πΊπΈ
TPI-Abuse
2026-08-24 22:22:57
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.130.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.130.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 18:22:50.923660 2026] [security2:error] [pid 16660:tid 16660] [client 172.71.130.103:10692] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pacepk.com"] [uri "/.git/config"] [unique_id "aozEOhxRPdpcA-pu5FPYyAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-24 17:10:17
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.130.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.130.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 13:10:09.891255 2026] [security2:error] [pid 17769:tid 17769] [client 172.71.130.103:11692] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.intellectualcapitalmanagementsystems.com"] [uri "/.git/HEAD"] [unique_id "aox68cd_biMQqodpTHpu7AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-22 08:39:24
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 172.71.130.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 172.71.130.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 04:39:18.975868 2026] [security2:error] [pid 25547:tid 25547] [client 172.71.130.103:9678] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.creators.freedrm.org"] [uri "/.git/HEAD"] [unique_id "aolgNpuEQlNl_lTz7VYougAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-20 18:11:16
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.130.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.130.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 14:11:11.118918 2026] [security2:error] [pid 7761:tid 7761] [client 172.71.130.103:13809] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.k4uu.com"] [uri "/.git/config"] [unique_id "aodDP-mNrxNUbNR_IlB5QgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
MPL
2026-08-19 21:24:16
(5 days ago)
tcp/443 (5 or more attempts)
Port Scan
πΊπΈ
TPI-Abuse
2026-08-18 12:34:38
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.130.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.130.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 08:34:31.728875 2026] [security2:error] [pid 2309:tid 2309] [client 172.71.130.103:12696] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.mmldesign.com"] [uri "/.git/HEAD"] [unique_id "aoRRV8FlJFA3vMqofIFcPQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-15 15:51:21
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.130.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.130.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 11:51:14.090539 2026] [security2:error] [pid 5429:tid 5429] [client 172.71.130.103:13620] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "xcingenieria.com"] [uri "/.git/HEAD"] [unique_id "aoCK8g70_SY3RCNE2zxWrwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-30 06:14:35
(3 weeks ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
π³π±
debestelapp
2026-07-30 00:05:05
(3 weeks ago)
Web App Attack
π¬π§
OptimusGO
2026-07-16 01:25:34
(1 month ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-16 02:25:34 UTC
Log evidence:
172.71.130.103 - - [16/Jul/2026:02:25:20 +0100] "GET /api/vars%2ejs HTTP/1.1" 404 118 "-" "curl/8.7.1"
07/16/2026-02:25:20.093559 [**] [1:1000201:1] SCANNER: Bot-like User-Agent Detected [**] [Classification: Attempted Information Leak] [Priority: 2] {TCP} 172.71.130.103:12841 -> 185.127.18.66:80
show less
Port Scan
Brute-Force
π³π±
homeshowdomain.nl
2026-07-15 22:01:39
(1 month ago)
Auto-ban: >3000 req/min op 2026-07-15
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-07-15 08:08:36
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.130.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.130.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 04:08:33.056572 2026] [security2:error] [pid 32544:tid 32544] [client 172.71.130.103:10522] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "escribaniasmith.com.ar"] [uri "/.env"] [unique_id "aldAAdXyBmu6LAhsYfU-igAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-12 16:06:42
(3 months ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
Anonymous
2026-02-12 09:39:59
(6 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
π«π·
domainemporium
2026-02-11 09:21:09
(6 months ago)
(mod_security) mod_security triggered on hostname [redacted] 172.71.130.103 (FR/France/-): (CF_ENAB ...
show more
(mod_security) mod_security triggered on hostname [redacted] 172.71.130.103 (FR/France/-): (CF_ENABLE)
show less
SQL Injection