๐ง๐ช
madeit
2026-08-25 20:07:36
(1 day ago)
Web App Attack
Anonymous
2026-08-01 19:22:53
(3 weeks ago)
Web App Attack
Brute-Force
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-07-10 02:53:15
(1 month ago)
172.71.164.200 - - [10/Jul/2026:05:53:14 +0300] "GET /.vscode/sftp.json HTTP/1.1" 301 162 "-" "Mozil ...
show more
172.71.164.200 - - [10/Jul/2026:05:53:14 +0300] "GET /.vscode/sftp.json HTTP/1.1" 301 162 "-" "Mozilla/5.0 (l9scan/2.0.8323e2733313e27363e2237313; +https://leakix.net)"
...
show less
Hacking
Web App Attack
๐ท๐บ
DZBOT
2026-07-08 23:54:43
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฉ๐ช
acadeova
2026-05-15 04:22:34
(3 months ago)
๐จ Recon detected (nft drop)
SRC=172.71.164.200
Observed=TCP dpt=80 in=enp0s6 ttl=59
Time=recent(jour ...
show more
๐จ Recon detected (nft drop)
SRC=172.71.164.200
Observed=TCP dpt=80 in=enp0s6 ttl=59
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐บ๐ธ
WellSpring
2026-05-13 01:00:39
(3 months ago)
wordpress scan on 740.today/wp-admin/install.php โ WellSpr.ing/NetSentinel civic-AI security layer
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 03:03:32
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.164.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.164.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 23:03:27.056726 2026] [security2:error] [pid 679385:tid 679385] [client 172.71.164.200:10270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.flyinganorak.com"] [uri "/.env.tmp"] [unique_id "adRz_4CYJ3YssGLRpTdK-gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 06:48:15
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.164.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.164.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 02:48:10.373951 2026] [security2:error] [pid 11469:tid 11469] [client 172.71.164.200:9304] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.fales-lorenz.net"] [uri "/.git/index"] [unique_id "adNXKrFBAIMs_5bv7k29WQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 15:12:23
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.164.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.164.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 11:12:19.423322 2026] [security2:error] [pid 14244:tid 14244] [client 172.71.164.200:14103] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webuychesterfieldhouses.com"] [uri "/.env.bak"] [unique_id "adJ705ZHhtV0eRs1SVm5MAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-04-04 21:46:42
(4 months ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Lentini
2026-04-04 14:55:04
(4 months ago)
visuitslagen.nl: malicious request:/.env.production
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-04-04 04:21:52
(4 months ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/-
Web App Attack
๐บ๐ธ
mnsf
2026-04-03 22:05:34
(4 months ago)
Scanning/Probing (14)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 19:51:09
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.164.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.164.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 15:51:02.208676 2026] [security2:error] [pid 1573:tid 1573] [client 172.71.164.200:9533] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.marinasure.com"] [uri "/.git/logs/HEAD"] [unique_id "adAaJh2twaOqfhAisRNyhAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 17:22:39
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 172.71.164.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.164.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 13:22:32.810195 2026] [security2:error] [pid 9543:tid 9543] [client 172.71.164.200:12345] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||imageries.quickasawink.org|F|2"] [data ".env.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "imageries.quickasawink.org"] [uri "/.env.backup"] [unique_id "ac_3WDd0Det-FbW2g1NA0gAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack