๐ท๐บ
DZBOT
2026-06-24 16:48:49
(2 days ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 03:22:05
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.148.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.148.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 23:22:00.966651 2026] [security2:error] [pid 25259:tid 25259] [client 172.71.148.64:12517] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "computerian.net"] [uri "/.git/config"] [unique_id "aiDvWNBvk9e5BZQpBun1kAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 23:01:35
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.148.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.148.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 19:01:30.254502 2026] [security2:error] [pid 29355:tid 29355] [client 172.71.148.64:11505] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sydneysue.com"] [uri "/.git/config"] [unique_id "ah9gyn-ab5IRoBhQRbtfZwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-02 20:05:30
(3 weeks ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 17:27:52
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.148.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.148.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 13:27:48.521583 2026] [security2:error] [pid 3275:tid 3275] [client 172.71.148.64:12220] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thewanderinghermit.com"] [uri "/.git/config"] [unique_id "ah8SlL8p4ndQFi246TW_SQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 12:00:20
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.148.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.148.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 08:00:16.597943 2026] [security2:error] [pid 22926:tid 22926] [client 172.71.148.64:11764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chairetis.com"] [uri "/.git/config"] [unique_id "ah7F0BTYcrr1B_RIjtsw4gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-05-25 00:34:10
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-24 10:40:49
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.148.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.148.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 24 06:40:43.386366 2026] [security2:error] [pid 3398:tid 3398] [client 172.71.148.64:11730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "caymancline.com"] [uri "/.git/config"] [unique_id "ahLVq6dSQCaIN8hRzzXSTQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
dispensight
2026-05-19 04:08:35
(1 month ago)
Access to dispensight.com: 5 request(s) [200:5]. URIs: /. UA: http://dispensight.cfd/wp-admin/instal ...
show more
Access to dispensight.com: 5 request(s) [200:5]. URIs: /. UA: http://dispensight.cfd/wp-admin/install.php?step=1. Window: 18/May/2026:11:44:02 -0400 to 19/May/2026:00:08:35 -0400.
show less
Hacking
Bad Web Bot
๐จ๐ฆ
dispensight
2026-05-18 07:00:00
(1 month ago)
Automated WordPress exploit probe via honeydomain. UA: dispensight.cfd. Cloudflare Germany proxy.
Bad Web Bot
๐จ๐ฆ
dispensight
2026-05-15 22:19:15
(1 month ago)
Automated WordPress exploit probe via honeydomain. Rotating through dispensight.forum, .club. 3 hits ...
show more
Automated WordPress exploit probe via honeydomain. Rotating through dispensight.forum, .club. 3 hits. Cloudflare Germany proxy.
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-15 07:30:34
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.148.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.148.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 03:30:23.332299 2026] [security2:error] [pid 32029:tid 32029] [client 172.71.148.64:9334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "manvsfoodlocations.com"] [uri "/.env.development.local"] [unique_id "agbLj38uR1MU_Y4LvlV6QgAAAAY"], referer: https://www.google.com/search?q=manvsfoodlocations.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
dispensight
2026-05-12 05:15:35
(1 month ago)
WordPress UA-spoofed probe (400). Cloudflare proxy, Germany. Referrer: dispensight.forum (Dispensigh ...
show more
WordPress UA-spoofed probe (400). Cloudflare proxy, Germany. Referrer: dispensight.forum (Dispensight Clown Vacuum).
show less
Web App Attack
Bad Web Bot
๐จ๐ฆ
dispensight
2026-05-11 13:03:00
(1 month ago)
WordPress installation fingerprinting via Dispensight Clown Vacuum (dispensight.buzz, dispensight.sb ...
show more
WordPress installation fingerprinting via Dispensight Clown Vacuum (dispensight.buzz, dispensight.sbs): UA contains wp-admin/install.php?step=1 โ scanner probed honeypot TLD(s), 301 to canonical exposes origin. Cloudflare proxy. 2 requests.
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-11 02:53:45
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 172.71.148.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.148.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 22:53:41.465557 2026] [security2:error] [pid 31742:tid 31742] [client 172.71.148.64:12433] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gisur.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gisur.com"] [uri "/backup.sql"] [unique_id "agFEteYcazcazTG1jYyodQAAABA"], referer: https://www.google.com/search?q=gisur.com
show less
Brute-Force
Bad Web Bot
Web App Attack