๐ณ๐ฑ
BlueWire Hosting
2026-10-10 19:16:13
(1 hour ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 08:12:48
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 04:12:34.617093 2026] [security2:error] [pid 28291:tid 28291] [client 172.71.183.159:11416] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shtondo.com"] [uri "/.env.dev"] [unique_id "asnzcqSbOcLSBIHshMDDNQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 05:36:05
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 01:35:52.693882 2026] [security2:error] [pid 6146:tid 6146] [client 172.71.183.159:11201] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "va-designers.com"] [uri "/wp-config.php.bak"] [unique_id "asnOuP3ea9dk_puNtwNhXAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 01:12:18
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 21:11:55.456323 2026] [security2:error] [pid 3351:tid 3351] [client 172.71.183.159:12986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "midway-island.com"] [uri "/.env.staging"] [unique_id "asg_W4jtiaWLA6kmsk7keQAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 21:52:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 17:52:17.890519 2026] [security2:error] [pid 3579:tid 3587] [client 172.71.183.159:10375] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "credit-protector.com"] [uri "/.env.staging"] [unique_id "asgQkYrwhCJbtLhWWf-8JwAAAIY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 11:16:05
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 172.71.183.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.183.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 07:15:50.404821 2026] [security2:error] [pid 6621:tid 6621] [client 172.71.183.159:9579] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||periodthreads.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "periodthreads.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asd7ZhVsT9oa33-1u4VxggAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 06:36:56
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 02:36:39.990256 2026] [security2:error] [pid 20015:tid 20015] [client 172.71.183.159:14054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "achari.com"] [uri "/.env.save"] [unique_id "asc596yB7ojMOz_niXh9FwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 03:59:07
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 23:59:02.217766 2026] [security2:error] [pid 13141:tid 13141] [client 172.71.183.159:13318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "captechtraining.com"] [uri "/.env.save"] [unique_id "ascVBm_O2tpDcvbQbSoHJwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 23:59:09
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 172.71.183.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.183.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 19:59:02.090207 2026] [security2:error] [pid 23587:tid 23590] [client 172.71.183.159:9770] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pattinauction.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pattinauction.com"] [uri "/index.php.bak"] [unique_id "asbcxmBA89UEkXv5itR8DwAAAME"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-07 20:36:24
(3 days ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 20:12:24
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 16:12:18.342142 2026] [security2:error] [pid 11614:tid 11614] [client 172.71.183.159:13807] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "killeenbarrelsandtotes.com"] [uri "/.htaccess"] [unique_id "asanou_Bc5tnz-s9Cbyo0QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 19:56:22
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 15:56:14.445843 2026] [security2:error] [pid 3350:tid 3350] [client 172.71.183.159:11423] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "universitydental.org"] [uri "/.env.production"] [unique_id "asaj3qMB2lLrDdVbX_Lf7QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-07 05:17:57
(3 days ago)
[07/Oct/2026:08:17:57 +0300] -- 172.71.183.159 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.en ...
show more
[07/Oct/2026:08:17:57 +0300] -- 172.71.183.159 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.old HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-06 20:07:44
(4 days ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 15:53:10
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 11:53:06.093216 2026] [security2:error] [pid 15908:tid 15908] [client 172.71.183.159:13719] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "foundintranslation.net"] [uri "/wp-config.php"] [unique_id "asUZYmUjXV5AMx0wuG72TwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack