๐บ๐ธ
TPI-Abuse
2026-10-04 01:48:17
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.119.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.119.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 21:48:13.664651 2026] [security2:error] [pid 1087058:tid 1087147] [client 172.71.119.66:9856] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "travelusa.us"] [uri "/.git/config"] [unique_id "asGwXYTvGVgfnek601thsgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-10-02 12:21:15
(2 days ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐ง๐ฌ
Stoyko Stoykov
2026-10-02 06:10:35
(2 days ago)
172.71.119.66 - - [02/Oct/2026:09:10:34 +0300] "GET /config/config.js HTTP/2.0" 404 0 "-" "Mozilla/5 ...
show more
172.71.119.66 - - [02/Oct/2026:09:10:34 +0300] "GET /config/config.js HTTP/2.0" 404 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Hacking
Web App Attack
๐ฉ๐ช
LavrinenkoRM
2026-10-02 02:11:50
(2 days ago)
Sentinel WAF: web/rozfarbui.org.ua; scanner path; confidence=90; blocked_at=2026-10-02T01:58:56.1597 ...
show more
Sentinel WAF: web/rozfarbui.org.ua; scanner path; confidence=90; blocked_at=2026-10-02T01:58:56.159742+00:00
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-25 23:31:09
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.119.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.119.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 19:31:04.580454 2026] [security2:error] [pid 26199:tid 26199] [client 172.71.119.66:13582] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theledman.com"] [uri "/.git/config"] [unique_id "arcEOIjNcA8YjduQO2I_xQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-09-25 09:49:42
(1 week ago)
172.71.119.66 - - [25/Sep/2026:12:49:42 +0300] "GET /config/heroku%2ejs HTTP/2.0" 404 0 "-" "curl/8. ...
show more
172.71.119.66 - - [25/Sep/2026:12:49:42 +0300] "GET /config/heroku%2ejs HTTP/2.0" 404 0 "-" "curl/8.7.1"
...
show less
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-09-19 17:04:43
(2 weeks ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
dynamix
2026-09-12 18:32:57
(3 weeks ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 08:44:04
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.119.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.119.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 04:43:58.407048 2026] [security2:error] [pid 18342:tid 18342] [client 172.71.119.66:11323] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "quantumacceleration.org"] [uri "/.git/HEAD"] [unique_id "apfhzh31LKtaz8HIbRklYwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-09-01 21:07:01
(1 month ago)
[Wed Sep 02 07:07:00.669043 2026] [security2:error] [pid 305199] [client 172.71.119.66:10067] [clien ...
show more
[Wed Sep 02 07:07:00.669043 2026] [security2:error] [pid 305199] [client 172.71.119.66:10067] [client 172.71.119.66] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "valueaddedpromotions.com.au"] [uri "/.git/config"] [unique_id "apc-dNY1k4KOMfaDn6bhWgAAAAo"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 09:24:52
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.119.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.119.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:24:45.212022 2026] [security2:error] [pid 9755:tid 9755] [client 172.71.119.66:13911] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ellesorority.com"] [uri "/.git/config"] [unique_id "apaZ3aZGQyTUxrLsOlqA1AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 09:17:58
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.119.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.119.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 05:17:53.686917 2026] [security2:error] [pid 7440:tid 7440] [client 172.71.119.66:12328] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sarawatt.com"] [uri "/.git/HEAD"] [unique_id "apVGwVLZpW39GOjkrtrp_QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 06:28:27
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.119.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.119.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 02:28:23.917172 2026] [security2:error] [pid 5568:tid 5568] [client 172.71.119.66:9861] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "azpinklimos.com"] [uri "/.git/HEAD"] [unique_id "apUfByLJBrBmVr9RB8k-bgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 03:57:53
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.119.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.119.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 23:57:48.696808 2026] [security2:error] [pid 4921:tid 4921] [client 172.71.119.66:13465] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hdestimating.com"] [uri "/.git/HEAD"] [unique_id "apT7vBl7UINRZnmhnM7YYAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 21:19:24
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.119.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.119.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 17:19:19.711461 2026] [security2:error] [pid 29485:tid 29485] [client 172.71.119.66:11299] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.jhbookdesign.com"] [uri "/.git/config"] [unique_id "apNM18Uvt9q4YtmptckH3wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack