๐บ๐ธ
TPI-Abuse
2026-10-09 20:34:58
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 16:34:52.501279 2026] [security2:error] [pid 17404:tid 17404] [client 172.71.182.15:14078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "louiemobilemixology.com"] [uri "/wp-config.php.save"] [unique_id "aslP7M9jkFBtn00fJ18XWgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 18:20:32
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 14:20:24.938494 2026] [security2:error] [pid 15757:tid 15757] [client 172.71.182.15:12725] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.pseudo.space"] [uri "/.env.local"] [unique_id "askwaGyflAEZzC8F_R7NlQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
MarkGGN
2026-10-09 14:57:34
(13 hours ago)
Web attack. 172.71.182.15 - - [09/Oct/2026:16:57:33 +0200] "GET /.env.save HTTP/2.0" 403 129 "-" "Mo ...
show more
Web attack. 172.71.182.15 - - [09/Oct/2026:16:57:33 +0200] "GET /.env.save HTTP/2.0" 403 129 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0"
172.71.182.15 - - [09/Oct/2026:16:57:33 +0200] "GET /.git/config HTTP/2.0" 403 129 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 12:59:13
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 172.71.182.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.182.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 08:59:08.643165 2026] [security2:error] [pid 25617:tid 25617] [client 172.71.182.15:9352] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||xtremeautodetailing.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "xtremeautodetailing.com"] [uri "/index.php.bak"] [unique_id "asjlHPJu9iv3dO7lGkSDeAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 09:51:19
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 05:51:12.963451 2026] [security2:error] [pid 7244:tid 7263] [client 172.71.182.15:11289] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "upperwilds.com"] [uri "/.env.production"] [unique_id "asi5EMST75cF20wRjZR4WAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-10-08 20:21:20
(1 day ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 15:56:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 11:56:16.138273 2026] [security2:error] [pid 26551:tid 26551] [client 172.71.182.15:13885] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kontikimotorcycles.com"] [uri "/.env.staging"] [unique_id "ase9IGA508x5TgI6FnVVBAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 07:01:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 03:00:58.236529 2026] [security2:error] [pid 2019:tid 2019] [client 172.71.182.15:12668] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brightspine.com"] [uri "/.env.production"] [unique_id "asc_qsGOE7Bg50b6BA0WrAAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 05:53:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 01:53:43.277975 2026] [security2:error] [pid 26766:tid 26766] [client 172.71.182.15:13077] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dtla2028.com"] [uri "/.svn/entries"] [unique_id "ascv59Nj7ykaiHeX14_izAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 03:39:25
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 23:39:20.698597 2026] [security2:error] [pid 25908:tid 25908] [client 172.71.182.15:12482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "title47.com"] [uri "/.env"] [unique_id "ascQaLqVl5vYl_0Ck5yXZAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-07 21:12:40
(2 days ago)
[08/Oct/2026:00:12:40 +0300] -- 172.71.182.15 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[08/Oct/2026:00:12:40 +0300] -- 172.71.182.15 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.local HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 20:06:16
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 16:06:12.631493 2026] [security2:error] [pid 21129:tid 21129] [client 172.71.182.15:11929] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "intersystems-aircargo.com"] [uri "/wp-config.php.save"] [unique_id "asamNLIWVtt2U5gr06uhnQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 14:59:41
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 10:59:33.403133 2026] [security2:error] [pid 13871:tid 13871] [client 172.71.182.15:11668] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "envirotreecare.com"] [uri "/.env.staging"] [unique_id "asZeVZImtCEmD6upUVV3sAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 05:25:32
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 01:25:17.946811 2026] [security2:error] [pid 11529:tid 11584] [client 172.71.182.15:13610] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hotairwelder.com"] [uri "/.svn/entries"] [unique_id "asXXvWHqy-WPtP1YaNoD5AAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 23:33:51
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 172.71.182.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 172.71.182.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 19:33:36.231901 2026] [security2:error] [pid 15887:tid 15887] [client 172.71.182.15:12656] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "cpectec.com"] [uri "/.env.old"] [unique_id "asWFUM_mu-0AUgPl_trPNgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack