๐ง๐ช
madeit
2026-08-23 00:41:54
(3 days ago)
Web App Attack
Anonymous
2026-08-16 13:50:42
(1 week ago)
(caddyscan) Scanner path probe from 172.69.130.84 (CA/Canada/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 172.69.130.84 (CA/Canada/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 172.69.130.84 - - [16/Aug/2026:13:50:40 +0000] "GET /wp-admin/js/widgets HTTP/1.1"
[REDACTED] 200 2627 172.69.130.84 - - [16/Aug/2026:13:50:41 +0000] "GET /wp-admin/css HTTP/1.1"
[REDACTED] 200 2627 172.69.130.84 - - [16/Aug/2026:13:50:41 +0000] "GET /wp-admin/includes HTTP/1.1"
[REDACTED] 200 2627 172.69.130.84 - - [16/Aug/2026:13:50:41 +0000] "GET /wp-admin/classwithtostring.php HTTP/1.1"
[REDACTED] 200 2627 172.69.130.84 - - [16/Aug/2026:13:50:41 +0000] "GET /wp-admin/css/colors/modern HTTP/1.1"
show less
Port Scan
๐บ๐ธ
mawan
2026-07-13 05:51:02
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
mnsf
2026-06-09 07:06:04
(2 months ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-09 05:15:53
(2 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐จ๐ฆ
polycoda
2026-04-08 03:48:23
(4 months ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ Excessive 40X Errors (Decay-Based)
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 04:31:38
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 00:31:35.038705 2026] [security2:error] [pid 893657:tid 893657] [client 172.69.130.84:10126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.willmarksynthetics.com"] [uri "/.git/index"] [unique_id "adSIp3FXUm70MuoPd_f2oAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 13:10:57
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 09:10:51.731873 2026] [security2:error] [pid 30272:tid 30272] [client 172.69.130.84:14314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "benchmarkbcs.com"] [uri "/.env.save"] [unique_id "adOw2wAVTAbHCHvPOyVFAwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 10:07:59
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 06:07:43.529489 2026] [security2:error] [pid 15442:tid 15442] [client 172.69.130.84:13816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "batchovens.net.daveweisman.com"] [uri "/.env.development"] [unique_id "adI0b2_00dgQnic1w8Lu0wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 05:51:22
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 01:51:18.919135 2026] [security2:error] [pid 19351:tid 19351] [client 172.69.130.84:10289] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vaxd.cs-mall.com"] [uri "/site/.env"] [unique_id "adH4VsDfV1M3Jyd9F5nCxwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 21:48:28
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 17:48:20.288418 2026] [security2:error] [pid 6303:tid 6303] [client 172.69.130.84:10880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "greatwesternfirearms.deubellzebub.com"] [uri "/.env.production.bak"] [unique_id "adGHJE7wxMCUpwm2cxeeNAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 16:44:25
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 12:44:17.675290 2026] [security2:error] [pid 30591:tid 30591] [client 172.69.130.84:11433] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.southsideaccountingservices.com"] [uri "/.env"] [unique_id "adE_4VD3TObRdvLHNYAq7AAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 13:28:29
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 09:28:21.120766 2026] [security2:error] [pid 1089:tid 1089] [client 172.69.130.84:14279] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.emmtrucking.com"] [uri "/.env.production"] [unique_id "adER9c_6tdPDzWTOqmDk1wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 13:08:34
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 09:08:27.567987 2026] [security2:error] [pid 28803:tid 28803] [client 172.69.130.84:12203] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.imbrasacademic.bridgital.com"] [uri "/.env.old"] [unique_id "adENS3xynXpr3jKMH_ycPwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 09:36:37
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 05:36:32.774040 2026] [security2:error] [pid 1233:tid 1242] [client 172.69.130.84:11590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.siraceservices.com"] [uri "/.env2"] [unique_id "adDboEHVMthDOo07TUfLzwAAAIE"]
show less
Brute-Force
Bad Web Bot
Web App Attack