๐บ๐ธ
TPI-Abuse
2026-07-29 07:20:12
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.69.71.43 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.71.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 03:20:03.318060 2026] [security2:error] [pid 3550124:tid 3550124] [client 172.69.71.43:12396] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aylinvictoria.com"] [uri "/.env.save"] [unique_id "ammpo2RAKTd7MZ1DO7sZcAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-07-25 02:10:15
(4 days ago)
[SatJul2504:10:07.7961672026][security2:error][pid1855442:tid1855519][client172.69.71.43:0]ModSecuri ...
show more
[SatJul2504:10:07.7961672026][security2:error][pid1855442:tid1855519][client172.69.71.43:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"labaita-lanzo.it.81-17-25-250.cpanel.site\"][uri\"/.env.save\"][unique_id\"amQa_5yF_oG-JCYrFwWt3wAAAAg\"]\,referer:https://www.google.com/search\?q=labaita-lanzo.it.81-17-25-250.cpanel.site
show less
Hacking
Web App Attack
๐บ๐ธ
mnsf
2026-06-17 00:08:12
(1 month ago)
Abuse Detected (2)
Brute-Force
Web App Attack
Anonymous
2026-06-07 19:44:29
(1 month ago)
invalid request
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-05-07 02:26:53
(2 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
myagent.site
2026-03-30 07:06:49
(3 months ago)
Blocking for trying to access an exploit file: /.env.php
Hacking
๐บ๐ธ
mnsf
2026-03-26 09:05:38
(4 months ago)
Scanning/Probing (16)
Brute-Force
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-03-24 07:50:25
(4 months ago)
172.69.71.43 - - [24/Mar/2026:09:50:07 +0200] "GET /wp-admin/ HTTP/1.1" 404 2869 "-" "Mozilla/5.0 (W ...
show more
172.69.71.43 - - [24/Mar/2026:09:50:07 +0200] "GET /wp-admin/ HTTP/1.1" 404 2869 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.69.71.43 - - [24/Mar/2026:09:50:24 +0200] "GET /wp-content/uploads/ HTTP/1.1" 404 2870 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ช๐ธ
el-brujo
2026-02-22 16:24:04
(5 months ago)
22/Feb/2026:17:24:04.246430 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
22/Feb/2026:17:24:04.246430 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 172.69.71.43] ModSecurity: Warning. Pattern match "(?:^|=)\\\\\\\\s*(?:{|\\\\\\\\s*\\\\\\\\(\\\\\\\\s*|\\\\\\\\w+=(?:[^\\\\\\\\s]*|\\\\\\\\$.*|\\\\\\\\$.*|<.*|>.*|\\\\\\\\'.*\\\\\\\\'|\\\\".*\\\\")\\\\\\\\s+|!\\\\\\\\s*|\\\\\\\\$)*\\\\\\\\s*(?:'|\\\\")*(?:[\\\\\\\\?\\\\\\\\*\\\\\\\\[\\\\\\\\]\\\\\\\\(\\\\\\\\)\\\\\\\\-\\\\\\\\|+\\\\\\\\w'\\\\"\\\\\\\\./\\\\\\\\\\\\\\\\]+/)?[\\\\\\\\\\\\\\\\'\\\\"]*(?:l[\\\\\\\\\\\\\\\\'\\\\"]*(?:s(?:[\\\\\\\\\\\\\\\\'\\\\"]*(?:b[\\\\\\\\\\\\\\\\'\\\\"]*_[\\\\\\\\\\\\\\\\'\\\\"]*r[\\\\\\\\\\\\\\\\'\\\\"]*e[\\\\\\\\\\\\\\\\'\\\\"]*l[\\\\\\\\\\\\\\\\' ..." at ARGS_NAMES:php echo esc_url(. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "464"] [id "932150"] [msg "Remote Command Execution: Direct Unix Command Execution"] [data "Matched Data: php found within ARGS_NAMES:php echo esc_url(: php echo esc_url("] [se
...
