๐บ๐ธ
p0tatosmash3r
2026-10-07 18:16:50
(1 hour ago)
Honeypot-observed malicious activity: unauth data-store / config enumeration; data-store enumeration ...
show more
Honeypot-observed malicious activity: unauth data-store / config enumeration; data-store enumeration.
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-07 06:35:01
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 02:34:57.019006 2026] [security2:error] [pid 25451:tid 25451] [client 172.71.182.235:11847] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stukabird.com"] [uri "/.git/config"] [unique_id "asXoEQtijpFSkIu0sa3RxQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 11:49:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 07:49:34.978374 2026] [security2:error] [pid 32337:tid 32337] [client 172.71.182.235:12375] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "epicjellyfish.com"] [uri "/.env.old"] [unique_id "asTgTntZHeVEiPD8uBLfXwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 21:30:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 17:29:46.736585 2026] [security2:error] [pid 22756:tid 22756] [client 172.71.182.235:10948] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "radiointernational.net"] [uri "/.svn/entries"] [unique_id "asQWyubStCrKS6uXsaP6lgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 21:09:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 17:09:32.313717 2026] [security2:error] [pid 4912:tid 4912] [client 172.71.182.235:11561] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "xtrl.com"] [uri "/.svn/entries"] [unique_id "asQSDFDsj5wPNtY8aiBjgQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-05 13:25:22
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 10:56:37
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 06:56:31.833852 2026] [security2:error] [pid 32378:tid 32378] [client 172.71.182.235:13091] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "boat-registration-france.com.boatregistrationdelaware.com"] [uri "/.git/config"] [unique_id "asOCX3982oEbTT2JXsn1mQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-05 08:34:17
(2 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ช๐ธ
bohl-aiG5aef
2026-10-05 05:58:44
(2 days ago)
Suricata Alert [SID:2031502] ET INFO Request to Hidden Environment File - Inbound
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-05 05:32:55
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 01:32:50.517276 2026] [security2:error] [pid 32555:tid 32572] [client 172.71.182.235:10920] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "supradig.com"] [uri "/.env.old"] [unique_id "asM2gmJSbcLSQqunmKgEDAAAAU8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 15:37:53
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 172.71.182.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.182.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 11:37:47.079342 2026] [security2:error] [pid 32158:tid 32158] [client 172.71.182.235:12926] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mrflatpeople.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mrflatpeople.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asJyyzk3c7OlKYtFanv-7gAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 04:50:57
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 00:50:52.620323 2026] [security2:error] [pid 7982:tid 7982] [client 172.71.182.235:10333] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jtagulator.com"] [uri "/.git/config"] [unique_id "asHbLH_85rfFD0PbcQ2m-QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 09:42:09
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 05:42:05.326153 2026] [security2:error] [pid 10967:tid 10967] [client 172.71.182.235:9373] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.flutepraise.com"] [uri "/.env.local"] [unique_id "ar4q7QykXsFibNNYtbVbbAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-01 01:03:02
(6 days ago)
[01/Oct/2026:04:03:01 +0300] -- 172.71.182.235 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.gi ...
show more
[01/Oct/2026:04:03:01 +0300] -- 172.71.182.235 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 02:36:57
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 22:36:49.116462 2026] [security2:error] [pid 14332:tid 14332] [client 172.71.182.235:9732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adoniahenterprises.com"] [uri "/.git/config"] [unique_id "arskQT-KKh3vF8OpKj8IewAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack