๐บ๐ธ
TPI-Abuse
2026-08-25 08:24:23
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.131.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.131.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 04:24:16.102572 2026] [security2:error] [pid 32036:tid 32055] [client 172.71.131.30:10159] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mentz.me.aafm.us"] [uri "/.git/HEAD"] [unique_id "ao1RMK5xcDHY2tbvWPVHFAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 21:58:07
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.131.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.131.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 17:58:00.828480 2026] [security2:error] [pid 17698:tid 17698] [client 172.71.131.30:12429] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.tomorrowsdust.net"] [uri "/.git/HEAD"] [unique_id "aoy-aKPiySX6z9aZvDQPOQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 10:40:36
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.131.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.131.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 06:40:28.377694 2026] [security2:error] [pid 13096:tid 13096] [client 172.71.131.30:10738] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.networkteam.csennews.com"] [uri "/.git/config"] [unique_id "aorOHHVyh58WFtuKl2hAiwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 00:20:56
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.131.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.131.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 20:20:50.058951 2026] [security2:error] [pid 13255:tid 13255] [client 172.71.131.30:13339] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.deubellzebub.com"] [uri "/.git/config"] [unique_id "aoo84sEuYht-SmFDBNy1kQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 01:00:33
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.131.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.131.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 21:00:25.829762 2026] [security2:error] [pid 24347:tid 24373] [client 172.71.131.30:10965] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.daydreambeliever.us"] [uri "/.git/config"] [unique_id "aoejKaGM9TT_YLVJc8E9BwAAAIo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-18 18:53:11
(6 days ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 21:45:25
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.131.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.131.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 17:45:20.146072 2026] [security2:error] [pid 6839:tid 6839] [client 172.71.131.30:10999] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.wookheo.com"] [uri "/.git/HEAD"] [unique_id "aoOA8F-mwMBglnRbstDzYAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 07:11:39
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.131.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.131.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 03:11:33.441108 2026] [security2:error] [pid 6876:tid 6876] [client 172.71.131.30:12008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.expresstires.us"] [uri "/.git/config"] [unique_id "aoFipRA5ugdpTzqPsIa-NwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 06:46:08
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.131.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.131.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 02:46:04.286644 2026] [security2:error] [pid 3393624:tid 3393671] [client 172.71.131.30:11185] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.collegeofdivinescience.aafm.us"] [uri "/.git/HEAD"] [unique_id "aoFcrINUOjIvCXBH42KbcAAAANA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-30 06:14:37
(3 weeks ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
mawan
2026-07-27 14:43:21
(4 weeks ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฌ๐ง
OptimusGO
2026-07-16 01:28:16
(1 month ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-16 02:28:16 UTC
Log evidence:
172.71.131.30 - - [16/Jul/2026:02:28:16 +0100] "GET /configs/settings%2ejs HTTP/1.1" 404 118 "-" "curl/8.7.1"
07/16/2026-02:28:16.121067 [**] [1:1000201:1] SCANNER: Bot-like User-Agent Detected [**] [Classification: Attempted Information Leak] [Priority: 2] {TCP} 172.71.131.30:11705 -> 185.127.18.66:80
show less
Port Scan
Brute-Force
๐ณ๐ฑ
homeshowdomain.nl
2026-06-16 22:03:49
(2 months ago)
Auto-ban: >3000 req/min op 2026-06-16
Web App Attack
SSH
Hacking
๐ฆ๐บ
dyln
2026-06-09 21:29:03
(2 months ago)
Dyls honeypot brute-force: proto8 (13 total hits)
Brute-Force
Anonymous
2026-06-09 16:07:22
(2 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH