๐บ๐ธ
TPI-Abuse
2026-06-04 10:35:59
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.148.129 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.148.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 06:35:52.759649 2026] [security2:error] [pid 19355:tid 19355] [client 172.71.148.129:14295] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "leannadsweeney.com"] [uri "/.git/config"] [unique_id "aiFVCKxxtuJnYjNpK_uhHAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 21:19:46
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.148.129 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.148.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 17:19:41.572637 2026] [security2:error] [pid 19275:tid 19275] [client 172.71.148.129:9243] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bencramer.net"] [uri "/.git/config"] [unique_id "aiCabSDurrZ83Qo8O6ouPAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-02 08:06:46
(2 days ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-29 20:34:58
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.148.129 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.148.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 29 16:34:51.725791 2026] [security2:error] [pid 19339:tid 19339] [client 172.71.148.129:11640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wethepeoplealliance.org.rejuvenationsystems.com"] [uri "/.git/config"] [unique_id "ahn4a4IO-MjuYeA1AvemzAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-29 15:38:44
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.148.129 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.148.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 29 11:38:41.035822 2026] [security2:error] [pid 19294:tid 19294] [client 172.71.148.129:10630] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "allinstol.info"] [uri "/.git/config"] [unique_id "ahmzAfVuhZorMXahJ0gaBgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-23 11:29:28
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 172.71.148.129 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 172.71.148.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 07:29:21.404107 2026] [security2:error] [pid 19617:tid 19617] [client 172.71.148.129:11849] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "alexcorp.click"] [uri "/.git/config"] [unique_id "ahGPkY31P6FABT8hf-2_8QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-05-23 05:18:14
(1 week ago)
Bad Web Bot
๐จ๐ฆ
dispensight
2026-05-19 20:01:24
(2 weeks ago)
ngrok traffic to s01-app.dispensight.ca: 1 req(s) [GET:1] URIs: /. UA-class: WordPress. UA: http://d ...
show more
ngrok traffic to s01-app.dispensight.ca: 1 req(s) [GET:1] URIs: /. UA-class: WordPress. UA: http://dispensight.space/wp-admin/install.php?step=1. Geo: Germany / Cloudflare, Inc.. Flags: proxy, threats:bot. Window: 2026-05-19T13:01:24-07:00 to 2026-05-19T13:01:24-07:00.
show less
Hacking
Bad Web Bot
๐ณ๐ฑ
COMPLEX
2026-05-16 00:29:24
(2 weeks ago)
Unsolicited TCP traffic | Action: DROP | Port 2087
Brute-Force
๐ฉ๐ช
4server
2026-05-14 04:41:59
(3 weeks ago)
[ThuMay1406:41:53.0224732026][security2:error][pid2753827:tid2753945][client172.71.148.129:0]ModSecu ...
show more
[ThuMay1406:41:53.0224732026][security2:error][pid2753827:tid2753945][client172.71.148.129:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(curl\|wget\|python\|nikto\|sqlmap\|acunetix\|fimap\|dirbuster\|cmsmap\)\"atREQUEST_HEADERS:user-agent.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"217\"][id\"990210\"][msg\"Suspicioususer-agentblocked\"][hostname\"krausbeck.ch.136-243-54-122.cpanel.site\"][uri\"/.git/config\"][unique_id\"agVSkco4ECPefxQ5SuvlNQAAANg\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-05-12 13:54:58
(3 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฆ๐บ
trentwiles.com
2026-05-11 02:46:32
(3 weeks ago)
Unauthorized connection attempt detected from IP address 172.71.148.129 to port 443 [SYD]
Port Scan
๐จ๐ฆ
dispensight
2026-05-08 15:01:30
(3 weeks ago)
WordPress UA-spoofed probe (400). Cloudflare proxy, Germany. Referrer: dispensight.space (Dispensigh ...
show more
WordPress UA-spoofed probe (400). Cloudflare proxy, Germany. Referrer: dispensight.space (Dispensight Clown Vacuum).
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-08 13:57:29
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.148.129 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.148.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 09:57:21.469545 2026] [security2:error] [pid 14665:tid 14671] [client 172.71.148.129:13915] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "metastrata.com"] [uri "/.git/config"] [unique_id "af3rwRrA65Bz_iu7nM7_jgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-05-08 10:22:17
(3 weeks ago)
Login credentials theft attempt
Hacking