๐บ๐ธ
TPI-Abuse
2026-05-20 20:02:57
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 149.143.137.38 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 149.143.137.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 16:02:47.300227 2026] [security2:error] [pid 26531:tid 26531] [client 149.143.137.38:47275] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||panesarlaw.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "panesarlaw.com"] [uri "/backup.sql"] [unique_id "ag4TZ_hVRAZLtBL-tySgMgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 10:26:39
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.137.38 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.137.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 06:26:23.403109 2026] [security2:error] [pid 26924:tid 26924] [client 149.143.137.38:49197] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cffragrances.iee-usa.com"] [uri "/.env.old"] [unique_id "agb0z6g9syRSnrSRau1S9AAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 08:20:06
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.137.38 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.137.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:19:57.784674 2026] [security2:error] [pid 14705:tid 14705] [client 149.143.137.38:49433] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "deniz-bilgisayar.com"] [uri "/.git/config"] [unique_id "agbXLXyVScozbnLVJ6Z1zQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 07:31:51
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 149.143.137.38 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 149.143.137.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 03:31:34.939932 2026] [security2:error] [pid 28341:tid 28341] [client 149.143.137.38:40335] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||boens.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "boens.org"] [uri "/wp-content/mysql.sql"] [unique_id "agbL1ssCoOI6U0NsGqG9bwAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 06:43:37
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 149.143.137.38 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 149.143.137.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 02:42:53.810541 2026] [security2:error] [pid 14379:tid 14379] [client 149.143.137.38:46629] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||callahan-co.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "callahan-co.com"] [uri "/dump.sql"] [unique_id "agbAbcTghV1voMsFDBFMWwAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 06:21:06
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.137.38 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.137.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 02:19:11.724153 2026] [security2:error] [pid 24994:tid 24994] [client 149.143.137.38:50423] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blanchebb.com"] [uri "/.env.secret"] [unique_id "aga636eX4IL1-nKA9MrJ4AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-14 07:49:10
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.137.38 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.137.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 03:48:50.782207 2026] [security2:error] [pid 16500:tid 16500] [client 149.143.137.38:39269] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mdp-interiors.com"] [uri "/.env.2"] [unique_id "agV-Ysk99_NHOFBgS31RpwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-12 20:35:28
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.137.38 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.137.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 16:35:08.559281 2026] [security2:error] [pid 9050:tid 9050] [client 149.143.137.38:44635] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "atelier92.com"] [uri "/.env~"] [unique_id "agOO_CBl4moOMVA_00CLnwAAAD0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-12 16:45:56
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.137.38 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.137.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 12:45:35.183727 2026] [security2:error] [pid 3158:tid 3158] [client 149.143.137.38:57669] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.l3l4.com"] [uri "/.env.old"] [unique_id "agNZL_DpeXFb9o6Qz8zGPAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-12 13:53:54
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.137.38 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.137.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 09:52:18.984964 2026] [security2:error] [pid 12301:tid 12301] [client 149.143.137.38:53655] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "peanutcarvings.com"] [uri "/.env.bak"] [unique_id "agMwkpJQnDjSatW2yB9l-gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 10:57:24
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.137.38 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.137.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 06:57:10.751380 2026] [security2:error] [pid 5525:tid 5539] [client 149.143.137.38:44605] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.realitybytes.us.mailporte.com"] [uri "/.env"] [unique_id "agG2Bttcma20ptefJmaeOQAAAMs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 04:52:38
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 149.143.137.38 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 149.143.137.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 00:52:12.134314 2026] [security2:error] [pid 31197:tid 31197] [client 149.143.137.38:40421] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pizzadata.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pizzadata.com"] [uri "/backup.sql"] [unique_id "agFgfPcz1T6aKXkos5PnMAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
derester
2026-05-10 22:36:04
(3 months ago)
Forwarded traffic flood detected by MikroTik (threshold: >100 new connections/s, burst 1)
DDoS Attack
Anonymous
2026-05-09 23:25:28
(3 months ago)
(caddyscan) Scanner path probe from 149.143.137.38 (US/United States/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 149.143.137.38 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 0 149.143.137.38 - - [09/May/2026:22:49:34 +0000] "HEAD /backend/.env HTTP/1.1"
[REDACTED] 200 2627 149.143.137.38 - - [09/May/2026:23:25:26 +0000] "GET /.env.live HTTP/1.1"
[REDACTED] 200 2627 149.143.137.38 - - [09/May/2026:23:25:26 +0000] "GET /.env.uat HTTP/1.1"
[REDACTED] 200 2627 149.143.137.38 - - [09/May/2026:23:25:26 +0000] "GET /.env.dev HTTP/1.1"
[REDACTED] 200 2627 149.143.137.38 - - [09/May/2026:23:25:26 +0000] "GET /.env.backup HTTP/1.1"
show less
Port Scan
Anonymous
2026-05-09 13:44:04
(3 months ago)
(caddyscan) Scanner path probe from 149.143.137.38 (US/United States/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 149.143.137.38 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 149.143.137.38 - - [09/May/2026:12:47:54 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 149.143.137.38 - - [09/May/2026:12:47:54 +0000] "GET /phpMyAdmin/ HTTP/1.1"
[REDACTED] 200 2627 149.143.137.38 - - [09/May/2026:12:47:54 +0000] "GET /.git/HEAD HTTP/1.1"
[REDACTED] 200 2627 149.143.137.38 - - [09/May/2026:13:44:00 +0000] "GET /.aws/credentials HTTP/1.1"
[REDACTED] 200 2627 149.143.137.38 - - [09/May/2026:13:44:00 +0000] "GET /.env.txt HTTP/1.1"
show less
Port Scan