๐บ๐ธ
TPI-Abuse
2026-06-09 17:58:17
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 172.69.214.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.69.214.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 13:58:12.476133 2026] [security2:error] [pid 11441:tid 11441] [client 172.69.214.30:13847] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.dudleyanddudley.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.dudleyanddudley.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "aihUNHGFgPhAQYP6hmUt-AAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
dyln
2026-05-28 17:12:01
(3 weeks ago)
Dyls honeypot brute-force: proto8 (135 total hits)
Brute-Force
Anonymous
2026-05-14 06:27:43
(1 month ago)
Web App Attack
Brute-Force
Web App Attack
๐ฉ๐ช
Blexyel
2026-05-10 04:23:16
(1 month ago)
172.69.214.30 - - [10/May/2026:06:23:15 +0200] "GET /wp-includes/SimplePie/wp-login.php HTTP/1.1" 30 ...
show more
172.69.214.30 - - [10/May/2026:06:23:15 +0200] "GET /wp-includes/SimplePie/wp-login.php HTTP/1.1" 301 169 "-" "-" "136.243.2.38"
...
show less
Brute-Force
Web App Attack
๐ณ๐ด
noteng.no
2026-04-13 22:52:39
(2 months ago)
2026/04/14 00:52:12 [error] 1036041#1036041: *861535 open() "/var/www/html/wp-admin.php" failed (2: ...
show more
2026/04/14 00:52:12 [error] 1036041#1036041: *861535 open() "/var/www/html/wp-admin.php" failed (2: No such file or directory), client: 172.69.214.30, server: eval.noteng.no, request: "GET /wp-admin.php HTTP/1.1", host: "eval.noteng.no"
2026/04/14 00:52:15 [error] 1036041#1036041: *861535 open() "/var/www/html/wp-signup.php" failed (2: No such file or directory), client: 172.69.214.30, server: eval.noteng.no, request: "GET /wp-signup.php? HTTP/1.1", host: "eval.noteng.no"
2026/04/14 00:52:38 [error] 1036041#1036041: *861535 open() "/var/www/html/mailer.php" failed (2: No such file or directory), client: 172.69.214.30, server: eval.noteng.no, request: "GET /mailer.php HTTP/1.1", host: "eval.noteng.no"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-04-08 08:20:00
(2 months ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 22:58:43
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 18:58:37.848629 2026] [security2:error] [pid 4484:tid 4484] [client 172.69.214.30:13328] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.wildemar.info"] [uri "/.env_secret"] [unique_id "adLpHVT7zSxVXNYDNTjdNwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 23:05:15
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 19:05:08.431767 2026] [security2:error] [pid 29810:tid 29810] [client 172.69.214.30:12990] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "powerlinemultimedia.net"] [uri "/.env.local"] [unique_id "adGZJJDZMeRRvPXyFz4PlwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 19:44:32
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 15:44:25.055972 2026] [security2:error] [pid 10621:tid 10621] [client 172.69.214.30:10696] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.schrankhome.com"] [uri "/.env_settings"] [unique_id "adFqGbp_3aMQlkvE6fkn2AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 16:23:56
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 12:23:51.917153 2026] [security2:error] [pid 7245:tid 7245] [client 172.69.214.30:12721] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.burke698.org.nilestree.com"] [uri "/server/.env"] [unique_id "adE7FwkM7Lgqk8hAWgZqugAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 13:41:31
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 09:41:27.117524 2026] [security2:error] [pid 22923:tid 23032] [client 172.69.214.30:10128] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.boxwoodgarden.com"] [uri "/.env.dist"] [unique_id "adEVB855JaV7D4JDZAvt2wAAAVI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 13:21:53
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 09:21:45.750442 2026] [security2:error] [pid 31152:tid 31152] [client 172.69.214.30:9545] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "watersideaccommodation.com"] [uri "/.env.production.bak"] [unique_id "adEQaWnM1ytGj5ISYqn_ewAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 10:57:05
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 06:56:56.660721 2026] [security2:error] [pid 4966:tid 4966] [client 172.69.214.30:12109] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.hcadwin.com"] [uri "/.env.json"] [unique_id "adDueFWuQrQUXnYGW03LjwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 10:35:43
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 06:35:40.053448 2026] [security2:error] [pid 11867:tid 11867] [client 172.69.214.30:11545] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bluemarineboats.com"] [uri "/.env.local"] [unique_id "adDpfMiz_J78qlE39CVwXQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 08:50:36
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 04:50:28.044311 2026] [security2:error] [pid 9257:tid 9257] [client 172.69.214.30:11753] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.register-yacht-dubai.com"] [uri "/.env.dev"] [unique_id "adDQ1K9TVqpYyM15hhZoOAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack