๐บ๐ธ
TPI-Abuse
2026-10-06 22:41:15
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 18:41:09.742480 2026] [security2:error] [pid 2920:tid 2940] [client 172.71.182.29:10949] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lasertagmetairie.com"] [uri "/.env.dev"] [unique_id "asV5BR2H9gtiNq1eNHI1cgAAANI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 22:19:34
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 18:19:29.485105 2026] [security2:error] [pid 13217:tid 13217] [client 172.71.182.29:12119] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sifnosgreekcatering.com"] [uri "/.env.staging"] [unique_id "asVz8c_hxsXBL_8g4nrF_gAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 11:37:49
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 07:37:26.826756 2026] [security2:error] [pid 20045:tid 20045] [client 172.71.182.29:10121] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nomanszone.org"] [uri "/wp-config.php.old"] [unique_id "asTddvAVQ_dNBXhD_xwYMAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 09:24:57
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 05:24:52.110315 2026] [security2:error] [pid 6699:tid 6699] [client 172.71.182.29:10194] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "saramics.net"] [uri "/.env.old"] [unique_id "asS-ZG3PgYNrfXTAEk8ngAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 07:06:37
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 03:06:25.104789 2026] [security2:error] [pid 4463:tid 4463] [client 172.71.182.29:12204] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mathewyoung.com"] [uri "/.env"] [unique_id "asSd8b2RSwXO0hkcHImwcAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 05:20:55
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 01:20:46.449451 2026] [security2:error] [pid 10499:tid 10499] [client 172.71.182.29:14263] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pr-professional.com"] [uri "/.env.backup"] [unique_id "asSFLqZL0D_gbtHy0rdzfQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 22:21:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 18:21:36.273406 2026] [security2:error] [pid 29858:tid 29858] [client 172.71.182.29:12481] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shawnlayne.com"] [uri "/.env.production"] [unique_id "asQi8OTB1xiyJdOAVTEpzgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 02:52:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 22:52:01.301925 2026] [security2:error] [pid 17012:tid 17012] [client 172.71.182.29:10884] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cbrtome.cl"] [uri "/.env"] [unique_id "asMQ0VYI7wv2M1wjYiLQHgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
Mga Admin
2026-10-04 05:58:49
(2 days ago)
172.71.182.29 - - [04/Oct/2026:12:58:48 +0700] "GET /wp-content/plugins/woocommerce/readme.txt HTTP/ ...
show more
172.71.182.29 - - [04/Oct/2026:12:58:48 +0700] "GET /wp-content/plugins/woocommerce/readme.txt HTTP/1.1" 404 69 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ฏ๐ต
ki3
2026-10-01 14:27:42
(5 days ago)
Fail2Ban: Web App Attacks and Forum Spam 172.71.182.29 1790864861.0(JST)
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 10:46:57
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 06:46:52.015430 2026] [security2:error] [pid 11279:tid 11279] [client 172.71.182.29:13599] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.scpublicity.com"] [uri "/.git/HEAD"] [unique_id "ar46HE9SwhwQu92-a-OYXgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 06:33:17
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 02:33:10.513609 2026] [security2:error] [pid 18108:tid 18108] [client 172.71.182.29:13409] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.godcanuseyou.com"] [uri "/.env.local"] [unique_id "ar3-pieE_qK9OMamWJvrAAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
SilverZippo
2026-10-01 01:46:06
(6 days ago)
Web App Attack
Web App Attack
๐ฉ๐ช
altenglaner
2026-09-30 22:28:08
(6 days ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
Lee Daniel
2026-09-30 13:20:43
(6 days ago)
172.71.182.29 - - [30/Sep/2026:09:20:42 -0400] "GET /.htaccess HTTP/1.1" 403 6316 "-" "Mozilla/5.0 ( ...
show more
172.71.182.29 - - [30/Sep/2026:09:20:42 -0400] "GET /.htaccess HTTP/1.1" 403 6316 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack