π³π±
wlt-blocker
2026-06-21 04:55:06
(8 hours ago)
Unauthorized access to webpage admin
Web App Attack
Anonymous
2026-05-12 08:55:28
(1 month ago)
(caddyscan) Scanner path probe from 172.71.120.54 (CA/Canada/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 172.71.120.54 (CA/Canada/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 172.71.120.54 - - [12/May/2026:08:54:49 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 172.71.120.54 - - [12/May/2026:08:54:49 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 172.71.120.54 - - [12/May/2026:08:54:57 +0000] "GET /.env.swp HTTP/1.1"
[REDACTED] 200 2627 172.71.120.54 - - [12/May/2026:08:54:59 +0000] "GET /.env.development.local HTTP/1.1"
[REDACTED] 200 2627 172.71.120.54 - - [12/May/2026:08:55:23 +0000] "GET /.env.example HTTP/1.1"
show less
Port Scan
πΊπΈ
freeutka
2026-05-11 12:37:44
(1 month ago)
WordPress brute-force login attempt on wp-login.php.
Brute-Force
Web App Attack
πΊπΈ
freeutka
2026-05-06 08:01:05
(1 month ago)
WordPress brute-force login attempt on wp-login.php.
Brute-Force
Web App Attack
πΊπΈ
freeutka
2026-05-04 22:04:55
(1 month ago)
WordPress brute-force login attempt on wp-login.php.
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-28 08:54:24
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 172.71.120.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.120.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 04:54:18.891437 2026] [security2:error] [pid 21103:tid 21103] [client 172.71.120.54:11121] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.blacktieokc.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.blacktieokc.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "afB1uoPlUIaA-ebC0-fx1AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-15 02:44:05
(2 months ago)
172.71.120.54 - - [15/Apr/2026:04:44:05 +0200] "GET //wp1/wp-includes/wlwmanifest.xml HTTP/1.0" 404 ...
show more
172.71.120.54 - - [15/Apr/2026:04:44:05 +0200] "GET //wp1/wp-includes/wlwmanifest.xml HTTP/1.0" 404 460 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
172.71.120.54 - - [15/Apr/2026:04:44:05 +0200] "GET //wp1/wp-includes/wlwmanifest.xml HTTP/1.1" 404 246 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
172.71.120.54 - - [15/Apr/2026:04:44:05 +0200] "GET //test/wp-includes/wlwmanifest.xml HTTP/1.1" 404 246 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
172.71.120.54 - - [15/Apr/2026:04:44:05 +0200] "GET //test/wp-includes/wlwmanifest.xml HTTP/1.0" 404 460 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
172.71.120.54 - - [15/Apr/2026:04:44:05 +0200] "GET //media/wp-includes/wlwmanifest.xml HTTP/1
...
show less
Brute-Force
Web App Attack
π«π·
Campus France
2026-04-08 15:51:47
(2 months ago)
[Wed Apr 08 17:51:45.169054 2026] [php:error] [pid 1388361] [client 172.71.120.54:10783] script '/va ...
show more
[Wed Apr 08 17:51:45.169054 2026] [php:error] [pid 1388361] [client 172.71.120.54:10783] script '/var/www/html/fwe.php' not found or unable to stat
[Wed Apr 08 17:51:46.817055 2026] [php:error] [pid 1388361] [client 172.71.120.54:10783] script '/var/www/html/g.php' not found or unable to stat
[Wed Apr 08 17:51:46.936909 2026] [php:error] [pid 1388361] [client 172.71.120.54:10783] script '/var/www/html/tx1.php' not found or unable to stat
[Wed Apr 08 17:51:47.168674 2026] [php:error] [pid 1388361] [client 172.71.120.54:10783] script '/var/www/html/xv.php' not found or unable to stat
[Wed Apr 08 17:51:47.269890 2026] [php:error] [pid 1388361] [client 172.71.120.54:10783] script '/var/www/html/x56.php' not found or unable to stat
...
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-08 00:51:51
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.120.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.120.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 20:51:43.986674 2026] [security2:error] [pid 1621394:tid 1621394] [client 172.71.120.54:9296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.bruskiewitz.com"] [uri "/.env.json"] [unique_id "adWmn5_tDCU2DpLeoWDhUgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-07 18:09:38
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.120.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.120.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 14:09:34.088096 2026] [security2:error] [pid 1831548:tid 1831548] [client 172.71.120.54:13654] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "skintormint.com"] [uri "/.env.save"] [unique_id "adVIXuKPg_2-1_sWHHJ0RgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Campus France
2026-04-07 10:19:59
(2 months ago)
[Tue Apr 07 12:19:59.094152 2026] [php:error] [pid 422052] [client 172.71.120.54:9720] script '/var/ ...
show more
[Tue Apr 07 12:19:59.094152 2026] [php:error] [pid 422052] [client 172.71.120.54:9720] script '/var/www/html/asd67.php' not found or unable to stat
[Tue Apr 07 12:19:59.194428 2026] [php:error] [pid 422052] [client 172.71.120.54:9720] script '/var/www/html/1.php' not found or unable to stat
[Tue Apr 07 12:19:59.452605 2026] [php:error] [pid 422052] [client 172.71.120.54:9720] script '/var/www/html/rithin.php' not found or unable to stat
[Tue Apr 07 12:19:59.587743 2026] [php:error] [pid 422052] [client 172.71.120.54:9720] script '/var/www/html/gpt-sh.php' not found or unable to stat
[Tue Apr 07 12:19:59.688293 2026] [php:error] [pid 422052] [client 172.71.120.54:9720] script '/var/www/html/gifclass.php' not found or unable to stat
...
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-06 22:42:12
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.120.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.120.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 18:42:08.231465 2026] [security2:error] [pid 694909:tid 694909] [client 172.71.120.54:12675] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.carterindustries.net"] [uri "/srv/.env"] [unique_id "adQ2wO4WtqMMnFj9TcMKlAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-06 13:03:37
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.120.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.120.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 09:03:29.464128 2026] [security2:error] [pid 113542:tid 113542] [client 172.71.120.54:10055] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "edperusse.com.andiamocomputers.com"] [uri "/.env.bak"] [unique_id "adOvId8mPmTzi3KR8uCuOgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-06 11:36:55
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.120.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.120.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 07:36:49.021907 2026] [security2:error] [pid 126618:tid 126618] [client 172.71.120.54:12942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.coloradofingerprinting.com"] [uri "/home/.env"] [unique_id "adOa0TXkMABNKHubm90eBwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-06 04:23:26
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.120.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.120.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 00:23:19.764011 2026] [security2:error] [pid 9979:tid 9979] [client 172.71.120.54:9967] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.fiyaplatform.com"] [uri "/.env.production"] [unique_id "adM1N_M4tCBsSn0kLw1PAQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack