๐บ๐ธ
TPI-Abuse
2026-10-08 04:58:11
(43 minutes ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 00:58:05.188806 2026] [security2:error] [pid 13615:tid 13615] [client 172.71.183.101:11477] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mightyhoop.com"] [uri "/.env"] [unique_id "asci3cWXBUV3rWcUZNR1-gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 04:10:50
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 00:10:23.224317 2026] [security2:error] [pid 29414:tid 29414] [client 172.71.183.101:13767] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dunnretired.com"] [uri "/wp-config.php.save"] [unique_id "ascXr5O5XexZLwPxEyT_SQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 03:44:00
(1 hour ago)
(mod_security) mod_security (id:949110) triggered by 172.71.183.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 172.71.183.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 23:43:52.272442 2026] [security2:error] [pid 28675:tid 28675] [client 172.71.183.101:11494] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "letahitibookings.com"] [uri "/.env.save"] [unique_id "ascReA852n9NEVplp-jF4wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 03:26:39
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 23:26:24.739955 2026] [security2:error] [pid 11248:tid 11248] [client 172.71.183.101:13860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ballast-capital.com"] [uri "/.env.old"] [unique_id "ascNYF-A7mhw3gpGtp87qwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 03:01:09
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 23:00:54.339842 2026] [security2:error] [pid 15732:tid 15732] [client 172.71.183.101:9580] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fluff3.instagenii.com"] [uri "/.git/config"] [unique_id "ascHZsqVTJs0xEMP94b7EwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-08 02:36:25
(3 hours ago)
[08/Oct/2026:05:36:25 +0300] -- 172.71.183.101 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.en ...
show more
[08/Oct/2026:05:36:25 +0300] -- 172.71.183.101 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.old HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 01:46:25
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 21:46:18.402762 2026] [security2:error] [pid 23527:tid 23572] [client 172.71.183.101:12530] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arthansl.com"] [uri "/.env.old"] [unique_id "asb16rx94Ypj1U8E1kEqrgAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 23:40:07
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 172.71.183.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.183.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 19:39:54.272425 2026] [security2:error] [pid 23959:tid 23959] [client 172.71.183.101:13334] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cruisingforsex.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cruisingforsex.com"] [uri "/index.php.bak"] [unique_id "asbYSgpmfifHxp4Y6KoK3gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 22:53:07
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 18:52:58.803058 2026] [security2:error] [pid 22938:tid 22938] [client 172.71.183.101:12296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "outofthebluephotography.com"] [uri "/.env.dev"] [unique_id "asbNSjQ_GFC9KDsO6pK54QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 22:17:48
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 18:17:42.593071 2026] [security2:error] [pid 19554:tid 19554] [client 172.71.183.101:13483] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "deafinitely.com"] [uri "/wp-config.php.old"] [unique_id "asbFBjzrH-dJ6NfxYwuzFAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-07 14:03:02
(15 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 06:39:23
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 02:39:15.027983 2026] [security2:error] [pid 32521:tid 32521] [client 172.71.183.101:11823] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cook-islands-boat-registration.com"] [uri "/.env.dev"] [unique_id "asXpE_lejkdkVtszYJYWvgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 06:04:33
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 02:04:14.519915 2026] [security2:error] [pid 6294:tid 6294] [client 172.71.183.101:10756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ralphharris.org"] [uri "/.env.save"] [unique_id "asXg3tBRDYLhvdAJxRJJHwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
gszasz
2026-10-07 05:39:42
(1 day ago)
[Wed Oct 07 00:51:39.204307 2026] [authz_core:error] [pid 4988:tid 5077] [client 172.71.183.101:1258 ...
show more
[Wed Oct 07 00:51:39.204307 2026] [authz_core:error] [pid 4988:tid 5077] [client 172.71.183.101:12589] AH01630: client denied by server configuration: /srv/magnetic17.physics.muni.cz/www/.htaccess
[Wed Oct 07 04:11:13.912056 2026] [authz_core:error] [pid 5227:tid 5267] [client 172.71.183.101:12277] AH01630: client denied by server configuration: /srv/magnetic17.physics.muni.cz/www/.htaccess
[Wed Oct 07 07:39:42.062760 2026] [authz_core:error] [pid 4988:tid 5109] [client 172.71.183.101:9829] AH01630: client denied by server configuration: /srv/magnetic17.physics.muni.cz/www/.htaccess
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 04:07:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 00:07:07.353350 2026] [security2:error] [pid 11507:tid 11507] [client 172.71.183.101:10642] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mountainjaytherapy.com"] [uri "/.env.local"] [unique_id "asXFa5lSSTI8i3bmPwsR6wAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack