๐บ๐ธ
TPI-Abuse
2026-10-08 13:54:41
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 09:54:24.861722 2026] [security2:error] [pid 21683:tid 21683] [client 172.71.183.12:10344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "donnathedoglady.com"] [uri "/.env.staging"] [unique_id "asegkNUz-6wANhbhCTOJUQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 07:57:33
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 03:57:15.001698 2026] [security2:error] [pid 4768:tid 4768] [client 172.71.183.12:14161] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.belgiophar.com"] [uri "/wp-config.php.save"] [unique_id "asdM20eKpLZ2n1oZHfDZhwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 00:53:01
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 20:52:57.563647 2026] [security2:error] [pid 12741:tid 12760] [client 172.71.183.12:10426] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sailcleaner.com"] [uri "/.env.backup"] [unique_id "asbpaS1rnGYqPmSuxj-44gAAAU0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 19:56:25
(19 hours ago)
(mod_security) mod_security (id:210730) triggered by 172.71.183.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.183.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 15:56:18.202643 2026] [security2:error] [pid 1666:tid 1666] [client 172.71.183.12:12621] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||universitydental.org|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "universitydental.org"] [uri "/index.php.bak"] [unique_id "asaj4qAiLdNLhbMrNSiiAAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-07 18:05:54
(21 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-07 05:10:41
(1 day ago)
[07/Oct/2026:08:10:40 +0300] -- 172.71.183.12 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-c ...
show more
[07/Oct/2026:08:10:40 +0300] -- 172.71.183.12 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-config.php HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 09:40:05
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 05:39:58.725343 2026] [security2:error] [pid 31659:tid 31659] [client 172.71.183.12:13176] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "getitenglish.com"] [uri "/.git/config"] [unique_id "asTB7ibpIBsseo3h8pXXkQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 06:52:24
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 02:52:20.545197 2026] [security2:error] [pid 17229:tid 17229] [client 172.71.183.12:11890] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kaleidoscope-glass.com"] [uri "/.git/HEAD"] [unique_id "asNJJGtdNU-GlPRiUKOeIQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 15:53:49
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 11:53:41.548374 2026] [security2:error] [pid 15365:tid 15385] [client 172.71.183.12:9473] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "advertisingfirm.org"] [uri "/.env.backup"] [unique_id "asJ2hRYBZugfzfnjy1_SBQAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 09:33:21
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 05:33:16.649008 2026] [security2:error] [pid 20222:tid 20222] [client 172.71.183.12:12587] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "foundintranslation.net"] [uri "/.env"] [unique_id "asIdXFceYdT9NkVO3efLPgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 13:44:32
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:44:24.835018 2026] [security2:error] [pid 27943:tid 27943] [client 172.71.183.12:13564] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.spaceritual.net"] [uri "/.env.backup"] [unique_id "ar5juIXpeENkXsLf8Knj9wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
XICTRON
2026-09-30 17:25:11
(1 week ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-30 06:56:44
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-26 14:53:14
(1 week ago)
[26/Sep/2026:17:53:14 +0300] -- 172.71.183.12 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[26/Sep/2026:17:53:14 +0300] -- 172.71.183.12 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.local HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 11:34:42
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 07:34:30.207099 2026] [security2:error] [pid 27788:tid 27788] [client 172.71.183.12:13072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "geofreightint.com"] [uri "/.env"] [unique_id "aretxi06abLikka9VYqZhwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack