πΊπΈ
TPI-Abuse
2026-06-19 19:14:30
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 172.69.130.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.69.130.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 15:14:22.219821 2026] [security2:error] [pid 11471:tid 11471] [client 172.69.130.19:13571] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.acraloc.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.acraloc.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "ajWVDkTPRPTXA3OGokOtuAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π²π½
octageeks.com
2026-06-10 04:35:02
(1 week ago)
Wordpress malicious attack:[octaflood]
Web App Attack
πΊπΈ
mnsf
2026-06-09 07:05:11
(1 week ago)
Abuse Detected (1)
Brute-Force
Web App Attack
Anonymous
2026-06-09 00:01:40
(1 week ago)
Web App Attack
Brute-Force
Web App Attack
πΊπΈ
mnsf
2026-06-04 18:05:15
(2 weeks ago)
Abuse Detected (1)
Brute-Force
Web App Attack
πΊπΈ
mnsf
2026-06-04 12:05:52
(2 weeks ago)
Abuse Detected (2)
Brute-Force
Web App Attack
Anonymous
2026-05-21 18:42:55
(4 weeks ago)
Web App Attack
Brute-Force
Web App Attack
π«π·
chengkev
2026-05-12 02:51:46
(1 month ago)
Esta IP fue detectada por CrowdSec, activando crowdsecurity/http-probing
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-04-08 11:55:22
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 07:55:01.121840 2026] [security2:error] [pid 2599460:tid 2599460] [client 172.69.130.19:10786] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "psicotanato.com.mx.elpais.mx"] [uri "/.env.save"] [unique_id "adZCFb8mPwpBwCbRce4dYgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-08 05:50:06
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 01:50:00.164602 2026] [security2:error] [pid 1943724:tid 1943724] [client 172.69.130.19:13969] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.cmcnow.net"] [uri "/.env.old"] [unique_id "adXsiOo79_5NmKJZhWiLagAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π¦
yukon.ca
2026-04-07 07:25:41
(2 months ago)
Web Server Enforcement Violation: ALFA Webshell Over HTTP
Port:80
Hacking
Exploited Host
πΊπΈ
TPI-Abuse
2026-04-07 00:17:16
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 20:17:10.860033 2026] [security2:error] [pid 1298868:tid 1298887] [client 172.69.130.19:12239] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "besfixedwireless.com.exede-sales.com"] [uri "/.env.staging"] [unique_id "adRNBlCqcWKh3sBuKFopfwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-06 17:53:17
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 13:53:13.194326 2026] [security2:error] [pid 214460:tid 214460] [client 172.69.130.19:13413] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.usashooters.gemexpressions.com"] [uri "/.env.local"] [unique_id "adPzCcYFxx3Y628hCj1a-AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-06 13:23:57
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 09:23:50.957427 2026] [security2:error] [pid 104298:tid 104298] [client 172.69.130.19:10322] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "asapstarsmogcheck.com"] [uri "/backend/.env"] [unique_id "adOz5kkjS8YnsYRS8femGAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-06 10:00:31
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 06:00:19.496313 2026] [security2:error] [pid 24806:tid 24806] [client 172.69.130.19:10965] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.mvscouts.org"] [uri "/.env.local"] [unique_id "adOEMysCaAt-j66aTcJXWQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack