๐บ๐ธ
TPI-Abuse
2026-10-08 22:09:33
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 172.71.182.52 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.182.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 18:09:29.792889 2026] [security2:error] [pid 4146:tid 4146] [client 172.71.182.52:13336] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||davidrayskinner.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "davidrayskinner.com"] [uri "/index.php.bak"] [unique_id "asgUmTsOxXdkQZK9i_XOCgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 21:01:46
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.52 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 17:01:40.100805 2026] [security2:error] [pid 27000:tid 27000] [client 172.71.182.52:13209] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.loriarsenault.com"] [uri "/.env.old"] [unique_id "asgEtL4gDYPPdpCr854dCgAAADY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 16:14:52
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.52 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 12:14:39.562701 2026] [security2:error] [pid 21813:tid 21813] [client 172.71.182.52:14054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "partybusdet.com"] [uri "/wp-config.php.old"] [unique_id "asfBb6Jh4pTmCBKYGwXbewAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 07:18:02
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.52 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 03:17:57.771058 2026] [security2:error] [pid 874:tid 874] [client 172.71.182.52:13320] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bakerimaging.com"] [uri "/.svn/entries"] [unique_id "asdDpUC7nmckoUE8ArifewAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 03:52:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.52 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 23:52:02.371216 2026] [security2:error] [pid 21948:tid 21948] [client 172.71.182.52:10877] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "renomarsh.com"] [uri "/wp-config.php.save"] [unique_id "ascTYovknkzdptpjL1BZJgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-07 21:06:34
(1 day ago)
[08/Oct/2026:00:06:33 +0300] -- 172.71.182.52 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-c ...
show more
[08/Oct/2026:00:06:33 +0300] -- 172.71.182.52 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-config.php HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 18:24:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.52 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 14:24:05.084611 2026] [security2:error] [pid 7791:tid 7791] [client 172.71.182.52:9231] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftiptondds.com"] [uri "/.env.dev"] [unique_id "asaORUopMULDZtGvvrSY8wAAAJQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 17:12:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.52 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 13:12:39.874149 2026] [security2:error] [pid 25202:tid 25221] [client 172.71.182.52:9903] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.amphoracollectors.org"] [uri "/wp-config.php.old"] [unique_id "asZ9h73QtO2XMYcgzoR2fAAAARE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 20:32:15
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.52 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 16:32:02.843438 2026] [security2:error] [pid 28481:tid 28481] [client 172.71.182.52:12349] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jsommer.com"] [uri "/wp-config.php"] [unique_id "asVawmYfv5l37WyVzKA2vQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-06 14:49:18
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 07:31:59
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.52 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 03:31:52.508069 2026] [security2:error] [pid 4762:tid 4762] [client 172.71.182.52:10523] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "megapct.com"] [uri "/.env.staging"] [unique_id "asSj6MpXX7-w5s0SzIeU0gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 03:48:17
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.52 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 23:48:10.143596 2026] [security2:error] [pid 10275:tid 10275] [client 172.71.182.52:12776] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rangerroma.com"] [uri "/.env.bak"] [unique_id "asRvehdfs5nxCdlSNSz29AAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 00:41:28
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.52 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 20:41:22.491692 2026] [security2:error] [pid 24769:tid 24769] [client 172.71.182.52:10326] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "briannalls.com"] [uri "/.env.production"] [unique_id "asLyMm-pZTeT5qp-VpQPdgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-10-04 21:15:54
(4 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐ต๐ฐ
sbk97 (https://sayor.net)
2026-10-04 07:42:20
(5 days ago)
SAYOR honeypot: observed attack /geoserver/wfs?request=ListStoredQueries&service=wfs&version=2.0.0
Brute-Force