Anonymous
2026-10-07 13:03:23
(47 minutes ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-07 10:17:56
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.109 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 06:17:35.166282 2026] [security2:error] [pid 27650:tid 27668] [client 172.71.182.109:11898] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "volcano-sa.com"] [uri "/.env.save"] [unique_id "asYcPxOkB3Tr4xplgYRRlAAAAIg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-07 09:24:20
(4 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 02:24:13
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 172.71.182.109 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.182.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 22:24:08.418411 2026] [security2:error] [pid 15398:tid 15398] [client 172.71.182.109:10537] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.register-yacht-cook-islands.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.register-yacht-cook-islands.com"] [uri "/index.php.bak"] [unique_id "asWtSFr0rW7wYMcDyUoW6QAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 00:52:45
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.109 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 20:52:31.852417 2026] [security2:error] [pid 22406:tid 22406] [client 172.71.182.109:11897] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stukabird.com"] [uri "/.env.bak"] [unique_id "asWXz2X7K2_1gdA2R4yYFwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 21:07:51
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.109 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 17:07:47.211993 2026] [security2:error] [pid 6147:tid 6147] [client 172.71.182.109:9857] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pierrebastin.com"] [uri "/.env.staging"] [unique_id "asVjI4l9UKwLVepKBJTxwwAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 20:41:27
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.109 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 16:41:11.893447 2026] [security2:error] [pid 4761:tid 4761] [client 172.71.182.109:13787] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clowaterart.com"] [uri "/.env.save"] [unique_id "asVc55VxUsTtDKmU3cDwzwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 16:29:46
(21 hours ago)
(mod_security) mod_security (id:210730) triggered by 172.71.182.109 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.182.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 12:29:35.398363 2026] [security2:error] [pid 19635:tid 19635] [client 172.71.182.109:12546] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||toytractorrepair.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "toytractorrepair.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asUh7xf0hDPzdFdtcj7l4gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 15:11:57
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.109 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 11:11:46.781019 2026] [security2:error] [pid 1541:tid 1541] [client 172.71.182.109:13759] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jessiedavison.com"] [uri "/.env"] [unique_id "asUPsleQqX1jgvSMGhBJfgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 12:23:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.109 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 08:23:16.684813 2026] [security2:error] [pid 22052:tid 22052] [client 172.71.182.109:11862] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mrflatpeople.com"] [uri "/.htaccess"] [unique_id "asToNNFY17PqMk56yQgDXQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Petros Stefanakis
2026-10-06 12:15:47
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 172.71.182.109 (-)
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-06 11:18:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.109 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 07:18:03.481171 2026] [security2:error] [pid 9911:tid 10023] [client 172.71.182.109:9517] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cityofmiddleton.org"] [uri "/.git/HEAD"] [unique_id "asTY6w1GtpMWlt7Farl93QAAAQw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 04:18:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.109 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 00:18:08.641412 2026] [security2:error] [pid 17167:tid 17180] [client 172.71.182.109:12467] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "captainpurpleproductions.com"] [uri "/.svn/entries"] [unique_id "asR2gDFubW9w6hyKKbwnkgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 03:33:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.109 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 23:33:46.583371 2026] [security2:error] [pid 15464:tid 15464] [client 172.71.182.109:9829] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stationrestaurant.ca"] [uri "/.env"] [unique_id "asRsGtPsSFhg0KZOQlklsgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-10-05 04:16:55
(2 days ago)
[MonOct0506:16:52.0979792026][security2:error][pid342022:tid342046][client172.71.182.109:0]ModSecuri ...
show more
[MonOct0506:16:52.0979792026][security2:error][pid342022:tid342046][client172.71.182.109:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\^/wp-content/plugins/[\^/] /\(readme\\\\\\\\.txt\|changelog\\\\\\\\.txt\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"735\"][id\"960828\"][msg\"WordPresspluginenumerationblocked\"][hostname\"mio-ip.ch\"][uri\"/wp-content/plugins/woocommerce/readme.txt\"][unique_id\"asMktO69iTPQAToFYkQ4YgAAAJY\"]
show less
Hacking
Web App Attack