๐ฌ๐ง
OptimusGO
2026-06-25 19:51:22
(1 hour ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-06-25 20:51:22 UTC
Log evidence:
172.71.103.135 - - [25/Jun/2026:20:51:21 +0100] "GET /www/.env HTTP/1.1" 404 118 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:47.0) Gecko/20100101 Firefox/47.0"
06/25/2026-20:51:21.983922 [wDrop] [**] [1:1000110:2] SECURITY CRITICAL: .env File Access Attempt - INSTANT BAN [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 172.71.103.135:13301 -> 185.127.18.66:80
06/25/2026-20:51:21.983922 [wDrop] [**] [1:7000911:2] FINSERV CRITICAL: Environment File Access [**] [Classification: Web Application Attack] [Priority: 1] {TCP} 172.71.103.135:13301 -> 185.127.18.66:80
show less
Port Scan
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-04-08 23:43:47
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.103.135 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.103.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 19:43:43.879539 2026] [security2:error] [pid 1963082:tid 1963082] [client 172.71.103.135:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.webuildbeaches.com"] [uri "/.env.production"] [unique_id "adboL_uM2UwRMCZe6Kp56QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
chrisj
2026-02-05 00:54:21
(4 months ago)
[Thu Feb 05 00:53:46.498867 2026] [proxy_fcgi:error] [pid 556127:tid 556127] [client 172.71.103.135: ...
show more
[Thu Feb 05 00:53:46.498867 2026] [proxy_fcgi:error] [pid 556127:tid 556127] [client 172.71.103.135:10304] AH01071: Got error 'Primary script unknown', referer: http://vandogh.com/site-info.php
[Thu Feb 05 00:53:51.819099 2026] [proxy_fcgi:error] [pid 556127:tid 556127] [client 172.71.103.135:10304] AH01071: Got error 'Primary script unknown', referer: http://vandogh.com/index.php?=phpinfo()
[Thu Feb 05 00:54:20.809821 2026] [proxy_fcgi:error] [pid 556165:tid 556165] [client 172.71.103.135:12219] AH01071: Got error 'Primary script unknown', referer: http://vandogh.com/test.php
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-01-24 18:05:43
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.103.135 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.103.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 24 13:05:40.379353 2026] [security2:error] [pid 2595431:tid 2595431] [client 172.71.103.135:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.webuildbeaches.com"] [uri "/.git/HEAD"] [unique_id "aXUJ9BSRRAtjQNIWj_m_QwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
no1knows.com
2025-12-29 20:18:39
(5 months ago)
2025/12/29 20:18:17 [error] 85075#85075: *29253 FastCGI sent in stderr: "Primary script unknown" whi ...
show more
2025/12/29 20:18:17 [error] 85075#85075: *29253 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 172.71.103.135, server: ldn.no1knows.com, request: "GET /store/wp-login.php HTTP/1.1", upstream: "fastcgi://unix:/run/php-fpm/www.sock:", host: "staging.no1knows.com"
2025/12/29 20:18:18 [error] 85075#85075: *29253 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 172.71.103.135, server: ldn.no1knows.com, request: "GET /wp-login.php HTTP/1.1", upstream: "fastcgi://unix:/run/php-fpm/www.sock:", host: "staging.no1knows.com"
2025/12/29 20:18:20 [error] 85075#85075: *29253 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 172.71.103.135, server: ldn.no1knows.com, request: "GET /blog/wp-login.php HTTP/1.1", upstream: "fastcgi://unix:/run/php-fpm/www.sock:", host: "staging.no1knows.com"
...
show less
Brute-Force
Bad Web Bot
๐ซ๐ท
dynamix
2025-10-12 07:23:45
(8 months ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-08 00:02:00
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.103.135 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.103.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 07 20:01:49.802895 2025] [security2:error] [pid 11807:tid 11807] [client 172.71.103.135:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.webuildbeaches.com"] [uri "/.env"] [unique_id "aL4c7dAcrldiphn3o-CiZAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Niko's Stuff
2025-09-05 18:57:21
(9 months ago)
[1x] Triggered application-multi,language-multi platform-multi,attack-generic | Score: 5 | Msg: Inbo ...
show more
[1x] Triggered application-multi,language-multi platform-multi,attack-generic | Score: 5 | Msg: Inbound Anomaly Score Exceeded (Total Score: 5) | Uri: /.env | Client: 172.71.103.135 172.71.103.135 | Hostname: api.nikostuff.com | Blocked web application firewall detected attack
show less
Brute-Force
๐จ๐ณ
ThreatBook.io
2025-06-28 01:03:33
(11 months ago)
2025-06-27 15:30:41 /
Web App Attack
Anonymous
2025-05-29 19:38:12
(1 year ago)
Probing for Open Source CMS Components
Hacking
Brute-Force
๐บ๐ธ
canine.tools
2025-05-23 03:30:19
(1 year ago)
[fail2ban Auto Report] anubis block
Bad Web Bot
๐จ๐ณ
ThreatBook.io
2025-05-20 00:38:17
(1 year ago)
2025-05-19 16:00:07 /
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-18 20:54:59
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.71.103.135 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.103.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 18 16:54:55.924562 2025] [security2:error] [pid 4053945:tid 4053945] [client 172.71.103.135:59014] [client 172.71.103.135] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.wiszen.org"] [uri "/.git/config"] [unique_id "aCpJH5ZsYHAVOER34j0OuwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-05-15 20:52:51
(1 year ago)
Port probe to tcp/80 (http)
[srv125]
Port Scan
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-05-08 16:11:17
(1 year ago)
Port probe to tcp/8080 (http)
[srv125]
Port Scan
Bad Web Bot
Web App Attack