๐บ๐ธ
freeutka
2026-05-12 18:20:41
(1 month ago)
WordPress brute-force login attempt on wp-login.php.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-29 16:48:59
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.69.151.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.151.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 29 12:48:53.312632 2026] [security2:error] [pid 13580:tid 13580] [client 172.69.151.2:9311] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tvr77.garyrankin.com"] [uri "/.git/config"] [unique_id "afI2dX0u8o9NBmgDwmC_igAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-25 08:51:56
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.69.151.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.151.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 25 04:51:52.214314 2026] [security2:error] [pid 28006:tid 28006] [client 172.69.151.2:11994] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "evannine.com"] [uri "/.git/config"] [unique_id "aeyAqHHhEYPZBqVIBvPExAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-04-12 15:32:24
(2 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ณ๐ฑ
Site.eu
2026-04-06 04:32:11
(2 months ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-04-04 12:49:28
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.151.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.151.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 08:49:22.453027 2026] [security2:error] [pid 32290:tid 32290] [client 172.69.151.2:9749] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.salazartransfers.com"] [uri "/.git/refs/heads/main"] [unique_id "adEI0ltm00H0G-cGhYXI6QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 12:17:04
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.151.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.151.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 08:16:59.158983 2026] [security2:error] [pid 9098:tid 9098] [client 172.69.151.2:9372] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.bakerimaging.com"] [uri "/.git/refs/heads/main"] [unique_id "adEBO8tsCiVOQGG1ZPtHYAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
mondor.ro
2026-04-03 21:24:44
(2 months ago)
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 172.69.151.2, Reason:[ ...
show more
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 172.69.151.2, Reason:[(mod_security) mod_security (id:210492) triggered by 172.69.151.2 (DE/Germany/-): 3 in the last 3600 secs]; Ports: *; Direction: inout; Trigger: LF_CLUSTER; Logs:
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-04-03 19:22:39
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.151.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.151.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 15:22:23.954810 2026] [security2:error] [pid 8918:tid 8918] [client 172.69.151.2:13499] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.dougallbaillie.com"] [uri "/.env.dev"] [unique_id "adATb9IycfaTmbm-opwYcgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
grassau.com
2026-04-03 03:23:37
(2 months ago)
(mod_security) mod_security triggered on hostname [redacted] 172.69.151.2 (DE/Germany/Hesse/Frankfur ...
show more
(mod_security) mod_security triggered on hostname [redacted] 172.69.151.2 (DE/Germany/Hesse/Frankfurt am Main/-)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-04-03 02:05:11
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.151.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.151.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 22:05:00.543844 2026] [security2:error] [pid 11417:tid 11417] [client 172.69.151.2:13091] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.pr-professional.com"] [uri "/.git/refs/heads/master"] [unique_id "ac8gTE7ZaOz9XXhglnAj5wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-02 02:47:15
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.151.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.151.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 01 22:47:05.008657 2026] [security2:error] [pid 27231:tid 27257] [client 172.69.151.2:10523] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "certifiedpoliticalscientist.com.aafm.us"] [uri "/.git/logs/HEAD"] [unique_id "ac3Yqdy0o2Vazx18QyJv7gAAAQs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 03:11:43
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.151.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.151.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 23:11:37.248586 2026] [security2:error] [pid 32359:tid 32359] [client 172.69.151.2:13897] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.shipthunder.com"] [uri "/.env.save"] [unique_id "acs7aaB7FTKanHZmMCdxnwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-30 04:51:39
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.151.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.151.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 00:51:31.323400 2026] [security2:error] [pid 18004:tid 18004] [client 172.69.151.2:10366] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.jaspersplanet.com"] [uri "/.env.old"] [unique_id "acoBU_z6M56rPvs0O0gCgAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-29 23:56:30
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.151.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.151.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 29 19:56:24.670946 2026] [security2:error] [pid 30054:tid 30054] [client 172.69.151.2:10703] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.fables4teenagers.com"] [uri "/.env.tmp"] [unique_id "acm8KIbyQQ7pOztZ8ashZQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack