π«π·
UnixPrime
2026-09-03 23:46:19
(5 hours ago)
172.71.123.46 - - [04/Sep/2026:01:46:18 +0200] "GET /.env.dist HTTP/1.1" 404 4130 "-" "Mozilla/5.0 ( ...
show more
172.71.123.46 - - [04/Sep/2026:01:46:18 +0200] "GET /.env.dist HTTP/1.1" 404 4130 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
172.71.123.46 - - [04/Sep/2026:01:46:18 +0200] "GET /.env.swp HTTP/1.1" 404 4130 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
π§πͺ
madeit
2026-09-03 20:31:27
(8 hours ago)
Web App Attack
π¨π
4server
2026-09-02 07:46:45
(1 day ago)
[WedSep0209:46:39.6789172026][security2:error][pid2853983:tid2854008][client172.71.123.46:0]ModSecur ...
show more
[WedSep0209:46:39.6789172026][security2:error][pid2853983:tid2854008][client172.71.123.46:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"duoacaja.com\"][uri\"/.git/HEAD\"][unique_id\"apfUXwglW8VaKJBP9RIFBAAAAIw\"]
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 17:38:38
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.123.46 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.123.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 13:38:33.952494 2026] [security2:error] [pid 17118:tid 17118] [client 172.71.123.46:9398] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "solidthought.com"] [uri "/.git/HEAD"] [unique_id "apcNma0CCt7rIm4HqUJKwQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 13:10:00
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.123.46 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.123.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:09:53.224508 2026] [security2:error] [pid 12161:tid 12161] [client 172.71.123.46:9716] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thedoodlists.com"] [uri "/.git/config"] [unique_id "apbOoV1BFKkieRXWcG5LNQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-31 05:34:30
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.123.46 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.123.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 01:34:23.827391 2026] [security2:error] [pid 29752:tid 29752] [client 172.71.123.46:12951] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "the-megg.com"] [uri "/.git/HEAD"] [unique_id "apUSX4OP14gTr4XMAeJ1cgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-31 02:08:22
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.123.46 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.123.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 22:08:18.739375 2026] [security2:error] [pid 14095:tid 14095] [client 172.71.123.46:12175] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yeungshk.com"] [uri "/.git/config"] [unique_id "apTiEhn5IH92l1QJg5OhWQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-30 18:14:23
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.123.46 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.123.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 14:14:15.566057 2026] [security2:error] [pid 6835:tid 6835] [client 172.71.123.46:12842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "easyweb-publishing.com"] [uri "/.git/HEAD"] [unique_id "apRy95C_A_XVnLC8QvqakQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-29 17:13:10
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.123.46 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.123.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 13:13:05.066784 2026] [security2:error] [pid 27283:tid 27283] [client 172.71.123.46:11853] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.scotts.net"] [uri "/.git/config"] [unique_id "apMTIdRxduAtpR4Uqzt95wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-08-28 10:13:05
(6 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 07:10:30
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.123.46 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.123.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 03:10:22.928686 2026] [security2:error] [pid 28232:tid 28232] [client 172.71.123.46:11774] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "accommodation.bookingsouthafrica.com"] [uri "/.git/HEAD"] [unique_id "ao_i3jrhn2G-HdewKgxc5QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 17:05:15
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.123.46 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.123.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 13:05:08.808458 2026] [security2:error] [pid 3945:tid 3945] [client 172.71.123.46:11849] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "denvercitymotorparts.com"] [uri "/.git/HEAD"] [unique_id "ao8cxF3WNZXLJxMTWepafQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-08-25 21:59:30
(1 week ago)
Auto-ban: >3000 req/min op 2026-08-25
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-08-24 19:41:37
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.123.46 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.123.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 15:41:31.305881 2026] [security2:error] [pid 10277:tid 10291] [client 172.71.123.46:11735] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.charteredeconomist.aafm.us"] [uri "/.git/config"] [unique_id "aoyea9IRPXcwv_lXIqZOJgAAAEw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-24 12:06:06
(1 week ago)
Trying to access config files
Web App Attack