๐ง๐ช
madeit
2026-09-10 14:10:15
(2 weeks ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-04 04:22:43
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.127.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.127.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 00:22:40.311163 2026] [security2:error] [pid 24697:tid 24716] [client 172.71.127.3:12664] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "colinkyffinmusic.com"] [uri "/.git/config"] [unique_id "appHkEeqX6fStequpTYsqAAAANE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 23:19:26
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.127.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.127.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 19:19:18.612767 2026] [security2:error] [pid 19183:tid 19183] [client 172.71.127.3:9489] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rmjaero.com"] [uri "/.git/config"] [unique_id "apdddpa9Wyk0NFHi2ywccAAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 15:57:31
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.127.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.127.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 11:57:23.536034 2026] [security2:error] [pid 13338:tid 13338] [client 172.71.127.3:13195] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mw-creations.com"] [uri "/.git/config"] [unique_id "apb142Bxgg0AJedFpOGdNgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-18 00:02:30
(1 month ago)
Web App Attack
Anonymous
2026-08-07 23:50:07
(1 month ago)
172.71.127.3 - - [08/Aug/2026:01:50:02 +0200] "GET /opt/%2eenv HTTP/1.1" 403 124 "-" "curl/8.7.1"
17 ...
show more
172.71.127.3 - - [08/Aug/2026:01:50:02 +0200] "GET /opt/%2eenv HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.71.127.3 - - [08/Aug/2026:01:50:02 +0200] "GET /%2egit/config.old HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.71.127.3 - - [08/Aug/2026:01:50:03 +0200] "GET /%2eenv HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.71.127.3 - - [08/Aug/2026:01:50:03 +0200] "GET /%2egit/%63onfig HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.71.127.3 - - [08/Aug/2026:01:50:03 +0200] "GET /%2fpublic%2f%2eenv HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.71.127.3 - - [08/Aug/2026:01:50:03 +0200] "GET /httpd%2econf HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.71.127.3 - - [08/Aug/2026:01:50:03 +0200] "GET /%2esvn/entries HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.71.127.3 - - [08/Aug/2026:01:50:04 +0200] "GET /conf%2ed/default.conf HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.71.127.3 - - [08/Aug/2026:01:50:04 +0200] "GET /%2eazure/config HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.71.127.3 - - [08/Aug/2026:01:50:04 +0200] "GET /_rsc HTTP/1.1" 403 124 "-" "
...
show less
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-07 13:58:51
(1 month ago)
Web App Attack
Anonymous
2026-07-30 06:04:26
(1 month ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ฉ๐ช
mattk
2026-04-08 08:38:19
(5 months ago)
port scan
Port Scan
Anonymous
2026-04-07 01:42:00
(5 months ago)
Web App Attack
Brute-Force
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-01-27 23:57:32
(7 months ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐ง๐ท
chronos
2026-01-24 08:01:40
(8 months ago)
2026-01-24 03:25:55 UTC-3||Unauthorized connection attempt detected for port scanning
Port Scan
๐ฌ๐ง
no1knows.com
2026-01-18 03:53:52
(8 months ago)
2026/01/18 03:53:24 [error] 3276208#3276208: *87593 FastCGI sent in stderr: "Primary script unknown" ...
show more
2026/01/18 03:53:24 [error] 3276208#3276208: *87593 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 172.71.127.3, server: ldn.no1knows.com, request: "GET /api/phpinfo.php HTTP/1.1", upstream: "fastcgi://unix:/run/php-fpm/www.sock:", host: "dev.no1knows.com"
2026/01/18 03:53:24 [error] 3276203#3276203: *87639 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 172.71.127.3, server: ldn.no1knows.com, request: "GET /core/phpinfo.php HTTP/1.1", upstream: "fastcgi://unix:/run/php-fpm/www.sock:", host: "dev.no1knows.com"
2026/01/18 03:53:26 [error] 3276203#3276203: *87639 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 172.71.127.3, server: ldn.no1knows.com, request: "GET /metadata/phpinfo.php HTTP/1.1", upstream: "fastcgi://unix:/run/php-fpm/www.sock:", host: "dev.no1knows.com"
...
show less
Brute-Force
Bad Web Bot
๐ซ๐ท
dynamix
2026-01-06 14:30:22
(8 months ago)
Multiple WAF Violations
Web App Attack
Anonymous
2025-08-24 00:22:57
(1 year ago)
[Sun Aug 24 02:22:56.209137 2025] [authz_core:error] [pid 26450] [client 172.71.127.3:64422] AH01630 ...
show more
[Sun Aug 24 02:22:56.209137 2025] [authz_core:error] [pid 26450] [client 172.71.127.3:64422] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sun Aug 24 02:22:56.227895 2025] [authz_core:error] [pid 26450] [client 172.71.127.3:64422] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sun Aug 24 02:22:56.246624 2025] [authz_core:error] [pid 26450] [client 172.71.127.3:64422] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack