๐บ๐ธ
TPI-Abuse
2026-10-06 23:22:52
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 19:22:41.337923 2026] [security2:error] [pid 4557:tid 4557] [client 172.71.183.121:10394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "haco.us"] [uri "/.env.backup"] [unique_id "asWCwdhPeBZbdDv98rueVAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 16:29:16
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 12:29:07.262802 2026] [security2:error] [pid 19641:tid 19641] [client 172.71.183.121:14217] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "erinrusso.com"] [uri "/.env.old"] [unique_id "asUh0zQssFiaD_YUSy4CjAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-06 16:17:39
(8 hours ago)
[06/Oct/2026:19:17:39 +0300] -- 172.71.183.121 Ban reason: Scanner [CMS_GENERIC] | Request: GET /con ...
show more
[06/Oct/2026:19:17:39 +0300] -- 172.71.183.121 Ban reason: Scanner [CMS_GENERIC] | Request: GET /config.php HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 15:32:51
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 172.71.183.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.183.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 11:32:42.885068 2026] [security2:error] [pid 3981:tid 3981] [client 172.71.183.121:13346] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.register-yacht-guernsey.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.register-yacht-guernsey.com"] [uri "/index.php.bak"] [unique_id "asUUmjh7VAZiTYJRDo3mwAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-10-06 14:17:24
(10 hours ago)
Unauthorized access to webpage admin
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 11:41:35
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 07:41:28.300640 2026] [security2:error] [pid 23653:tid 23653] [client 172.71.183.121:11511] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nomanszone.org"] [uri "/.env"] [unique_id "asTeaDkwysGkrQAE-Zq8MQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 04:28:55
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 00:28:29.606400 2026] [security2:error] [pid 25407:tid 25407] [client 172.71.183.121:12860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "title30.com"] [uri "/.env.save"] [unique_id "asR47fKvpu2TVLt11smg7wAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 01:01:05
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 172.71.183.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.183.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 21:00:26.527775 2026] [security2:error] [pid 9590:tid 9590] [client 172.71.183.121:10808] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||new-bethel-baptist-church.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "new-bethel-baptist-church.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asRIKn7oAOFfNPH3zh2VXAAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 22:21:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 18:21:37.187403 2026] [security2:error] [pid 4645:tid 4645] [client 172.71.183.121:11719] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shawnlayne.com"] [uri "/.env.old"] [unique_id "asQi8bbJIqa7e7iOs9AbHwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 07:22:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 03:22:15.621947 2026] [security2:error] [pid 17220:tid 17220] [client 172.71.183.121:9757] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kaleidoscope-glass.com"] [uri "/.env.backup"] [unique_id "asNQJ7rUDNaYMgf6r-hiBgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
crnpekgoz
2026-10-03 11:01:58
(3 days ago)
Malicious HTTP GET request for '/.docker/config.json' (HTTP 301) from 172.71.183.121. Threat: Web Gรผ ...
show more
Malicious HTTP GET request for '/.docker/config.json' (HTTP 301) from 172.71.183.121. Threat: Web Gรผvenlik Aรงฤฑฤฤฑ Taramasฤฑ (.env/bot). Blocked by WardenGuard Web Shield.
show less
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-09-30 17:23:03
(6 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 15:39:47
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:39:42.080903 2026] [security2:error] [pid 15774:tid 15815] [client 172.71.183.121:9698] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tomithai.com"] [uri "/.env.staging"] [unique_id "ar0tPq9kX7kI_J6nmPs0-QAAAYA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-30 12:07:28
(6 days ago)
[30/Sep/2026:15:07:28 +0300] -- 172.71.183.121 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[30/Sep/2026:15:07:28 +0300] -- 172.71.183.121 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /wp-config.php.bak HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 07:14:12
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 03:14:07.859170 2026] [security2:error] [pid 7486:tid 7486] [client 172.71.183.121:12758] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ageh.com"] [uri "/.env"] [unique_id "ary2vw3U3fwQ-eeTJ6B8swAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack