๐บ๐ธ
TPI-Abuse
2026-06-21 04:46:19
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.144.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.144.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 00:46:11.180038 2026] [security2:error] [pid 12833:tid 12833] [client 172.71.144.67:10649] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.directnic.games.websiterescuecontest.com"] [uri "/.env.old"] [unique_id "ajdsk6WEHV_mOT0Gdz86VgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 11:39:11
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.144.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.144.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 07:39:06.994119 2026] [security2:error] [pid 1048:tid 1048] [client 172.71.144.67:12788] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thomaschemicals.com"] [uri "/.git/config"] [unique_id "ajE12kLOSuBbp9OxOYcF2gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-13 05:24:23
(1 week ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ท๐บ
DZBOT
2026-06-10 00:08:34
(1 week ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 19:48:02
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.144.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.144.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 15:47:54.515974 2026] [security2:error] [pid 18148:tid 18148] [client 172.71.144.67:11734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.landscapedesignworkshop.com"] [uri "/.git/config"] [unique_id "aiR5auDgDwMCrGiGkrOE5AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
TheCoon
2026-06-06 02:15:01
(2 weeks ago)
Automated: Credential theft attempt - JSON bomb served
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-02 13:27:18
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.144.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.144.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 09:27:13.549728 2026] [security2:error] [pid 19433:tid 19448] [client 172.71.144.67:12565] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "khalessilaw.com"] [uri "/.git/config"] [unique_id "ah7aMSc76dYmmFhUEU1P8wAAAQw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 09:11:12
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.144.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.144.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 05:11:05.280981 2026] [security2:error] [pid 18192:tid 18192] [client 172.71.144.67:12825] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "borzois.com"] [uri "/.git/config"] [unique_id "ah6eKWuH6DlF5KvxWgRfzAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
iNetWorker
2026-06-01 00:36:10
(3 weeks ago)
trolling for resource vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-30 12:03:53
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.144.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.144.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 08:03:46.663034 2026] [security2:error] [pid 12289:tid 12289] [client 172.71.144.67:14163] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "prestigedomainsales.com.crazycoin.net"] [uri "/.git/config"] [unique_id "ahrSIsDaOSKUOQcmerLx0QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-28 15:08:50
(3 weeks ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐จ๐ฆ
dispensight
2026-05-19 13:10:18
(1 month ago)
ngrok traffic to secureleaf-fraud-api-v1.ngrok.io: 1 req(s) [GET:1] URIs: /. UA-class: WordPress. UA ...
show more
ngrok traffic to secureleaf-fraud-api-v1.ngrok.io: 1 req(s) [GET:1] URIs: /. UA-class: WordPress. UA: http://dispensight.info/wp-admin/install.php?step=1. Geo: Germany / Cloudflare, Inc.. Flags: proxy, threats:bot. Window: 2026-05-19T06:10:18-07:00 to 2026-05-19T06:10:18-07:00.
show less
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-11 11:21:57
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.144.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.144.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 07:21:45.730580 2026] [security2:error] [pid 18694:tid 18694] [client 172.71.144.67:9660] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.orcastrong.iyp-home.com"] [uri "/sftp-config.json"] [unique_id "agG7ye30opHOx91RAQJXJQAAAB4"], referer: https://www.google.com/search?q=www.orcastrong.iyp-home.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
dispensight
2026-05-11 05:20:18
(1 month ago)
WordPress UA-spoofed probe (400). Cloudflare proxy, Germany. Referrer: dispensight.info (Dispensight ...
show more
WordPress UA-spoofed probe (400). Cloudflare proxy, Germany. Referrer: dispensight.info (Dispensight Clown Vacuum).
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-08 11:56:30
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.144.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.144.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 07:56:25.260295 2026] [security2:error] [pid 2705:tid 2705] [client 172.71.144.67:13362] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hipstan.com"] [uri "/.git/config"] [unique_id "af3PadnUnbxbY7OODP3nBQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack