๐บ๐ธ
TPI-Abuse
2026-10-01 05:48:25
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 01:48:17.605420 2026] [security2:error] [pid 9581:tid 9581] [client 172.71.182.191:11518] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "compassionfatigue.org"] [uri "/.env.backup"] [unique_id "ar30IebHKfcDZ7kCiUcFoQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:41:22
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:41:17.434711 2026] [security2:error] [pid 22360:tid 22360] [client 172.71.182.191:9945] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "1healthplace.com"] [uri "/.env.production"] [unique_id "ar0DbZoEdmHfGI6S0V5W4wAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-09-30 09:52:09
(22 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 01:58:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 21:58:42.606019 2026] [security2:error] [pid 24969:tid 24969] [client 172.71.182.191:11750] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.greatwesternfirearms.com"] [uri "/.git/config"] [unique_id "arxs0pfNEl2Jqfi3K31-LQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Inartis
2026-09-29 22:56:08
(1 day ago)
172.71.182.191 - - [30/Sep/2026:00:56:06 +0200] "GET /.env.local HTTP/2.0" 404 50890 "-" "Mozilla/5. ...
show more
172.71.182.191 - - [30/Sep/2026:00:56:06 +0200] "GET /.env.local HTTP/2.0" 404 50890 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 21:37:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 17:37:12.619156 2026] [security2:error] [pid 5215:tid 5215] [client 172.71.182.191:13382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "supaskills.com"] [uri "/.env.local"] [unique_id "arwviH9m4uYf3JRtM7jhQwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 21:20:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 17:20:00.288712 2026] [security2:error] [pid 15109:tid 15121] [client 172.71.182.191:14081] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vote4joegardner.com"] [uri "/.svn/entries"] [unique_id "arwrgAox0sRMi_e61-KULQAAAIo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Lunix
2026-09-29 18:45:38
(1 day ago)
Brute-Force
Web App Attack
๐บ๐ธ
Lee Daniel
2026-09-29 10:42:56
(1 day ago)
172.71.182.191 - - [29/Sep/2026:06:42:55 -0400] "GET /.htaccess HTTP/1.1" 403 377 "-" "Mozilla/5.0 ( ...
show more
172.71.182.191 - - [29/Sep/2026:06:42:55 -0400] "GET /.htaccess HTTP/1.1" 403 377 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 19:05:49
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 15:05:43.804238 2026] [security2:error] [pid 30166:tid 30166] [client 172.71.182.191:12902] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "esmital.cl"] [uri "/.env"] [unique_id "arq6h82jXBfh_MO_61GxegAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 16:04:41
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 12:04:35.359523 2026] [security2:error] [pid 12912:tid 12912] [client 172.71.182.191:10729] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stevedegroodt.com"] [uri "/.svn/entries"] [unique_id "arqQEwXO0484U9TVrP9bxwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-27 23:06:53
(3 days ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-27 21:10:53
(3 days ago)
"GET /wp-content/plugins/woocommerce/readme.txt HTTP/1.1"
Hacking
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-27 13:48:29
(3 days ago)
[27/Sep/2026:16:48:29 +0300] -- 172.71.182.191 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp- ...
show more
[27/Sep/2026:16:48:29 +0300] -- 172.71.182.191 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-content/plugins/woocommerce/readme.txt HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-26 10:58:10
(4 days ago)
172.71.182.191 - - [26/Sep/2026:10:57:07 +0000] "GET /.env.backup HTTP/2.0" 403 0 "-" "Mozilla/5.0 ( ...
show more
172.71.182.191 - - [26/Sep/2026:10:57:07 +0000] "GET /.env.backup HTTP/2.0" 403 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0" "2a06:98c0:3600::103" edge="172.71.182.191"
172.71.182.191 - - [26/Sep/2026:10:57:15 +0000] "GET /.env.local HTTP/2.0" 403 0 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E148 Safari/604.1" "2a06:98c0:3600::103" edge="172.71.182.191"
172.71.182.191 - - [26/Sep/2026:10:57:15 +0000] "GET /.env.backup HTTP/2.0" 403 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0" "2a06:98c0:3600::103" edge="172.71.182.191"
172.71.182.191 - - [26/Sep/2026:10:57:23 +0000] "GET /.git/HEAD HTTP/2.0" 403 2 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36" "2a06:98c0:3600::
...
show less
Web App Attack