๐บ๐ธ
TPI-Abuse
2026-10-11 08:12:26
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 11 04:12:21.913495 2026] [security2:error] [pid 31007:tid 31007] [client 172.71.182.43:12434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "medenseden.com"] [uri "/.env"] [unique_id "astE5T0br9gilO_yrZ96zgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 18:57:06
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 14:56:54.430737 2026] [security2:error] [pid 9468:tid 9468] [client 172.71.182.43:9830] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pbeyer.org"] [uri "/.env.production"] [unique_id "asqKdiZaiyTJs8MX0mL5FQAAAF0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-10 11:08:24
(1 day ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 18:34:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 14:33:57.993249 2026] [security2:error] [pid 32675:tid 32675] [client 172.71.182.43:11314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "accordionclub.org"] [uri "/.env.bak"] [unique_id "askzlbsi_KJ-UwN7ynWD5wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 14:04:37
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 10:04:32.287581 2026] [security2:error] [pid 12188:tid 12188] [client 172.71.182.43:13552] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michaelsabbey.com"] [uri "/.env.save"] [unique_id "asj0cCdwcEQ20GOJJnLkZgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 12:59:09
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 172.71.182.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.182.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 08:59:00.341435 2026] [security2:error] [pid 30080:tid 30080] [client 172.71.182.43:12411] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||xtremeautodetailing.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "xtremeautodetailing.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asjlFJbX6YaH6nUZ22qFpQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 08:27:53
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 04:27:47.743948 2026] [security2:error] [pid 2653:tid 2653] [client 172.71.182.43:9608] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "petiteplaisanceconservationfund.org"] [uri "/wp-config.php"] [unique_id "asilg4P2EmtqXgp3GomhcgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Bensay
2026-10-08 19:58:14
(2 days ago)
Repeated suspicious HTTP service scan against a blocked web sinkhole; threshold=3 events/10m; result ...
show more
Repeated suspicious HTTP service scan against a blocked web sinkhole; threshold=3 events/10m; result=blocked; user-agent=unknown
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-10-08 17:34:59
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 13:34:52.863424 2026] [security2:error] [pid 6346:tid 6346] [client 172.71.182.43:13660] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jwilder.com"] [uri "/.git/config"] [unique_id "asfUPBEtW3EmgYlNUmch3AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Bensay
2026-10-08 16:09:41
(2 days ago)
Repeated suspicious HTTP service scan against a blocked web sinkhole; threshold=3 events/10m; result ...
show more
Repeated suspicious HTTP service scan against a blocked web sinkhole; threshold=3 events/10m; result=blocked; user-agent=Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0
show less
Port Scan
๐บ๐ฆ
URAN Publishing Service
2026-10-08 02:53:43
(3 days ago)
[08/Oct/2026:05:53:43 +0300] -- 172.71.182.43 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[08/Oct/2026:05:53:43 +0300] -- 172.71.182.43 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 20:56:50
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 16:56:34.726229 2026] [security2:error] [pid 2377:tid 2377] [client 172.71.182.43:12685] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "primemanagementmn.com"] [uri "/.env.local"] [unique_id "asayAs5VdL6pxj9NINVCJAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 13:50:16
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 09:50:00.095689 2026] [security2:error] [pid 8266:tid 8266] [client 172.71.182.43:11027] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michaelwakim.com"] [uri "/.env.production"] [unique_id "asZOCIuesdXEVeTbQPODewAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 05:40:39
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 01:40:29.399058 2026] [security2:error] [pid 11626:tid 11707] [client 172.71.182.43:9342] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hotairwelder.com"] [uri "/wp-config.php.bak"] [unique_id "asXbTRF-1IuYlujoLY8U4AAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 22:47:08
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 18:46:55.231148 2026] [security2:error] [pid 16611:tid 16611] [client 172.71.182.43:10483] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "daviddobkin.com"] [uri "/.env.old"] [unique_id "asV6X6d4luJ2HxF3hVbzRwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack