๐บ๐ธ
TPI-Abuse
2026-05-16 11:22:08
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 149.143.136.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 149.143.136.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 07:21:59.072239 2026] [security2:error] [pid 9267:tid 9267] [client 149.143.136.217:55333] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kikisfriends.truefauxstudio.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kikisfriends.truefauxstudio.com"] [uri "/database.sql"] [unique_id "aghTVyJMz6BEEdKTuZXxagAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-16 10:26:35
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.136.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.136.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 06:26:29.263752 2026] [security2:error] [pid 6321:tid 6321] [client 149.143.136.217:44697] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ctjcisenate.org"] [uri "/.env"] [unique_id "aghGVfO69wrcJ99BznqVKgAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 15:19:43
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 149.143.136.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 149.143.136.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 11:19:38.013959 2026] [security2:error] [pid 12755:tid 12755] [client 149.143.136.217:54465] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ctemdr.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ctemdr.com"] [uri "/dump.sql"] [unique_id "agc5ikPGKYWJ8ovqaSBd0wAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 09:00:07
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 149.143.136.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 149.143.136.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:59:09.626426 2026] [security2:error] [pid 10344:tid 10344] [client 149.143.136.217:60461] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||brookspowell.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brookspowell.com"] [uri "/backup.sql"] [unique_id "agbgXetCulyuze_YHt6a4AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 08:24:12
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.136.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.136.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:23:35.818201 2026] [security2:error] [pid 17814:tid 17814] [client 149.143.136.217:47083] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rememberingjohnhanson.com"] [uri "/.git/config"] [unique_id "agbYB4T-V5zorIEG56GtwwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 08:01:44
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.136.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.136.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:01:28.222948 2026] [security2:error] [pid 20494:tid 20494] [client 149.143.136.217:39437] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "macro-astrology.com"] [uri "/.env.staging.local"] [unique_id "agbS2HwNl3BhqF369_3nYgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 06:41:40
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.136.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.136.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 02:41:11.386663 2026] [security2:error] [pid 23143:tid 23143] [client 149.143.136.217:55057] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gods-law.com"] [uri "/.env.old"] [unique_id "agbAB4WRU2-CG2WbYqGITwAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-13 08:49:06
(3 months ago)
(caddyscan) Scanner path probe from 149.143.136.217 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 149.143.136.217 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 149.143.136.217 - - [13/May/2026:08:09:30 +0000] "GET /.env.bak HTTP/1.1"
[REDACTED] 200 2627 149.143.136.217 - - [13/May/2026:08:09:30 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 149.143.136.217 - - [13/May/2026:08:42:25 +0000] "GET /.env.default HTTP/1.1"
[REDACTED] 200 0 149.143.136.217 - - [13/May/2026:08:48:51 +0000] "HEAD /.env.local HTTP/1.1"
[REDACTED] 200 2627 149.143.136.217 - - [13/May/2026:08:49:04 +0000] "GET /.env.staging.local HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-12 13:53:42
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.136.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.136.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 09:52:37.552223 2026] [security2:error] [pid 12301:tid 12301] [client 149.143.136.217:56881] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "keepaustinnuts.com"] [uri "/.env.stage"] [unique_id "agMwpZJQnDjSatW2yB9mDwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-05-12 12:10:12
(3 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-09 01:39:17
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.136.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.136.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 21:39:02.122666 2026] [security2:error] [pid 22102:tid 22102] [client 149.143.136.217:58417] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "honeybeeplace.com.garyrankin.com"] [uri "/.env.prod"] [unique_id "af6QNiuEzy5pFE1XVH5UTQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-08 23:38:11
(3 months ago)
(caddyscan) Scanner path probe from 149.143.136.217 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 149.143.136.217 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 370532wildcardprobe-1777277546133932182.bicities.org 200 0 149.143.136.217 - - [08/May/2026:23:16:34 +0000] "HEAD /backend/.env HTTP/1.1"
87660426042wildcardprobe-1777273106015408056.bicities.org 200 2627 149.143.136.217 - - [08/May/2026:23:21:06 +0000] "GET /.env.sample HTTP/1.1"
990754370532wildcardprobe-1777020811057846024.bicities.org 200 2627 149.143.136.217 - - [08/May/2026:23:23:27 +0000] "GET /.env.secret HTTP/1.1"
0866042200.wildcardprobe-1777273075586940549.bicities.org 200 2627 149.143.136.217 - - [08/May/2026:23:38:09 +0000] "GET /.git/config HTTP/1.1"
0866042200.wildcardprobe-1777273075586940549.bicities.org 200 0 149.143.136.217 - - [08/May/2026:23:38:09 +0000] "HEAD /.env.old HTTP/1.1"
show less
Port Scan
๐บ๐ธ
Charlesiv
2026-05-08 04:01:17
(3 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 7029 (Windstream Communi ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 7029 (Windstream Communications LLC)
Protocol: HTTP/1.1 (HEAD method)
Endpoint: /wp-config.php.bak
Timestamp: 2026-05-08T02:55:54Z
Ray ID: 9f85302eb80b0800
UA: Mozilla/5.0 (X11; Linux x86_64; rv:125.0) Gecko/20100101 Firefox/125.0
show less
Bad Web Bot
๐บ๐ธ
mnsf
2026-05-06 10:05:57
(3 months ago)
Scanning/Probing (23)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-06 08:07:11
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.136.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.136.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 06 04:06:47.162742 2026] [security2:error] [pid 24063:tid 24063] [client 149.143.136.217:34057] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "haywardcarpentry.com"] [uri "/.env~"] [unique_id "afr2l--Ormg2-WzFeg6SCwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack