πΊπΈ
TPI-Abuse
2026-10-11 00:59:36
(18 hours ago)
(mod_security) mod_security (id:210730) triggered by 172.71.182.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.182.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 20:59:24.583903 2026] [security2:error] [pid 24637:tid 24637] [client 172.71.182.160:11571] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||charmainecruz.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "charmainecruz.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asrfbLp-oQLeSqvVOdZ-wQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-10 20:14:28
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 16:14:23.648207 2026] [security2:error] [pid 8588:tid 8588] [client 172.71.182.160:12012] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "scruffware.com"] [uri "/.env.old"] [unique_id "asqcn10tau8g9wrjtssOSAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
bohl-aiG5aef
2026-10-10 09:48:22
(1 day ago)
Suricata Alert [SID:2009955] ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerab ...
show more
Suricata Alert [SID:2009955] ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability
show less
Web App Attack
πͺπΈ
bohl-aiG5aef
2026-10-10 08:59:53
(1 day ago)
Suricata Alert [SID:2019526] ET WEB_SERVER WEB-PHP phpinfo access
Web App Attack
π©πͺ
pltcldvlpr
2026-10-10 05:27:33
(1 day ago)
CMS/framework probe: 172.71.182.160 - - [10/Oct/2026:07:27:31 +0200] "GET /.env.old HTTP/2.0" 499 0 ...
show more
CMS/framework probe: 172.71.182.160 - - [10/Oct/2026:07:27:31 +0200] "GET /.env.old HTTP/2.0" 499 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15" asn=13335 org="Cloudflare, Inc." country=NL
...
show less
Web App Attack
π«π·
dynamix
2026-10-09 22:53:40
(1 day ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 19:50:59
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 15:50:54.146905 2026] [security2:error] [pid 2103:tid 2103] [client 172.71.182.160:10954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jessicalevant.com"] [uri "/.env.bak"] [unique_id "aslFnsIZlD9zhY53SuDWiwAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
altenglaner
2026-10-09 15:06:21
(2 days ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 12:26:03
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 08:25:56.313520 2026] [security2:error] [pid 24871:tid 24871] [client 172.71.182.160:11221] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.puckerbikini.com"] [uri "/.env.local"] [unique_id "asjdVPE0Iit8IjD7fgr79wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 10:11:56
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 06:11:47.659374 2026] [security2:error] [pid 20099:tid 20133] [client 172.71.182.160:13956] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oconnorpest.biz"] [uri "/.env"] [unique_id "asi94_bJJyeFqj_RynCoUgAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-10-09 04:48:48
(2 days ago)
[09/Oct/2026:07:48:46 +0300] -- 172.71.182.160 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.gi ...
show more
[09/Oct/2026:07:48:46 +0300] -- 172.71.182.160 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
π©πͺ
iNetWorker
2026-10-08 19:03:51
(3 days ago)
trolling for resource vulnerabilities
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 16:55:31
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 172.71.182.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.182.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 12:55:21.839477 2026] [security2:error] [pid 18456:tid 18456] [client 172.71.182.160:12404] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bencramer.org|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bencramer.org"] [uri "/index.php.bak"] [unique_id "asfK-XlzVq4et3f1irzokAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 13:21:06
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 09:20:59.929309 2026] [security2:error] [pid 7024:tid 7024] [client 172.71.182.160:12764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "biblestudentfiles.org"] [uri "/wp-config.php.bak"] [unique_id "aseYu2VwydKjuLyjaiRjtQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
bohl-aiG5aef
2026-10-08 12:25:31
(3 days ago)
Suricata Alert [SID:2009955] ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerab ...
show more
Suricata Alert [SID:2009955] ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability
show less
Web App Attack