show less
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2026-02-22 03:39:36
(5 months ago)
22/Feb/2026:04:39:35.995318 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
22/Feb/2026:04:39:35.995318 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 172.69.71.43] ModSecurity: Warning. Pattern match "(?:^|=)\\\\\\\\s*(?:{|\\\\\\\\s*\\\\\\\\(\\\\\\\\s*|\\\\\\\\w+=(?:[^\\\\\\\\s]*|\\\\\\\\$.*|\\\\\\\\$.*|<.*|>.*|\\\\\\\\'.*\\\\\\\\'|\\\\".*\\\\")\\\\\\\\s+|!\\\\\\\\s*|\\\\\\\\$)*\\\\\\\\s*(?:'|\\\\")*(?:[\\\\\\\\?\\\\\\\\*\\\\\\\\[\\\\\\\\]\\\\\\\\(\\\\\\\\)\\\\\\\\-\\\\\\\\|+\\\\\\\\w'\\\\"\\\\\\\\./\\\\\\\\\\\\\\\\]+/)?[\\\\\\\\\\\\\\\\'\\\\"]*(?:l[\\\\\\\\\\\\\\\\'\\\\"]*(?:s(?:[\\\\\\\\\\\\\\\\'\\\\"]*(?:b[\\\\\\\\\\\\\\\\'\\\\"]*_[\\\\\\\\\\\\\\\\'\\\\"]*r[\\\\\\\\\\\\\\\\'\\\\"]*e[\\\\\\\\\\\\\\\\'\\\\"]*l[\\\\\\\\\\\\\\\\' ..." at ARGS_NAMES:php echo esc_url( add_query_arg( 'get-post-lock', '1', wp_nonce_url( get_edit_post_link( $post->ID, 'url' ), 'lock-post_' . $post->ID ) ) ); ?>. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "464"] [id "932150"] [msg "Remote Command Execution
...
show less
Hacking
Web App Attack
๐บ๐ธ
chrisj
2026-02-12 11:01:06
(5 months ago)
[Thu Feb 12 11:01:04.385212 2026] [proxy_fcgi:error] [pid 737018:tid 737018] [client 172.69.71.43:93 ...
show more
[Thu Feb 12 11:01:04.385212 2026] [proxy_fcgi:error] [pid 737018:tid 737018] [client 172.69.71.43:9386] AH01071: Got error 'Primary script unknown', referer: http://devel.vandogh.com/ahax.php
[Thu Feb 12 11:01:04.496854 2026] [proxy_fcgi:error] [pid 737018:tid 737018] [client 172.69.71.43:9386] AH01071: Got error 'Primary script unknown', referer: http://devel.vandogh.com/php8.php#xleet
[Thu Feb 12 11:01:05.671255 2026] [proxy_fcgi:error] [pid 737018:tid 737018] [client 172.69.71.43:9386] AH01071: Got error 'Primary script unknown', referer: http://devel.vandogh.com/ioxi-o.php
...
show less
Brute-Force
Anonymous
2025-12-16 00:53:39
(7 months ago)
[Tue Dec 16 01:53:36.083621 2025] [authz_core:error] [pid 24872] [client 172.69.71.43:12638] AH01630 ...
show more
[Tue Dec 16 01:53:36.083621 2025] [authz_core:error] [pid 24872] [client 172.69.71.43:12638] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Dec 16 01:53:37.163931 2025] [authz_core:error] [pid 24872] [client 172.69.71.43:12638] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Dec 16 01:53:38.117568 2025] [authz_core:error] [pid 24872] [client 172.69.71.43:12638] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐ฎ๐น
mgarofano80
2025-09-25 10:49:01
(10 months ago)
Brute-Force
Web App Attack
๐ฎ๐น
mgarofano80
2025-09-23 06:38:52
(10 months ago)
Brute-Force
Web App Attack
๐ฎ๐น
mgarofano80
2025-09-21 12:51:22
(10 months ago)
Brute-Force
Web App Attack