๐ท๐บ
DZBOT
2026-06-17 21:37:51
(2 days ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 02:26:37
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.144.69 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.144.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 22:26:31.201987 2026] [security2:error] [pid 13538:tid 13538] [client 172.71.144.69:9851] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shelbysmoak.com"] [uri "/.git/config"] [unique_id "aioc13AUWkiook7aCY9CowAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
KIDOS
2026-06-07 18:34:58
(1 week ago)
KASM auto: exploit_/.git/config
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-06-07 01:05:57
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.144.69 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.144.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 21:05:52.895576 2026] [security2:error] [pid 1335:tid 1352] [client 172.71.144.69:9735] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lamco.us"] [uri "/.git/config"] [unique_id "aiTD8BcrOodxp6oprc8rHQAAAQ4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 19:31:22
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.144.69 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.144.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 15:31:17.375056 2026] [security2:error] [pid 18778:tid 18796] [client 172.71.144.69:10804] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chilltech.info"] [uri "/.git/config"] [unique_id "aiHShWf5jwJ_a5Cgc-x8xwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 18:00:06
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.144.69 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.144.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 14:00:00.437066 2026] [security2:error] [pid 30867:tid 30867] [client 172.71.144.69:12911] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "versahealthcare.com"] [uri "/.git/config"] [unique_id "ah8aIKyJg-aEy-L91Q8gfgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 12:06:49
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.144.69 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.144.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 08:06:43.016596 2026] [security2:error] [pid 18264:tid 18264] [client 172.71.144.69:11634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.goodfrequencies.com"] [uri "/.git/config"] [unique_id "ah7HU0tNaZ8Eh14XdrlN8QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-02 05:05:44
(2 weeks ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 10:25:43
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.144.69 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.144.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 06:25:37.650994 2026] [security2:error] [pid 29985:tid 29985] [client 172.71.144.69:12538] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lexie.org"] [uri "/.env.backup"] [unique_id "ahV1IRM9fcLjKisp8JE1rgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
cimee
2026-05-21 22:04:20
(4 weeks ago)
This IP accessed the path /.env.test, which is banned.
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-05-20 01:43:27
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐จ๐ฆ
dispensight
2026-05-18 21:30:03
(1 month ago)
ngrok traffic to secureleaf-fraud-api-v1.ngrok.io: 1 req(s) [GET:1] URIs: /. UA-class: WordPress. UA ...
show more
ngrok traffic to secureleaf-fraud-api-v1.ngrok.io: 1 req(s) [GET:1] URIs: /. UA-class: WordPress. UA: http://dispensight.help/wp-admin/install.php?step=1. Geo: Germany / Cloudflare, Inc.. Flags: proxy, threats:bot. Window: 2026-05-18T14:30:03-07:00 to 2026-05-18T14:30:03-07:00.
show less
Hacking
Bad Web Bot
๐ฆ๐บ
trentwiles.com
2026-05-11 19:29:47
(1 month ago)
Unauthorized connection attempt detected from IP address 172.71.144.69 to port 2087 [SYD]
Port Scan
๐จ๐ฆ
dispensight
2026-05-11 17:15:17
(1 month ago)
WordPress UA-spoofed probe (400). Cloudflare proxy, Germany. Referrer: dispensight.help (Dispensight ...
show more
WordPress UA-spoofed probe (400). Cloudflare proxy, Germany. Referrer: dispensight.help (Dispensight Clown Vacuum).
show less
Web App Attack
Bad Web Bot
๐จ๐ฆ
dispensight
2026-05-09 04:31:41
(1 month ago)
WordPress UA-spoofed probe (400). Cloudflare proxy, Germany. Referrer: dispensight.help (Dispensight ...
show more
WordPress UA-spoofed probe (400). Cloudflare proxy, Germany. Referrer: dispensight.help (Dispensight Clown Vacuum).
show less
Web App Attack
Bad Web Bot