πΊπΈ
TPI-Abuse
2026-05-18 06:21:12
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.243 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 18 02:21:07.368044 2026] [security2:error] [pid 22298:tid 22324] [client 149.143.135.243:58397] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.theextraordinaryoffice.monopostoyachts.com"] [uri "/.git/config"] [unique_id "agqv06jIm-7Gi15J1KWLiAAAAJg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-17 13:04:32
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.243 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 09:04:02.626010 2026] [security2:error] [pid 13606:tid 13606] [client 149.143.135.243:35695] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "schoolsliaisoncommunity.net"] [uri "/.htpasswd"] [unique_id "agm8wozx-Lgfv_gImqL2BAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-15 08:48:33
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.243 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:48:21.723436 2026] [security2:error] [pid 7869:tid 7869] [client 149.143.135.243:47453] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cthog.xyz"] [uri "/.git/config"] [unique_id "agbd1czzIH1k3YSSzTF9pgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-15 08:26:35
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.243 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:26:23.409675 2026] [security2:error] [pid 1613:tid 1613] [client 149.143.135.243:39123] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kirbysheetmetalworks.kirbysmw.com"] [uri "/.env"] [unique_id "agbYr59f3Qv14OI3MSt5UwAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-15 08:03:54
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.243 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:03:02.785169 2026] [security2:error] [pid 11082:tid 11082] [client 149.143.135.243:49693] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amazinghydraulics.com"] [uri "/.env.dev"] [unique_id "agbTNlETFmlMSycwoYDqywAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-15 07:36:02
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.243 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 03:35:13.219594 2026] [security2:error] [pid 24788:tid 24788] [client 149.143.135.243:45895] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.truecontrarian.royal-barbershop.com"] [uri "/.git/objects/"] [unique_id "agbMsdHZnBcBR__b9KP84gAAAGg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-15 06:21:18
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.243 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 02:20:45.933857 2026] [security2:error] [pid 30008:tid 30008] [client 149.143.135.243:59469] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pleatpindrapes.sternscape.com"] [uri "/.git/objects/"] [unique_id "aga7PQvb2t32N_JwyqCJjAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-14 07:48:45
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 149.143.135.243 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 149.143.135.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 03:48:26.405458 2026] [security2:error] [pid 14735:tid 14735] [client 149.143.135.243:46285] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mdp-interiors.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mdp-interiors.com"] [uri "/db.sql"] [unique_id "agV-SmaQJQKPj-wwv6wyJQAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-13 08:48:51
(3 months ago)
(caddyscan) Scanner path probe from 149.143.135.243 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 149.143.135.243 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 149.143.135.243 - - [13/May/2026:07:56:41 +0000] "GET /.env.dev HTTP/1.1"
[REDACTED] 200 2627 149.143.135.243 - - [13/May/2026:08:07:31 +0000] "GET /.env.old HTTP/1.1"
[REDACTED] 200 2627 149.143.135.243 - - [13/May/2026:08:07:31 +0000] "GET /root/.aws/config HTTP/1.1"
[REDACTED] 200 0 149.143.135.243 - - [13/May/2026:08:38:01 +0000] "HEAD /wp-config.php.bak HTTP/1.1"
[REDACTED] 200 0 149.143.135.243 - - [13/May/2026:08:48:49 +0000] "HEAD /.aws/credentials HTTP/1.1"
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-05-12 20:37:46
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.243 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 16:37:26.852272 2026] [security2:error] [pid 13943:tid 13943] [client 149.143.135.243:34795] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "urie.to.daveewalker.bz"] [uri "/.env.production"] [unique_id "agOPhl_9DSmYKSDq2MNA-gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-12 19:48:54
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.243 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 15:48:33.973531 2026] [security2:error] [pid 32051:tid 32051] [client 149.143.135.243:60519] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.vid.com"] [uri "/.env.production"] [unique_id "agOEEdwDuKkFY0HXr7rk_AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-12 12:46:17
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.243 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 08:45:46.829957 2026] [security2:error] [pid 19202:tid 19202] [client 149.143.135.243:50223] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sheamar.com"] [uri "/.env.old"] [unique_id "agMg-nTrjrCb9ke2W6iFnQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-05-12 02:13:32
(3 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-11 04:52:28
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.243 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 00:52:12.137286 2026] [security2:error] [pid 31194:tid 31194] [client 149.143.135.243:40111] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pizzadata.com"] [uri "/.env.test"] [unique_id "agFgfP7uX8C7chdk295vngAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-10 01:30:33
(3 months ago)
(caddyscan) Scanner path probe from 149.143.135.243 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 149.143.135.243 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 0 149.143.135.243 - - [10/May/2026:01:30:26 +0000] "HEAD /.aws/config HTTP/1.1"
[REDACTED] 200 0 149.143.135.243 - - [10/May/2026:01:30:26 +0000] "HEAD /.aws/credentials HTTP/1.1"
[REDACTED] 200 0 149.143.135.243 - - [10/May/2026:01:30:26 +0000] "HEAD /.env.example HTTP/1.1"
[REDACTED] 200 0 149.143.135.243 - - [10/May/2026:01:30:30 +0000] "HEAD /api/.env HTTP/1.1"
[REDACTED] 200 2627 149.143.135.243 - - [10/May/2026:01:30:31 +0000] "GET /.env.vault HTTP/1.1"
show less
Port Scan