1"
[REDACTED] 200 2627 149.143.135.218 - - [10/May/2026:14:19:08 +0000] "GET /.env.demo HTTP/1.1"
[REDACTED] 200 2627 149.143.135.218 - - [10/May/2026:14:19:10 +0000] "GET /.env.2 HTTP/1.1"
show less
Port Scan