πΊπΈ
TPI-Abuse
2026-08-26 20:47:34
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.130.215 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.130.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 16:47:29.517889 2026] [security2:error] [pid 7347:tid 7347] [client 172.71.130.215:10969] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.usaenquirer.com"] [uri "/.git/config"] [unique_id "ao9Q4Y-J_Vw2XasyImSJ2wAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 11:02:01
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.130.215 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.130.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 07:01:57.504432 2026] [security2:error] [pid 31092:tid 31092] [client 172.71.130.215:9222] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "graphixspace.robtown.com"] [uri "/.git/config"] [unique_id "ao7HpekJqJtuqq9e34ew4AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-25 07:08:27
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.130.215 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.130.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 03:08:21.643222 2026] [security2:error] [pid 3739:tid 3739] [client 172.71.130.215:9932] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.brunellecpa.com"] [uri "/.git/HEAD"] [unique_id "ao0_ZRXVgtXqe25BumGSngAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-08-24 12:30:00
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-22 20:24:51
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.130.215 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.130.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 16:24:43.740941 2026] [security2:error] [pid 27594:tid 27594] [client 172.71.130.215:12459] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clayton.cpking.com"] [uri "/.git/HEAD"] [unique_id "aooFixHEX-0QQqKnGv-q8wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-22 16:26:24
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.130.215 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.130.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 12:26:20.093381 2026] [security2:error] [pid 3119:tid 3119] [client 172.71.130.215:10205] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.thresholddigital.com"] [uri "/.git/HEAD"] [unique_id "aonNrMgsnEYDWu3b8RxkngAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-20 00:25:31
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.130.215 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.130.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 20:25:25.863248 2026] [security2:error] [pid 20575:tid 20594] [client 172.71.130.215:9568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.liamkiriadcompany.brucejoell.com"] [uri "/.git/config"] [unique_id "aoZJdewBNKI6z7FUElmWZgAAAJE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-18 09:48:15
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.130.215 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.130.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 05:48:12.515549 2026] [security2:error] [pid 2248:tid 2248] [client 172.71.130.215:10390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.colorwize.com"] [uri "/.git/config"] [unique_id "aoQqXHnAu2RC7H1_drPvQAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 07:58:47
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.130.215 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.130.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 03:58:40.978463 2026] [security2:error] [pid 12183:tid 12183] [client 172.71.130.215:10541] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.ctrussell.us"] [uri "/.git/config"] [unique_id "aoFtsMAMAeJEyT7LFviBNgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
paissangroup
2026-07-22 23:48:49
(1 month ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
mawan
2026-07-22 01:47:28
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
ππ°
pengpeng
2026-05-20 15:37:54
(3 months ago)
monitor: on ser162528253480 | port: 8443 | ttl: 58 script: github.com/sefinek/UFW-AbuseIPDB-Reporte ...
show more
monitor: on ser162528253480 | port: 8443 | ttl: 58 script: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
π«π·
masterguru
2026-03-31 13:09:54
(4 months ago)
Blocked Cloudflare Worker request. Pattern match "." at REQUEST_HEADERS:Cf-Worker. (5025-193)
Hacking
Anonymous
2026-01-23 20:01:24
(7 months ago)
2026-01-23T21:01:23.228453+01:00 nimbus sshd[48664]: Invalid user guest from 172.71.130.215 port 564 ...
show more
2026-01-23T21:01:23.228453+01:00 nimbus sshd[48664]: Invalid user guest from 172.71.130.215 port 56426
...
show less
Brute-Force
SSH
Anonymous
2026-01-23 18:38:20
(7 months ago)
2026-01-23T19:38:16.807189+01:00 nimbus sshd[46017]: pam_unix(sshd:auth): authentication failure; lo ...
show more
2026-01-23T19:38:16.807189+01:00 nimbus sshd[46017]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=172.71.130.215 user=root
2026-01-23T19:38:19.342597+01:00 nimbus sshd[46017]: Failed password for root from 172.71.130.215 port 56248 ssh2
...
show less
Brute-Force
SSH