๐ซ๐ท
dynamix
2026-10-09 22:20:25
(14 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 11:46:58
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.130.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.130.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 07:46:53.999610 2026] [security2:error] [pid 8662:tid 8680] [client 172.71.130.212:11056] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "earthlingtechnology.geoception.com"] [uri "/.git/config"] [unique_id "asOOLZp9dkGbzV87-vnj-gAAAU8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-10-05 07:44:45
(5 days ago)
Web App Attack
๐ฉ๐ช
yitzhaq
2026-10-03 23:10:41
(6 days ago)
172.71.130.212 - - [04/Oct/2026:01:10:39 +0200] "GET /alfa-rex.php7 HTTP/2.0" 404 311 "-" "Mozilla/5 ...
show more
172.71.130.212 - - [04/Oct/2026:01:10:39 +0200] "GET /alfa-rex.php7 HTTP/2.0" 404 311 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.71.130.212 - - [04/Oct/2026:01:10:39 +0200] "GET /onclickfuns.php HTTP/2.0" 404 341 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.71.130.212 - - [04/Oct/2026:01:10:39 +0200] "GET /user-new.php HTTP/2.0" 404 55 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
show less
Web App Attack
Brute-Force
๐ฉ๐ช
yitzhaq
2026-10-02 18:43:38
(1 week ago)
172.71.130.212 - - [02/Oct/2026:20:43:36 +0200] "GET /z60.php?p= HTTP/2.0" 404 341 "-" "-"
172.71.13 ...
show more
172.71.130.212 - - [02/Oct/2026:20:43:36 +0200] "GET /z60.php?p= HTTP/2.0" 404 341 "-" "-"
172.71.130.212 - - [02/Oct/2026:20:43:37 +0200] "GET /24.php HTTP/2.0" 404 78 "-" "-"
172.71.130.212 - - [02/Oct/2026:20:43:37 +0200] "GET /xxw.php HTTP/2.0" 404 55 "-" "-"
172.71.130.212 - - [02/Oct/2026:20:43:37 +0200] "GET /ebkid.php HTTP/2.0" 404 55 "-" "-"
show less
Web App Attack
Hacking
๐ฉ๐ช
www.mammazone.it
2026-09-30 10:16:55
(1 week ago)
[Wed Sep 30 12:05:27.693887 2026] [access_compat:error] [pid 2235509] [client 172.71.130.212:13875] ...
show more
[Wed Sep 30 12:05:27.693887 2026] [access_compat:error] [pid 2235509] [client 172.71.130.212:13875] AH01797: client denied by server configuration: /var/www/fabiodirauso.it/.config
[Wed Sep 30 12:16:55.678839 2026] [access_compat:error] [pid 2217863] [client 172.71.130.212:13875] AH01797: client denied by server configuration: /var/www/fabiodirauso.it/.env.config
...
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-30 07:34:53
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.130.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.130.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 03:34:49.557534 2026] [security2:error] [pid 18596:tid 18596] [client 172.71.130.212:12544] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mycampingmall.com"] [uri "/.git/config"] [unique_id "ary7mVNJ1-OEz2EvoDH9gQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-22 22:25:26
(2 weeks ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
www.mammazone.it
2026-09-18 05:31:02
(3 weeks ago)
[Fri Sep 18 07:23:27.982920 2026] [access_compat:error] [pid 3424876] [client 172.71.130.212:11952] ...
show more
[Fri Sep 18 07:23:27.982920 2026] [access_compat:error] [pid 3424876] [client 172.71.130.212:11952] AH01797: client denied by server configuration: /var/www/fabiodirauso.it/celery.config.swp
[Fri Sep 18 07:31:01.551942 2026] [access_compat:error] [pid 3424869] [client 172.71.130.212:11952] AH01797: client denied by server configuration: /var/www/fabiodirauso.it/next.config.ts.bak
...
show less
Hacking
Anonymous
2026-09-17 21:30:05
(3 weeks ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐ง๐ช
madeit
2026-09-17 13:19:20
(3 weeks ago)
Web App Attack
๐ฉ๐ช
www.mammazone.it
2026-09-10 09:32:31
(1 month ago)
[Thu Sep 10 11:26:49.774933 2026] [access_compat:error] [pid 1331845] [client 172.71.130.212:12222] ...
show more
[Thu Sep 10 11:26:49.774933 2026] [access_compat:error] [pid 1331845] [client 172.71.130.212:12222] AH01797: client denied by server configuration: /var/www/fabiodirauso.it/celery.config.yaml
[Thu Sep 10 11:32:31.111984 2026] [access_compat:error] [pid 1353214] [client 172.71.130.212:12222] AH01797: client denied by server configuration: /var/www/fabiodirauso.it/vitest.config.mjs
...
show less
Hacking
๐ฏ๐ต
S.O.B.A. Dev.
2026-09-06 12:39:29
(1 month ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐ฉ๐ช
iNetWorker
2026-09-02 05:47:42
(1 month ago)
trolling for resource vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 00:41:42
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.130.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.130.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:41:38.405039 2026] [security2:error] [pid 19133:tid 19133] [client 172.71.130.212:12479] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "martaaizenman.com"] [uri "/.git/HEAD"] [unique_id "apYfQhkdd4ZDfvu9bEMhtwAAAIE"]
show less
Brute-Force
Bad Web Bot
Web App Attack