๐บ๐ธ
TPI-Abuse
2026-07-20 13:54:59
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 172.69.214.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.69.214.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 09:54:52.829888 2026] [security2:error] [pid 20793:tid 20793] [client 172.69.214.138:24994] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.caferutadelaseda.com|F|2"] [data "[email protected] "] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.caferutadelaseda.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "al4orDHhgCyir-yQw-YHqwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-01 12:55:30
(3 weeks ago)
172.69.214.138 - - [01/Jul/2026:14:55:22 +0200] "GET /requirements%2eexample%2etxt HTTP/1.1" 403 124 ...
show more
172.69.214.138 - - [01/Jul/2026:14:55:22 +0200] "GET /requirements%2eexample%2etxt HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.69.214.138 - - [01/Jul/2026:14:55:22 +0200] "GET /drush/drush%2econf HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.69.214.138 - - [01/Jul/2026:14:55:23 +0200] "GET /mail/transport%2eenv HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.69.214.138 - - [01/Jul/2026:14:55:24 +0200] "GET /log/test%2ephp HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.69.214.138 - - [01/Jul/2026:14:55:24 +0200] "GET /staging/backend/%2eenv HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.69.214.138 - - [01/Jul/2026:14:55:25 +0200] "GET /actuator/mappings HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.69.214.138 - - [01/Jul/2026:14:55:26 +0200] "GET /api/new/db%2eenv HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.69.214.138 - - [01/Jul/2026:14:55:27 +0200] "GET /api/credentials%2eyml HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.69.214.138 - - [01/Jul/2026:14:55:27 +0200] "GET /config/db/settings%2eyml HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.69.214
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-11 06:05:43
(1 month ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐ฌ๐ง
sandra361
2026-05-28 07:11:04
(1 month ago)
Port scan detected: 19 attempts across 1 ports (443). | Evidence: REAPER_TARPIT:IN=enp1s0f0 OUT= SRC ...
show more
Port scan detected: 19 attempts across 1 ports (443). | Evidence: REAPER_TARPIT:IN=enp1s0f0 OUT= SRC=172.69.214.138 LEN=60 TOS=0x00 PREC=0x00 TTL=55 ID=40039 DF PROTO=TCP SPT=38733 DPT=443 WINDOW=65535 RES=0x00 SYN URGP=0
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-04-05 20:48:44
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 16:48:35.934417 2026] [security2:error] [pid 9661:tid 9661] [client 172.69.214.138:11355] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.nationalenq.com"] [uri "/.env.backup"] [unique_id "adLKoxWXY22aNwwtjzDpeQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 11:56:48
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 07:56:45.217968 2026] [security2:error] [pid 26187:tid 26187] [client 172.69.214.138:12575] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "parkplacemotel.modeltdr.com"] [uri "/.env.docker"] [unique_id "adJN_fumvRfVUGJoaOGeswAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 06:20:04
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 02:19:56.526737 2026] [security2:error] [pid 20572:tid 20572] [client 172.69.214.138:10149] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.noscentpro.com"] [uri "/private/.env"] [unique_id "adH_DNg9JxdQdiRvHtVHpQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 22:45:53
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 18:45:48.758137 2026] [security2:error] [pid 24387:tid 24387] [client 172.69.214.138:9536] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.globalvillagecambodia.org"] [uri "/config/.env.local"] [unique_id "adGUnJEx4YgD0N6GfYf20wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 21:02:14
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 17:02:09.307423 2026] [security2:error] [pid 15312:tid 15312] [client 172.69.214.138:10992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.noreservationslocations.com"] [uri "/.env"] [unique_id "adF8UScBAWCVAF7CAB-iyQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 19:45:14
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 15:45:09.763643 2026] [security2:error] [pid 12608:tid 12608] [client 172.69.214.138:12007] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.comsew.com.au"] [uri "/.git/refs/heads/master"] [unique_id "adFqRSTcwllvKBOvtC3zbwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 19:25:28
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 15:25:21.500952 2026] [security2:error] [pid 3050:tid 3050] [client 172.69.214.138:12698] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "limegreengirl.michaelward.com"] [uri "/.env.dev"] [unique_id "adFloYfx529kWz5gPgb5ewAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 14:43:10
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 10:42:58.527442 2026] [security2:error] [pid 4294:tid 4294] [client 172.69.214.138:10939] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.iconconstructors.com"] [uri "/.env.save"] [unique_id "adEjcrJJ_rDXE8S3qNZIqAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 10:56:06
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 06:55:59.298731 2026] [security2:error] [pid 20031:tid 20031] [client 172.69.214.138:12124] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.hcadwin.com"] [uri "/.env.backup"] [unique_id "adDuPyF798feByEy4uPMqAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 10:13:42
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 06:13:39.612384 2026] [security2:error] [pid 21000:tid 21000] [client 172.69.214.138:9388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.amoriotech.com"] [uri "/backend/.env"] [unique_id "adDkU3FnnEql30q0Is7wPQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 07:49:56
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 03:49:37.898187 2026] [security2:error] [pid 22686:tid 22686] [client 172.69.214.138:11265] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cloggersunlimited.com.joshuashands.org"] [uri "/.env.production.bak"] [unique_id "adDCkXOmQ4tg6VKaZ2b1zwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack