๐ท๐บ
DZBOT
2026-06-16 20:24:18
(1 day ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฉ๐ช
findlab
2026-06-15 16:25:02
(3 days ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-06-13 20:52:14
(4 days ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 16:46:44
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.164.88 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.164.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 12:46:40.104471 2026] [security2:error] [pid 15428:tid 15428] [client 172.71.164.88:14322] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aarce.me"] [uri "/.git/config"] [unique_id "aiGr8FkKa9otJ45y2BSJSgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 21:17:33
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.164.88 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.164.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 17:17:29.255438 2026] [security2:error] [pid 32197:tid 32197] [client 172.71.164.88:10500] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "artglass-jerusalem.net"] [uri "/.git/config"] [unique_id "aiCZ6VmReGZfjM_9UYn1BgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 18:48:57
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.164.88 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.164.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 14:48:52.094475 2026] [security2:error] [pid 18495:tid 18495] [client 172.71.164.88:13155] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "modele18.com"] [uri "/.git/config"] [unique_id "ah8llDSpRQdb8karFHLyCwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Lino Project
2026-06-02 07:36:13
(2 weeks ago)
172.71.164.88 - - [02/Jun/2026:09:36:12 +0200] "GET /.git/config HTTP/2.0" 403 253 "-" "curl/8.4.0"
...
show more
172.71.164.88 - - [02/Jun/2026:09:36:12 +0200] "GET /.git/config HTTP/2.0" 403 253 "-" "curl/8.4.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 06:42:13
(2 weeks ago)
(mod_security) mod_security (id:949110) triggered by 172.71.164.88 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 172.71.164.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 02:42:08.666517 2026] [security2:error] [pid 25618:tid 25618] [client 172.71.164.88:9390] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "justinpenney.com"] [uri "/.git/config"] [unique_id "ah57QOJlAoTsddTji-VmJAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 05:31:35
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.164.88 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.164.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 01:31:28.842464 2026] [security2:error] [pid 13418:tid 13418] [client 172.71.164.88:14126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "haroparke.com"] [uri "/.git/config"] [unique_id "ah5qsM0RpJVFL1IoPpB92wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-05-31 22:10:12
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฎ๐ฉ
Burayot
2026-05-20 08:53:05
(4 weeks ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 172.71.164.88 (DE/Germany/-): 1 in t ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 172.71.164.88 (DE/Germany/-): 1 in the last 3600 secs
show less
Web App Attack
๐ท๐บ
DZBOT
2026-05-20 00:26:48
(4 weeks ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐จ๐ฆ
dispensight
2026-05-16 01:13:38
(1 month ago)
Automated WordPress exploit probe via honeydomain. UA: dispensight.forum. Cloudflare Germany proxy.
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-16 00:19:59
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.164.88 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.164.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 20:19:04.434391 2026] [security2:error] [pid 13042:tid 13042] [client 172.71.164.88:9448] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.jangambleandco.com"] [uri "/.env.vercel"] [unique_id "age3-HhUEsdQikCq59w3NwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-13 14:30:10
(1 month ago)
(caddyscan) Scanner path probe from 172.71.164.88 (DE/Germany/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 172.71.164.88 (DE/Germany/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 172.71.164.88 - - [13/May/2026:13:36:14 +0000] "GET /.env.save HTTP/1.1"
[REDACTED] 200 2627 172.71.164.88 - - [13/May/2026:14:29:41 +0000] "GET /.env.save HTTP/1.1"
[REDACTED] 200 2627 172.71.164.88 - - [13/May/2026:14:29:41 +0000] "GET /.aws/credentials HTTP/1.1"
[REDACTED] 200 2627 172.71.164.88 - - [13/May/2026:14:29:47 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 172.71.164.88 - - [13/May/2026:14:30:05 +0000] "GET /.env.dusk.local HTTP/1.1"
show less
Port Scan