πΊπΈ
TPI-Abuse
2026-10-08 13:56:05
(15 hours ago)
(mod_security) mod_security (id:949110) triggered by 172.71.183.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 172.71.183.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 09:55:58.983117 2026] [security2:error] [pid 22279:tid 22279] [client 172.71.183.13:9800] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "sunstrongmetal.com"] [uri "/.env.old"] [unique_id "aseg7mb-qKmkJEiMAA35LgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
ππΊ
bcsaba
2026-10-08 00:11:19
(1 day ago)
Suricata: Alert - ET INFO Request to Hidden Environment File - Inbound
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 18:58:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 14:58:30.756092 2026] [security2:error] [pid 7310:tid 7310] [client 172.71.183.13:12345] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rodzillacharters.com"] [uri "/.env"] [unique_id "asaWVu1vqv9ZA_JrQkFsHAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 12:48:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 08:48:32.678387 2026] [security2:error] [pid 14914:tid 14914] [client 172.71.183.13:12910] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davidtempleofdeliverance.org"] [uri "/.env.backup"] [unique_id "asY_oOSm_hVJa6X4vjNdSgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 10:48:44
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 172.71.183.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.183.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 06:48:39.521902 2026] [security2:error] [pid 18767:tid 18767] [client 172.71.183.13:13835] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||staging.lindenwoodpark.org|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "staging.lindenwoodpark.org"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asYjh1IAHXxN00v5t6WTsgAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 08:26:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 04:26:31.649298 2026] [security2:error] [pid 6614:tid 6614] [client 172.71.183.13:13435] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cdromline.com"] [uri "/.env.local"] [unique_id "asYCN6mIK4ywB0NTmhl0PAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 06:30:38
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 172.71.183.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.183.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 02:30:32.222174 2026] [security2:error] [pid 21318:tid 21318] [client 172.71.183.13:14091] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||evolutionmedical.help|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "evolutionmedical.help"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asXnCN6kPYfDO6STaxRALgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-10-07 05:15:41
(2 days ago)
[07/Oct/2026:08:15:40 +0300] -- 172.71.183.13 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-c ...
show more
[07/Oct/2026:08:15:40 +0300] -- 172.71.183.13 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-config.php.save HTTP/1.1
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-06 14:46:40
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 10:46:36.401471 2026] [security2:error] [pid 16477:tid 16477] [client 172.71.183.13:11145] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pjbruner.com"] [uri "/.env.staging"] [unique_id "asUJzPot1F1z59LH9QzPuQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-06 08:30:15
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 04:29:19.541869 2026] [security2:error] [pid 29337:tid 29337] [client 172.71.183.13:14156] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "csennews.com"] [uri "/.env.old"] [unique_id "asSxX1GvEuuCO1HcOqCPiwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-06 08:10:34
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 04:10:28.060352 2026] [security2:error] [pid 29159:tid 29159] [client 172.71.183.13:13865] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "epicjellyfish.com"] [uri "/.env.backup"] [unique_id "asSs9PSEHPq1sVPWBUiExgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-04 03:15:27
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 23:15:22.662493 2026] [security2:error] [pid 8602:tid 8602] [client 172.71.183.13:10693] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "landjudging.com"] [uri "/.htaccess"] [unique_id "asHEyg-yPUxrQDs_B3yg8gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 19:05:19
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 15:05:15.756817 2026] [security2:error] [pid 4938:tid 4938] [client 172.71.183.13:11242] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "decroos.org"] [uri "/.git/HEAD"] [unique_id "ar6u6-szgbTVNzh3LERFtgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 20:02:26
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 16:02:18.093441 2026] [security2:error] [pid 31558:tid 31558] [client 172.71.183.13:10415] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blindshine.com"] [uri "/.env"] [unique_id "arwZShejD51hUBM9YhpKtQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 08:24:09
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 04:24:02.797713 2026] [security2:error] [pid 26546:tid 26546] [client 172.71.183.13:12742] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ashleycroft.com"] [uri "/.env.backup"] [unique_id "art1osLuogwBxpk_hg5OuQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack