๐บ๐ธ
TPI-Abuse
2026-10-07 09:23:38
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 05:23:33.985396 2026] [security2:error] [pid 28570:tid 28570] [client 172.71.182.252:10784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.register-yacht-cook-islands.com"] [uri "/.env.dev"] [unique_id "asYPlUJuOZ1gz5AzBkNUYgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-07 05:15:33
(8 hours ago)
[07/Oct/2026:08:15:32 +0300] -- 172.71.182.252 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.en ...
show more
[07/Oct/2026:08:15:32 +0300] -- 172.71.182.252 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.production HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-06 23:58:55
(13 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐ซ๐ฎ
sibahota
2026-10-06 22:39:26
(14 hours ago)
172.71.182.252 - - [06/Oct/2026:22:39:21 +0000] nidandiagnostic.com "GET /.env.old HTTP/2.0" 403 26 ...
show more
172.71.182.252 - - [06/Oct/2026:22:39:21 +0000] nidandiagnostic.com "GET /.env.old HTTP/2.0" 403 26 0.000 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15" - - - "http://nidandiagnostic.com"
...
show less
Web App Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-06 21:07:58
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 17:07:48.015089 2026] [security2:error] [pid 5141:tid 5141] [client 172.71.182.252:9493] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pierrebastin.com"] [uri "/.env.old"] [unique_id "asVjJFemlXn_pGkhm4aPXwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 16:29:49
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 12:29:39.369078 2026] [security2:error] [pid 21282:tid 21282] [client 172.71.182.252:11739] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "toytractorrepair.com"] [uri "/.env.local"] [unique_id "asUh86qRfxR5iGwhcxzmHAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 15:02:01
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 11:01:51.763525 2026] [security2:error] [pid 27485:tid 27485] [client 172.71.182.252:10903] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "megaandina.com"] [uri "/.env.staging"] [unique_id "asUNXzQIxPIh6bKoO8ZaPQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 12:56:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 08:55:37.801285 2026] [security2:error] [pid 9763:tid 9763] [client 172.71.182.252:10266] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thenolangroup.llc"] [uri "/.env.bak"] [unique_id "asTvyas4bhT5IYJAsxqUPgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 12:06:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 08:06:17.292480 2026] [security2:error] [pid 3994:tid 3994] [client 172.71.182.252:11420] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zodiacwin.com"] [uri "/.env.save"] [unique_id "asTkOQXk51_0XZcbReLSIwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 10:33:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 06:33:05.701000 2026] [security2:error] [pid 31217:tid 31314] [client 172.71.182.252:13831] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dulemba.com"] [uri "/.env.save"] [unique_id "asTOYTwg1A_4a6lmLFQ8uAAAAkY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 09:40:17
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 172.71.182.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.182.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 05:40:04.569453 2026] [security2:error] [pid 31623:tid 31623] [client 172.71.182.252:13321] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||getitenglish.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "getitenglish.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asTB9E1TNFjVOs0PFubdHgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-06 08:12:58
(1 day ago)
[Tue Oct 06 10:12:53.702239 2026] [authz_core:error] [pid 22108] [client 172.71.182.252:10535] AH016 ...
show more
[Tue Oct 06 10:12:53.702239 2026] [authz_core:error] [pid 22108] [client 172.71.182.252:10535] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Oct 06 10:12:54.866142 2026] [authz_core:error] [pid 22108] [client 172.71.182.252:10535] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Oct 06 10:12:55.001723 2026] [authz_core:error] [pid 22108] [client 172.71.182.252:10535] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 07:38:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 03:37:57.377633 2026] [security2:error] [pid 14163:tid 14163] [client 172.71.182.252:14043] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "xtrl.com"] [uri "/.env"] [unique_id "asSlVZ-5W6qkG6y32CWlgAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 04:28:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 00:28:24.484638 2026] [security2:error] [pid 29578:tid 29578] [client 172.71.182.252:12868] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "title30.com"] [uri "/.env.local"] [unique_id "asR46ObzD80EHA8swEq_0wAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 22:53:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 18:53:46.258293 2026] [security2:error] [pid 10821:tid 10821] [client 172.71.182.252:13395] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "register-boat-germany.com"] [uri "/.env.local"] [unique_id "asQqeg47Pt7g311JYAeX8gAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack