๐ซ๐ท
dynamix
2026-07-29 04:59:20
(1 hour ago)
Multiple WAF Violations
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-07-28 17:06:42
(13 hours ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐ฌ๐ง
sandra361
2026-05-26 03:58:01
(2 months ago)
Port scan detected: 7 attempts across 1 ports (443). | Evidence: GHOST_SCAN:IN=enp1s0f0 OUT= SRC=172 ...
show more
Port scan detected: 7 attempts across 1 ports (443). | Evidence: GHOST_SCAN:IN=enp1s0f0 OUT= SRC=172.69.214.127 LEN=60 TOS=0x00 PREC=0x00 TTL=55 ID=29927 DF PROTO=TCP SPT=13467 DPT=443 WINDOW=65535 RES=0x00 SYN URGP=0
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-04-05 16:08:31
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.127 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 12:08:24.490750 2026] [security2:error] [pid 25462:tid 25462] [client 172.69.214.127:12073] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.luciferdirective.com"] [uri "/.env.staging"] [unique_id "adKI-A7lDKPwj1VQ7mYLIQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 09:40:17
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.127 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 05:40:12.061151 2026] [security2:error] [pid 27395:tid 27395] [client 172.69.214.127:9691] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.electricmeatgrinder.com"] [uri "/.git/refs/heads/main"] [unique_id "adIt_IQ_bZu-UKg_zAI2GQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 06:21:02
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.127 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 02:20:54.378089 2026] [security2:error] [pid 21154:tid 21154] [client 172.69.214.127:13562] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.noscentpro.com"] [uri "/.envrc"] [unique_id "adH_RnSYNxxM3EVCRngg_gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 05:22:58
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.127 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 01:22:52.694299 2026] [security2:error] [pid 2595:tid 2595] [client 172.69.214.127:11987] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.gcigmbh.com"] [uri "/.env.development"] [unique_id "adHxrNMxmLScrnSzrkcVLQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 01:35:26
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.127 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 21:35:22.875482 2026] [security2:error] [pid 4139:tid 4139] [client 172.69.214.127:12728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.modernsalessolutions.com"] [uri "/.env.local.backup"] [unique_id "adG8Wi6gc0DNaQH2WPclKAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 23:01:06
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.127 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 19:01:00.408231 2026] [security2:error] [pid 23126:tid 23126] [client 172.69.214.127:11681] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rogerheath.com"] [uri "/.env.dev"] [unique_id "adGYLEp0R7BhXd3_QF2q-AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 19:41:56
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.127 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 15:41:53.236945 2026] [security2:error] [pid 3205:tid 3205] [client 172.69.214.127:11857] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.gapanda.com"] [uri "/.env.tmp"] [unique_id "adFpgYYWElIOZwN1QjSYhAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 19:24:12
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.127 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 15:24:07.433942 2026] [security2:error] [pid 3452:tid 3452] [client 172.69.214.127:11382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tunabay.com"] [uri "/backend/.env"] [unique_id "adFlV54dYFw9L20WkUuXDQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 17:46:39
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.127 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 13:46:32.121016 2026] [security2:error] [pid 26322:tid 26322] [client 172.69.214.127:9653] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.okeetokee.org"] [uri "/.env.old"] [unique_id "adFOeBg4CXy_46YOwiYAAAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 11:12:05
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.127 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 07:11:57.813247 2026] [security2:error] [pid 4077:tid 4077] [client 172.69.214.127:13954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.digitaltom.net"] [uri "/.env.prod"] [unique_id "adDx_RzfY1G-P9AISIVV4QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 09:22:28
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.127 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 05:22:17.284425 2026] [security2:error] [pid 3443:tid 3443] [client 172.69.214.127:9871] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.tortoisehosting.com"] [uri "/.env.backup"] [unique_id "adDYSaqSifhHj3MzbjjBbwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 09:06:51
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.127 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 05:06:47.150983 2026] [security2:error] [pid 32438:tid 32438] [client 172.69.214.127:13876] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.stpetersplayers.co.uk"] [uri "/.git/index"] [unique_id "adDUp8oSCfqlxlqSCiOoMAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack