Anonymous
2026-09-25 18:28:34
(1 day ago)
(caddyscan) Scanner path probe from 172.71.126.95 (FR/France/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 172.71.126.95 (FR/France/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 172.71.126.95 - - [25/Sep/2026:18:28:31 +0000] "GET /.env.backup HTTP/1.1"
[REDACTED] 200 2627 172.71.126.95 - - [25/Sep/2026:18:28:31 +0000] "GET /.env.anthropic HTTP/1.1"
[REDACTED] 200 2627 172.71.126.95 - - [25/Sep/2026:18:28:31 +0000] "GET /.env.dev HTTP/1.1"
[REDACTED] 200 2627 172.71.126.95 - - [25/Sep/2026:18:28:31 +0000] "GET /.env.development HTTP/1.1"
[REDACTED] 200 2627 172.71.126.95 - - [25/Sep/2026:18:28:31 +0000] "GET /.env.dist HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-23 07:20:34
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.126.95 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.126.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 03:20:27.589782 2026] [security2:error] [pid 9943:tid 9943] [client 172.71.126.95:9532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marydeal.com"] [uri "/.git/config"] [unique_id "arN9u4CPkOj1SQ_QzrD1tAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
www.mammazone.it
2026-09-18 16:01:09
(1 week ago)
[Fri Sep 18 18:01:08.821853 2026] [proxy_fcgi:error] [pid 3561595] [client 172.71.126.95:13231] AH01 ...
show more
[Fri Sep 18 18:01:08.821853 2026] [proxy_fcgi:error] [pid 3561595] [client 172.71.126.95:13231] AH01071: Got error 'Primary script unknown'
[Fri Sep 18 18:01:08.980122 2026] [proxy_fcgi:error] [pid 3493847] [client 172.71.126.95:13228] AH01071: Got error 'Primary script unknown'
...
show less
Hacking
๐ซ๐ท
dynamix
2026-09-18 01:49:01
(1 week ago)
Multiple WAF Violations
Web App Attack
๐ธ๐ฌ
cimee
2026-09-16 17:12:05
(1 week ago)
This IP accessed the path /wp-content/.env, which is banned.
Bad Web Bot
Web App Attack
๐ฉ๐ช
www.mammazone.it
2026-09-11 09:27:03
(2 weeks ago)
[Fri Sep 11 11:27:02.890017 2026] [proxy_fcgi:error] [pid 1647525] [client 172.71.126.95:13331] AH01 ...
show more
[Fri Sep 11 11:27:02.890017 2026] [proxy_fcgi:error] [pid 1647525] [client 172.71.126.95:13331] AH01071: Got error 'Primary script unknown'
[Fri Sep 11 11:27:03.113736 2026] [proxy_fcgi:error] [pid 1647525] [client 172.71.126.95:13331] AH01071: Got error 'Primary script unknown'
...
show less
Hacking
๐ณ๐ฑ
BlueWire Hosting
2026-09-02 13:08:11
(3 weeks ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 08:28:41
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.126.95 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.126.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 04:28:33.341038 2026] [security2:error] [pid 25451:tid 25451] [client 172.71.126.95:11681] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nationalenq.com"] [uri "/.git/HEAD"] [unique_id "apfeMSggxfXnZs5exRvoowAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 03:51:57
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.126.95 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.126.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:51:51.596901 2026] [security2:error] [pid 15450:tid 15482] [client 172.71.126.95:14059] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eceinal.com"] [uri "/.git/HEAD"] [unique_id "apZL19QRKL7ya4m-UCMTDQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-31 23:34:24
(3 weeks ago)
Web scanner: GET /.git/config
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-31 14:02:53
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.126.95 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.126.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 10:02:45.298429 2026] [security2:error] [pid 18478:tid 18478] [client 172.71.126.95:12566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "keymarketmedia.com"] [uri "/.git/HEAD"] [unique_id "apWJhQIcAhaDlkzD9PW_pAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-08-30 14:56:49
(3 weeks ago)
[SunAug3016:56:44.0869122026][security2:error][pid1420910:tid1420995][client172.71.126.95:0]ModSecur ...
show more
[SunAug3016:56:44.0869122026][security2:error][pid1420910:tid1420995][client172.71.126.95:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"farmaciaferrari.ch\"][uri\"/.git/config\"][unique_id\"apRErO_Bn1F_mNuyxmt_eAAAAJc\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 12:09:11
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.126.95 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.126.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 08:09:07.432150 2026] [security2:error] [pid 20948:tid 20948] [client 172.71.126.95:13737] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.zackfranz.com"] [uri "/.git/HEAD"] [unique_id "apLL43faW_UXm_w287LeawAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 11:52:59
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.126.95 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.126.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 07:51:25.731153 2026] [security2:error] [pid 27702:tid 27702] [client 172.71.126.95:13984] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.gurneysbottleshop.com"] [uri "/.git/HEAD"] [unique_id "apLHvdUjIldDbYD-v46NowAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 02:34:22
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.126.95 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.126.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:34:15.503398 2026] [security2:error] [pid 21639:tid 21639] [client 172.71.126.95:14281] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.istanbulartlist.pist.org.tr"] [uri "/.git/config"] [unique_id "apJFJ--xmWe6IQ6xpD-3wgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack