๐ง๐ช
madeit
2026-08-29 11:32:11
(11 hours ago)
Web App Attack
๐ง๐ช
madeit
2026-08-07 06:26:11
(3 weeks ago)
Web App Attack
Anonymous
2026-07-28 13:19:26
(1 month ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ท๐บ
DZBOT
2026-06-09 05:05:05
(2 months ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
WellSpring
2026-05-15 09:54:03
(3 months ago)
wordpress scan on 615.today/wp-admin/install.php โ WellSpr.ing/NetSentinel civic-AI security layer
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-13 07:00:10
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.164.201 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.164.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 03:00:03.597422 2026] [security2:error] [pid 27844:tid 27844] [client 172.71.164.201:12485] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rbmediaworks.com"] [uri "/.env.save"] [unique_id "agQhc8DsbUUKuw2T70hgigAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bescared
2026-05-12 06:01:40
(3 months ago)
F2B - Malicious activity detected. URL Probing. -151302cd-
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 03:03:32
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.164.201 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.164.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 23:03:26.784758 2026] [security2:error] [pid 681058:tid 681058] [client 172.71.164.201:9805] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.flyinganorak.com"] [uri "/.env.old"] [unique_id "adRz_sGaP6YZSzi_WM84LwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 06:48:17
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.164.201 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.164.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 02:48:10.564610 2026] [security2:error] [pid 17219:tid 17219] [client 172.71.164.201:13643] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.fales-lorenz.net"] [uri "/.env"] [unique_id "adNXKsvMlknwI1cEv88cwAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 15:12:07
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.164.201 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.164.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 11:11:59.597717 2026] [security2:error] [pid 14495:tid 14495] [client 172.71.164.201:14211] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webuychesterfieldhouses.com"] [uri "/.env.dev"] [unique_id "adJ7v6WgbcqxRcn_yctMbAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Lentini
2026-04-04 14:55:05
(4 months ago)
visuitslagen.nl: malicious request:/.env.save
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 19:51:11
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.164.201 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.164.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 15:51:02.137450 2026] [security2:error] [pid 3954:tid 3954] [client 172.71.164.201:13428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.marinasure.com"] [uri "/.git/index"] [unique_id "adAaJljauNYxlcaasA6MkwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 17:22:19
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 172.71.164.201 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.164.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 13:22:11.798651 2026] [security2:error] [pid 9357:tid 9357] [client 172.71.164.201:10717] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||imageries.quickasawink.org|F|2"] [data ".env.local.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "imageries.quickasawink.org"] [uri "/.env.local.backup"] [unique_id "ac_3QyEd8urFnNV7yFSKGAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 16:00:14
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.164.201 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.164.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 12:00:06.465365 2026] [security2:error] [pid 29266:tid 29266] [client 172.71.164.201:10570] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.carmichaellaw.org"] [uri "/.env.development"] [unique_id "ac_kBrmFEZ4rsH-xZhC5HgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-04-03 09:34:56
(4 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack