๐ณ๐ฑ
homeshowdomain.nl
2026-09-27 22:00:52
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-27
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-27 09:50:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.15.12 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.15.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 05:50:20.945656 2026] [security2:error] [pid 4877:tid 4877] [client 172.71.15.12:10367] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sydat.se"] [uri "/.git/config"] [unique_id "arjm3KW2eOs-PZiHEDHfHgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-09-27 06:36:00
(1 day ago)
block ruleset bad bot: misc bad content F608233CC4C86EE814CE8DDDA9C4A0D3C79882F6
Bad Web Bot
๐ณ๐ฑ
BlueWire Hosting
2026-09-27 03:03:00
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 05:45:57
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.15.12 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.15.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 01:45:54.719506 2026] [security2:error] [pid 27013:tid 27059] [client 172.71.15.12:10143] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "taxelon.com"] [uri "/.git/config"] [unique_id "ardcEgXewvJw7Muuh_iTEgAAANY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 23:58:13
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.15.12 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.15.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 19:58:05.668198 2026] [security2:error] [pid 25415:tid 25415] [client 172.71.15.12:11836] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tunabay.com"] [uri "/.git/config"] [unique_id "arcKjc87GOBc_3IcEk23WQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 21:45:44
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.15.12 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.15.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 17:45:40.672722 2026] [security2:error] [pid 22558:tid 22558] [client 172.71.15.12:10851] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "title50.com"] [uri "/.git/config"] [unique_id "arbrhDWPhVJYpoPeLi03sAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 03:32:04
(5 days ago)
172.71.15.12 - - [23/Sep/2026:05:32:02 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 " ...
show more
172.71.15.12 - - [23/Sep/2026:05:32:02 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
172.71.15.12 - - [23/Sep/2026:05:32:03 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
172.71.15.12 - - [23/Sep/2026:05:32:03 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
172.71.15.12 - - [23/Sep/2026:05:32:03 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
172.71.15.12 - - [23/Sep/2026:05:32:03 +0200] "GET //website/wp-includes/wlwmanifest.xml HTTP/1.1
...
show less
Brute-Force
Web App Attack
Anonymous
2026-09-18 03:15:32
(1 week ago)
172.71.15.12 - - [18/Sep/2026:05:15:31 +0200] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "- ...
show more
172.71.15.12 - - [18/Sep/2026:05:15:31 +0200] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
172.71.15.12 - - [18/Sep/2026:05:15:31 +0200] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
172.71.15.12 - - [18/Sep/2026:05:15:32 +0200] "GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
172.71.15.12 - - [18/Sep/2026:05:15:32 +0200] "GET /website/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
172.71.15.12 - - [18/Sep/2026:05:15:32 +0200] "GET /wp/wp-includes/wlwmanifest.xml HTTP/1.1" 404
...
show less
Brute-Force
Web App Attack
๐ง๐ช
madeit
2026-09-13 06:06:07
(2 weeks ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-08 04:13:47
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.15.12 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.15.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:13:41.682926 2026] [security2:error] [pid 2828:tid 2828] [client 172.71.15.12:10388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.microscopicpablo.com"] [uri "/.git/config"] [unique_id "ap-LdVzg9zAs53fD1gVT_wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-06 10:42:14
(3 weeks ago)
[06/Sep/2026:13:42:14 +0300] -- 172.71.15.12 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /c ...
show more
[06/Sep/2026:13:42:14 +0300] -- 172.71.15.12 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /config.env HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-04 12:56:02
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.15.12 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.15.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:55:55.063322 2026] [security2:error] [pid 21255:tid 21255] [client 172.71.15.12:11057] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trancelucid.com"] [uri "/.git/config"] [unique_id "apq_25SVlfXHbdAzMlweXQAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:04:49
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.15.12 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.15.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:04:41.868142 2026] [security2:error] [pid 236589:tid 236627] [client 172.71.15.12:10700] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chriskovac.com"] [uri "/.git/config"] [unique_id "apZ5CcfpSwUk1Zhun1ltuAAAAUs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-09-01 06:13:59
(3 weeks ago)
High-confidence malicious configuration/VCS probe
Web App Attack