๐บ๐ธ
TPI-Abuse
2026-08-21 12:24:17
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.127.144 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.127.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 08:24:12.334382 2026] [security2:error] [pid 1311:tid 1311] [client 172.71.127.144:10748] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rokket.com"] [uri "/.git/config"] [unique_id "aohDbHp6C8FXMw1jb5rkbgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 01:13:31
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.127.144 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.127.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 21:13:25.927273 2026] [security2:error] [pid 14670:tid 14670] [client 172.71.127.144:11724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.diarrheawolves.com"] [uri "/.git/config"] [unique_id "aoUDNcvHfyxxpXVFPegwMAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 23:19:09
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.127.144 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.127.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 19:19:04.833619 2026] [security2:error] [pid 29845:tid 29845] [client 172.71.127.144:13659] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.francisautodetailing.com"] [uri "/.git/HEAD"] [unique_id "aoToaJdYkBYbxbNA9NF0owAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 22:47:44
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.127.144 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.127.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 18:47:35.918342 2026] [security2:error] [pid 8611:tid 8750] [client 172.71.127.144:10424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.ptinct.com"] [uri "/.git/config"] [unique_id "aoThB48ytpUf1-fODdnfTgAAAM8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 10:52:53
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.127.144 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.127.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 06:52:44.461426 2026] [security2:error] [pid 13891:tid 13891] [client 172.71.127.144:11974] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.dunnretired.com"] [uri "/.git/HEAD"] [unique_id "aoQ5fNnDjWqkLCjsa6BEnAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 10:15:45
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.127.144 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.127.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 06:15:39.718409 2026] [security2:error] [pid 30255:tid 30255] [client 172.71.127.144:11242] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.cbsproductionsinc.com"] [uri "/.git/config"] [unique_id "aoQwy_AHuWEoeTCx_wq2iwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 06:03:34
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.127.144 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.127.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 02:03:27.142350 2026] [security2:error] [pid 28194:tid 28194] [client 172.71.127.144:12937] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.pinhole.us"] [uri "/.git/HEAD"] [unique_id "aoFSr3X2q_vR9JXvffCUDwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-08 14:40:53
(1 week ago)
Web App Attack
๐บ๐ธ
mawan
2026-08-08 10:41:26
(1 week ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
Anonymous
2026-07-29 22:02:05
(3 weeks ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
Anonymous
2026-07-29 07:00:00
(3 weeks ago)
Automated Apache web application probing in selected 24h window; attempts=69, unique_paths=69, error ...
show more
Automated Apache web application probing in selected 24h window; attempts=69, unique_paths=69, error_responses=5; targets include WordPress, .env/.git, phpMyAdmin, autodiscover, wpad.dat and related probe paths.
show less
Web App Attack
Anonymous
2026-07-29 07:00:00
(3 weeks ago)
Apache probe; attempts=141; exact paths: /2024/.env | /.env | /.env.copy | /.env.dev | /.env.dev.loc ...
show more
Apache probe; attempts=141; exact paths: /2024/.env | /.env | /.env.copy | /.env.dev | /.env.dev.local | /.env.local.php | /.env.production | /.env.staging | /.env.test | /.git/ | /.git/index | /.git/info | ///xmlrpc.php?rsd | /actuator/configprops | /actuator/health | /admin/console/.env | /administrator/.env | /api/.env.development | /api/core/.env | /app/config/.env | /app/config/.env.local | /app/config/.env.staging | /aws/ses/smtp.env | /back/.env | /backend/.env.development | /backend/.env.production | /beta/.env | /config/.env.local | /config/database.env | /configs/.env.development | /configs/.env.staging | /core/app/.env | /credentials/.env.local | /data/.env.development | /data/.env.local | /db/.env | /docker-compose/.env | /home/ec2-user/.aws/models/.env | /home/ec2-user/.aws/templates/.env | /home/ec2-user/.cache/bin/aws/lib/.env | /home/ec2-user/.conda/bin/aws/config/.env | /home/ec2-user/.conda | ... [119 exact paths total]
show less
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-10 21:59:43
(1 month ago)
Auto-ban: >3000 req/min op 2026-07-10
Web App Attack
SSH
Hacking
๐บ๐ธ
mawan
2026-07-09 21:06:35
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
mawan
2026-07-07 01:18:10
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack