๐ซ๐ท
dynamix
2026-10-01 01:12:37
(9 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 00:31:59
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 172.71.183.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.183.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 20:31:55.414337 2026] [security2:error] [pid 18766:tid 18771] [client 172.71.183.117:10502] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||21370.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "21370.com"] [uri "/index.php.bak"] [unique_id "ar2p-7xmlDTP2SKvwHopOQAAAIA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-30 20:22:55
(13 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:18:52
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:18:45.247810 2026] [security2:error] [pid 5863:tid 5863] [client 172.71.183.117:10184] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blog.mosherpit.com"] [uri "/.svn/entries"] [unique_id "ar0aRTHO96_nAaqgWEdPbgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:01:10
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:01:04.410967 2026] [security2:error] [pid 25711:tid 25711] [client 172.71.183.117:12769] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.aes-nihil.com"] [uri "/.git/config"] [unique_id "ar0WII3kBZ_2m5VELzA0ZAAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 10:31:26
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 06:31:19.425158 2026] [security2:error] [pid 16108:tid 16108] [client 172.71.183.117:10570] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ruthbalser.org"] [uri "/.env.staging"] [unique_id "arzk90j_OQaRfE9LJv2fQQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 09:31:55
(1 day ago)
[Wed Sep 30 11:31:53.871542 2026] [authz_core:error] [pid 31695] [client 172.71.183.117:13346] AH016 ...
show more
[Wed Sep 30 11:31:53.871542 2026] [authz_core:error] [pid 31695] [client 172.71.183.117:13346] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Wed Sep 30 11:31:53.922085 2026] [authz_core:error] [pid 31695] [client 172.71.183.117:13346] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Wed Sep 30 11:31:53.956706 2026] [authz_core:error] [pid 31695] [client 172.71.183.117:13346] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 05:47:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 01:47:42.353708 2026] [security2:error] [pid 20292:tid 20292] [client 172.71.183.117:10660] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ndakno.com"] [uri "/.git/config"] [unique_id "aryifrviZf2725ACfV2iGwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-09-30 00:48:22
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 14:21:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 10:20:59.893258 2026] [security2:error] [pid 2891:tid 2891] [client 172.71.183.117:11383] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.achildsspace.com"] [uri "/wp-config.php.bak"] [unique_id "arvJSye85XWOlC7wGhEkEAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 13:50:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 09:50:47.617978 2026] [security2:error] [pid 532:tid 532] [client 172.71.183.117:14097] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lemobba.com"] [uri "/.env.local"] [unique_id "arvCN2APIustaIZRx7K03AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 12:31:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 08:31:04.280501 2026] [security2:error] [pid 30037:tid 30037] [client 172.71.183.117:13467] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "constructiondomex.com"] [uri "/.env"] [unique_id "aruviH_CfG5HoF8WD37jqQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-29 09:45:35
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
Anonymous
2026-09-28 23:08:46
(2 days ago)
172.71.183.117 - - [28/Sep/2026:23:08:46 +0000] "GET /wp-content/plugins/woocommerce/readme.txt HTTP ...
show more
172.71.183.117 - - [28/Sep/2026:23:08:46 +0000] "GET /wp-content/plugins/woocommerce/readme.txt HTTP/2.0" 302 382 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 20:35:20
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 16:35:12.610187 2026] [security2:error] [pid 3009:tid 3009] [client 172.71.183.117:11199] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.register-yacht-italy.com"] [uri "/.env"] [unique_id "arrPgJFjf1OQkSodVXpK6QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack