๐บ๐ธ
TPI-Abuse
2026-10-07 05:21:33
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.225 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 01:21:20.248606 2026] [security2:error] [pid 12167:tid 12167] [client 172.71.182.225:10519] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cdromline.com"] [uri "/.env.old"] [unique_id "asXW0KGecQGWzfCu5nkUkwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 04:07:28
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.225 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 00:07:11.103314 2026] [security2:error] [pid 11507:tid 11507] [client 172.71.182.225:10806] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mountainjaytherapy.com"] [uri "/.htaccess"] [unique_id "asXFb5lSSTI8i3bmPwsR7wAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 03:12:06
(10 hours ago)
(mod_security) mod_security (id:949110) triggered by 172.71.182.225 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 172.71.182.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 23:12:02.397523 2026] [security2:error] [pid 26214:tid 26214] [client 172.71.182.225:12442] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "cpectec.com"] [uri "/.env.staging"] [unique_id "asW4gtS4gA0Cts8WsYyt6wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 02:20:11
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.225 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 22:20:06.773277 2026] [security2:error] [pid 1279:tid 1291] [client 172.71.182.225:13775] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lasertagmetairie.com"] [uri "/.env.production"] [unique_id "asWsViLA1cnrRhwk9MuNeAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 01:47:07
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.225 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 21:47:03.290703 2026] [security2:error] [pid 31371:tid 31371] [client 172.71.182.225:11163] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "humbliaslaw.com"] [uri "/.env.bak"] [unique_id "asWklz0Yx0hxjdYhUdwxnQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 22:42:49
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.225 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 18:42:45.991447 2026] [security2:error] [pid 14788:tid 14788] [client 172.71.182.225:10778] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fancycleaners.com"] [uri "/.git/config"] [unique_id "asV5ZSdOoFOnoWLDFh5vQgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 12:01:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.225 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 08:01:09.735528 2026] [security2:error] [pid 15305:tid 15305] [client 172.71.182.225:13002] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jkg1.com"] [uri "/.env.dev"] [unique_id "asTjBRB_nNCEpdqBz6DgFgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 08:30:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.225 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 04:29:19.539335 2026] [security2:error] [pid 26843:tid 26843] [client 172.71.182.225:11807] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "csennews.com"] [uri "/.env.backup"] [unique_id "asSxX__TidlNTQ9S_U5h6wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 08:54:01
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.225 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 04:53:57.925020 2026] [security2:error] [pid 14299:tid 14299] [client 172.71.182.225:9662] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "steveleeds.com"] [uri "/.env.backup"] [unique_id "asNlpc5zPxEY1SDdngHmewAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-10-05 04:41:28
(2 days ago)
Web App Attack
Anonymous
2026-10-04 14:43:39
(2 days ago)
Web Probe / Attack
Web App Attack
๐ต๐ฐ
sbk97 (https://sayor.net)
2026-10-04 07:42:20
(3 days ago)
SAYOR honeypot: observed attack /.env.save
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-04 03:13:04
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.225 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 23:12:57.602303 2026] [security2:error] [pid 17871:tid 17871] [client 172.71.182.225:9566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "versahealthcare.com"] [uri "/.git/config"] [unique_id "asHEOWT1yp0LhuOVbtWQdAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 13:35:24
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.225 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:35:17.357298 2026] [security2:error] [pid 23758:tid 23758] [client 172.71.182.225:14301] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lejzerowicz.org"] [uri "/.env.staging"] [unique_id "ar5hlfD3ZUvCmVxSIHtMqwAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 10:04:47
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.225 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 06:04:43.535243 2026] [security2:error] [pid 3693:tid 3693] [client 172.71.182.225:12180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thevenicecafe.com"] [uri "/.git/config"] [unique_id "ar4wOyjnwevc8PEXk_QYEwAAAD8"]
show less
Brute-Force
Bad Web Bot
Web App Attack