๐ง๐ช
madeit
2026-09-23 16:03:17
(18 hours ago)
Web App Attack
Anonymous
2026-09-01 18:04:11
(3 weeks ago)
[Tue Sep 01 20:04:00.932095 2026] [authz_core:error] [pid 27703] [client 172.69.214.27:11174] AH0163 ...
show more
[Tue Sep 01 20:04:00.932095 2026] [authz_core:error] [pid 27703] [client 172.69.214.27:11174] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Sep 01 20:04:01.084649 2026] [authz_core:error] [pid 27703] [client 172.69.214.27:11174] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Sep 01 20:04:10.820996 2026] [authz_core:error] [pid 26216] [client 172.69.214.27:11606] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐ง๐ช
madeit
2026-08-29 00:57:39
(3 weeks ago)
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-07-30 02:09:57
(1 month ago)
172.69.214.27 - - [30/Jul/2026:05:09:55 +0300] "GET /wp-comments-post.php HTTP/1.1" 302 4726 "-" "Mo ...
show more
172.69.214.27 - - [30/Jul/2026:05:09:55 +0300] "GET /wp-comments-post.php HTTP/1.1" 302 4726 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.69.214.27 - - [30/Jul/2026:05:09:56 +0300] "GET /wp-cron.php HTTP/1.1" 302 789 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 17:32:28
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 172.69.214.27 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.69.214.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 13:32:24.773529 2026] [security2:error] [pid 26441:tid 26441] [client 172.69.214.27:13444] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.shepherdsgroup.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.shepherdsgroup.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "al-tKAAa9izzUffmZROpEgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-04 00:21:07
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 172.69.214.27 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.69.214.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 20:21:03.546788 2026] [security2:error] [pid 19440:tid 19440] [client 172.69.214.27:9983] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.digitalcontraptionlabs.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.digitalcontraptionlabs.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "akhR77FuZTMhs8Ft0bxgZQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 02:54:16
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.27 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 22:54:11.557531 2026] [security2:error] [pid 15579:tid 15579] [client 172.69.214.27:9866] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.gurneysbottleshop.com"] [uri "/api/.env"] [unique_id "adHO04W1aePoJhMfy-JnKAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 01:40:46
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.27 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 21:40:30.685039 2026] [security2:error] [pid 22621:tid 22621] [client 172.69.214.27:10841] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michalovic.org"] [uri "/.env.development.local"] [unique_id "adG9jo7ExvjON5j1KdwWxwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 22:34:56
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.27 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 18:34:49.220572 2026] [security2:error] [pid 5667:tid 5667] [client 172.69.214.27:10174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.hisim.com.tr"] [uri "/.env~"] [unique_id "adGSCa2qOTSrQfXqsT1OWgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 22:13:51
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.27 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 18:13:41.172329 2026] [security2:error] [pid 6484:tid 6484] [client 172.69.214.27:11468] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.tekbit.com"] [uri "/.env"] [unique_id "adGNFRuAVsskRmPHdIEx1gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 15:12:57
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.27 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 11:12:52.396215 2026] [security2:error] [pid 2931:tid 2931] [client 172.69.214.27:11428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elpais.mx"] [uri "/.env.container"] [unique_id "adEqdNyxSDVaIp2Miv45FgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 13:53:14
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.27 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 09:53:09.073720 2026] [security2:error] [pid 8112:tid 8112] [client 172.69.214.27:12771] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.printpackcomplete.com"] [uri "/.env.production"] [unique_id "adEXxU2wUSgKQIHmG873zAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 13:27:33
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.27 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 09:27:24.123808 2026] [security2:error] [pid 16093:tid 16093] [client 172.69.214.27:10053] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.assheton.com"] [uri "/.env.backup"] [unique_id "adERvMP60f8mM6OCyTUwgwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 10:56:06
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.27 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 06:55:57.680532 2026] [security2:error] [pid 4970:tid 4970] [client 172.69.214.27:14118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.hcadwin.com"] [uri "/.env.local"] [unique_id "adDuPVqS51tsjt-03-fY0AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 10:29:38
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.27 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 06:29:34.320283 2026] [security2:error] [pid 20035:tid 20035] [client 172.69.214.27:10611] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ggisoft.com"] [uri "/home/.env"] [unique_id "adDoDleB33fa4Rnc2JN6ogAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack