Anonymous
2026-10-09 08:31:45
(1 day ago)
IP matched detection query many 3xx errors.
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-09 05:40:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.130.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.130.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 01:40:34.736634 2026] [security2:error] [pid 10112:tid 10112] [client 172.71.130.238:9513] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "billdavidow.com"] [uri "/.git/config"] [unique_id "ash-UgAL2kT9ZGqBlVQlbwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-10-08 19:32:54
(2 days ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 01:26:40
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.130.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.130.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 21:26:32.623338 2026] [security2:error] [pid 489:tid 492] [client 172.71.130.238:10386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "workbykathryn.workconfident.com"] [uri "/.git/config"] [unique_id "asROSHFsRpxednTleogVNgAAAYE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-03 22:06:03
(1 week ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 00:03:52
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.130.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.130.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 20:03:45.968272 2026] [security2:error] [pid 24375:tid 24375] [client 172.71.130.238:11497] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "infraredovens.net.daveweisman.com"] [uri "/.git/config"] [unique_id "arsAYRtQvRhwBTNY-U5VAgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-20 12:17:35
(2 weeks ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-13 02:20:03
(3 weeks ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐ฉ๐ช
ValtonTahiri
2026-09-08 18:02:12
(1 month ago)
UFW blocked a suspicious connection attempt to a closed or denied port. This activity is commonly as ...
show more
UFW blocked a suspicious connection attempt to a closed or denied port. This activity is commonly associated with port scanning, service discovery, or automated internet probing. Technical: source_ip=172.71.130.238; proto=TCP; source_port=13743; target_port=8080; flags=SYN
show less
Port Scan
๐บ๐ธ
Starburst SysOp Team
2026-09-08 08:19:54
(1 month ago)
(CT) IP 172.71.130.238 (FR/France/Paris Department/Paris/-) found to have 109 connections (0-mnz6-7)
Hacking
๐บ๐ธ
RH5
2026-09-02 16:33:36
(1 month ago)
Restricted URL probing (/.git/HEAD) (UTC 2026-09-02 16:33)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 23:31:42
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.130.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.130.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 19:31:38.305524 2026] [security2:error] [pid 1794:tid 1794] [client 172.71.130.238:9920] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "verdeprofundo.net"] [uri "/.git/HEAD"] [unique_id "apYO2pCRG_-klrXpzVYVSAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 21:30:05
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.130.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.130.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 17:30:00.466059 2026] [security2:error] [pid 1529269:tid 1529363] [client 172.71.130.238:13132] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.saskiarose.com"] [uri "/.git/config"] [unique_id "apNPWBrw4yIIQMokubhtJAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 18:07:12
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.130.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.130.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 14:07:04.661185 2026] [security2:error] [pid 26151:tid 26151] [client 172.71.130.238:12819] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.huboon.com"] [uri "/.git/config"] [unique_id "apMfyFw9W-deRHTwML__GAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 09:59:29
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.130.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.130.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 05:59:24.436426 2026] [security2:error] [pid 18612:tid 18612] [client 172.71.130.238:12960] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.pintoresdecasascdmx.com"] [uri "/.git/config"] [unique_id "apKtfDTb8fWMOyCGkUBJAQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack