๐บ๐ธ
TPI-Abuse
2026-10-10 04:02:46
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 00:02:38.573031 2026] [security2:error] [pid 15456:tid 15456] [client 172.71.182.99:9718] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "albuquerquelimobus.com"] [uri "/.env.dev"] [unique_id "asm43vlulUCltfrQSrvNpAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
craudiovizai
2026-10-09 18:30:46
(14 hours ago)
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. ...
show more
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. Blocked at the edge.
show less
Web App Attack
Bad Web Bot
๐ง๐ท
dominioz
2026-10-08 22:24:47
(1 day ago)
2026-10-08 22:24:33 GET /%2eenv - - 172.71.182.99 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64) ...
show more
2026-10-08 22:24:33 GET /%2eenv - - 172.71.182.99 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/122.0.0.0+Safari/537.36+Edg/122.0.0.0 - 301 0
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 18:18:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 14:17:58.011114 2026] [security2:error] [pid 13108:tid 13108] [client 172.71.182.99:12035] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zoesaadeh.com"] [uri "/wp-config.php.save"] [unique_id "asfeVst2zdPsGs1XJr6yxAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 16:45:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 12:45:28.033791 2026] [security2:error] [pid 16536:tid 16536] [client 172.71.182.99:13790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dave-curtis.com"] [uri "/wp-config.php"] [unique_id "asfIqBf6ZTLmUBMDfzikawAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 13:01:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 09:01:11.263733 2026] [security2:error] [pid 29877:tid 29905] [client 172.71.182.99:14172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sellmantitle.com"] [uri "/wp-config.php.save"] [unique_id "aseUF_oD078kA6Gu-tkmNQAAAFA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-08 12:18:24
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-08 07:09:27
(2 days ago)
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 172.71.182.99 - - [08/Oct/2026:09:09:18 +0200] "GET /phpinfo.php HTTP/2.0" 301 470 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 04:13:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 00:13:07.928538 2026] [security2:error] [pid 13140:tid 13140] [client 172.71.182.99:10546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "circlehealthcaregroup.com"] [uri "/wp-config.php.bak"] [unique_id "ascYU50uw1NdvAR5cS4MswAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 03:19:42
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 23:19:32.297764 2026] [security2:error] [pid 15709:tid 15709] [client 172.71.182.99:12587] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ironsightsarmory.com"] [uri "/.env.old"] [unique_id "ascLxGzw2rPHm3KiWA_NwAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 01:32:28
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 21:32:13.762793 2026] [security2:error] [pid 444:tid 444] [client 172.71.182.99:10340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "donutlocations.com"] [uri "/.env.backup"] [unique_id "asbyndcGuupq2a-juHv6JAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 01:00:13
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 20:59:38.646052 2026] [security2:error] [pid 955:tid 955] [client 172.71.182.99:9584] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rocketcityhotwheelers.com"] [uri "/.env.dev"] [unique_id "asbq-smYwympMCUhDspNVgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 00:29:56
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 20:29:44.734258 2026] [security2:error] [pid 6583:tid 6583] [client 172.71.182.99:9797] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "liebherr.pamplonaserviciotecnico.com"] [uri "/wp-config.php.bak"] [unique_id "asbj-P8KX-Gv9aKArrMNYQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 22:47:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 18:47:15.594001 2026] [security2:error] [pid 1273:tid 1273] [client 172.71.182.99:9281] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arkansasbest.com"] [uri "/.htaccess"] [unique_id "asbL867mKg3hNMaNo0femQAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 19:05:58
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.182.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.182.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 15:05:52.360738 2026] [security2:error] [pid 3334:tid 3334] [client 172.71.182.99:9616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "register-yacht-cook-islands.com"] [uri "/.env.bak"] [unique_id "asaYENSj_bM3BJhjtdU87gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack