๐บ๐ธ
TPI-Abuse
2026-05-19 17:14:14
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.232 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 19 13:14:08.069302 2026] [security2:error] [pid 16997:tid 16997] [client 149.143.135.232:41511] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ratbird.com"] [uri "/.env.yml"] [unique_id "agyaYMItPeeWbpO5R2waHAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-17 13:11:54
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.232 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 09:11:50.484510 2026] [security2:error] [pid 26236:tid 26236] [client 149.143.135.232:42359] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.island.cleanhorizons.org"] [uri "/backend/.env"] [unique_id "agm-lvpUyUHUzuwg15bSWwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 09:03:24
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 149.143.135.232 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 149.143.135.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 05:03:06.915492 2026] [security2:error] [pid 19650:tid 19650] [client 149.143.135.232:34771] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||crearetest.com.creartest.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "crearetest.com.creartest.com"] [uri "/wp-content/mysql.sql"] [unique_id "agbhSmJ26KIuHbgesgVEowAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 08:41:11
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.232 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:41:02.187288 2026] [security2:error] [pid 14442:tid 14461] [client 149.143.135.232:37811] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sattraffic.com"] [uri "/.svn/entries"] [unique_id "agbcHjZRkVGYX_uH--qPPwAAANA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 07:36:38
(4 months ago)
(mod_security) mod_security (id:949110) triggered by 149.143.135.232 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:949110) triggered by 149.143.135.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 03:36:24.336130 2026] [security2:error] [pid 16159:tid 16159] [client 149.143.135.232:33489] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mijn.photo"] [uri "/dump.sql"] [unique_id "agbM-FJ8My8riL_zXVIS4AAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 06:42:59
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 149.143.135.232 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 149.143.135.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 02:42:29.937556 2026] [security2:error] [pid 12945:tid 12945] [client 149.143.135.232:37733] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||callahan-co.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "callahan-co.com"] [uri "/dump.sql"] [unique_id "agbAVSGCmG-Quu49CPxOWQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-13 08:49:11
(4 months ago)
(caddyscan) Scanner path probe from 149.143.135.232 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 149.143.135.232 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 0 149.143.135.232 - - [13/May/2026:07:56:38 +0000] "HEAD /.env.local HTTP/1.1"
[REDACTED] 200 2627 149.143.135.232 - - [13/May/2026:07:56:42 +0000] "GET /.env.local.php HTTP/1.1"
[REDACTED] 200 0 149.143.135.232 - - [13/May/2026:08:16:58 +0000] "HEAD /.aws/credentials HTTP/1.1"
[REDACTED] 200 2627 149.143.135.232 - - [13/May/2026:08:48:49 +0000] "GET /api/actuator/env HTTP/1.1"
[REDACTED] 200 2627 149.143.135.232 - - [13/May/2026:08:49:05 +0000] "GET /.env.txt HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-12 13:31:35
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.232 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 09:31:00.628750 2026] [security2:error] [pid 6796:tid 6796] [client 149.143.135.232:58617] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lawrencehale.com"] [uri "/.env.sample"] [unique_id "agMrlBYwrIJ8dG8QMvzCIwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-12 11:09:53
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.232 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 07:09:48.125812 2026] [security2:error] [pid 14389:tid 14389] [client 149.143.135.232:51493] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "r-390.com"] [uri "/.git/objects/"] [unique_id "agMKfBcPJTCa5jUhyMNMJwAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-10 18:13:06
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.232 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 14:12:40.548902 2026] [security2:error] [pid 26100:tid 26100] [client 149.143.135.232:41233] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.jamelrobinson.com"] [uri "/.env.local"] [unique_id "agDKmFntlNBW1y_ubehhZgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-09 09:02:18
(4 months ago)
(caddyscan) Scanner path probe from 149.143.135.232 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 149.143.135.232 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 0 149.143.135.232 - - [09/May/2026:08:15:57 +0000] "HEAD /.aws/config HTTP/1.1"
[REDACTED] 200 2627 149.143.135.232 - - [09/May/2026:08:15:58 +0000] "GET /.env.prod HTTP/1.1"
[REDACTED] 200 2627 149.143.135.232 - - [09/May/2026:08:15:59 +0000] "GET /.env.staging HTTP/1.1"
[REDACTED] 200 2627 149.143.135.232 - - [09/May/2026:09:02:05 +0000] "GET /.DS_Store HTTP/1.1"
[REDACTED] 200 2627 149.143.135.232 - - [09/May/2026:09:02:15 +0000] "GET /.env.20240601 HTTP/1.1"
show less
Port Scan
๐บ๐ธ
Charlesiv
2026-05-08 04:01:15
(4 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
ASN: 7029 (Windst ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
ASN: 7029 (Windstream Communications LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2026-05-08T02:55:54Z
Ray ID: 9f85302e6e977b59
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4 Safari/605.1.15
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-08 03:16:35
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 149.143.135.232 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 149.143.135.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 23:16:22.261891 2026] [security2:error] [pid 27117:tid 27160] [client 149.143.135.232:35959] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||support.reviewweaver.app|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "support.reviewweaver.app"] [uri "/database.sql"] [unique_id "af1VhpY3E_bWL4WxoVN_JQAAAdI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐ฝ
impra
2026-05-08 00:51:25
(4 months ago)
Detected 10 connection attempts across 2 ports.
Port Scan
Hacking
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-05-05 06:47:01
(4 months ago)
Unidentified crawler ignoring robots.txt: 149.143.135.232 - - [05/May/2026:08:46:53 +0200] "GET /con ...
show more
Unidentified crawler ignoring robots.txt: 149.143.135.232 - - [05/May/2026:08:46:53 +0200] "GET /console HTTP/1.1" 301 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:124.0) Gecko/20100101 Firefox/124.0" asn=7029 org="Windstream Communications LLC"
149.143.135.232 - - [05/May/2026:08:46:53 +0200] "GET / HTTP/1.1" 403 564 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36" asn=7029 org="Windstream Communications LLC"
149.143.135.232 - - [05/May/2026:08:46:53 +0200] "GET /.gitconfig HTTP/1.1" 404 564 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36" asn=7029 org="Windstream Communications LLC"
...
show less
Bad Web Bot