๐ฉ๐ช
4server
2026-10-08 05:47:22
(4 minutes ago)
[ThuOct0807:47:14.8461462026][security2:error][pid1903285:tid1903363][client172.71.183.172:0]ModSecu ...
show more
[ThuOct0807:47:14.8461462026][security2:error][pid1903285:tid1903363][client172.71.183.172:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"martinairsagl.ch\"][uri\"//.aws/credentials\"][unique_id\"ascuYrtNTDWTFh6efcgmKQAAAJE\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-10-08 05:16:10
(35 minutes ago)
2 attacks on env grabbing URLs:
GET /.env.local HTTP/1.1
Hacking
๐ฉ๐ช
raph
2026-10-08 03:53:42
(1 hour ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-10-08 01:15:12
(4 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 01:09:05
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 21:08:50.658280 2026] [security2:error] [pid 22161:tid 22161] [client 172.71.183.172:13699] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mvpbees.com"] [uri "/.env"] [unique_id "asbtIgczUAlDTA4uZJbe-AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 00:36:40
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 20:36:33.755420 2026] [security2:error] [pid 10592:tid 10592] [client 172.71.183.172:13261] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thinkerblox.com"] [uri "/.env.production"] [unique_id "asblkQyLHxrbln2wG2n6zQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 00:20:03
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 172.71.183.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.183.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 20:19:51.196008 2026] [security2:error] [pid 26054:tid 26054] [client 172.71.183.172:13227] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||watonga.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "watonga.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asbhp1n2zJcI8tQFVXDr0wAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 23:53:48
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 19:53:43.429539 2026] [security2:error] [pid 28918:tid 28918] [client 172.71.183.172:11770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crescentcitycafe.org"] [uri "/.env.bak"] [unique_id "asbbh1tbh8mCaDIYUQRQVQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
Esko
2026-10-07 23:24:10
(6 hours ago)
172.71.183.172 - - [07/Oct/2026:23:24:10 +0000] "GET /.env.bak HTTP/1.1" 488 0 "-" "Mozilla/5.0 (Win ...
show more
172.71.183.172 - - [07/Oct/2026:23:24:10 +0000] "GET /.env.bak HTTP/1.1" 488 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0"
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-07 17:37:51
(12 hours ago)
[07/Oct/2026:20:37:51 +0300] -- 172.71.183.172 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.gi ...
show more
[07/Oct/2026:20:37:51 +0300] -- 172.71.183.172 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-10-07 16:52:44
(12 hours ago)
172.71.183.172 - - [07/Oct/2026:16:51:40 +0000] "GET /.terraform/terraform.tfstate HTTP/2.0" 403 0 " ...
show more
172.71.183.172 - - [07/Oct/2026:16:51:40 +0000] "GET /.terraform/terraform.tfstate HTTP/2.0" 403 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15" "2a06:98c0:3600::103" edge="172.71.183.172"
172.71.183.172 - - [07/Oct/2026:16:51:40 +0000] "GET /.aws/credentials HTTP/2.0" 403 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15" "2a06:98c0:3600::103" edge="172.71.183.172"
172.71.183.172 - - [07/Oct/2026:16:51:40 +0000] "GET /.npmrc HTTP/2.0" 403 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0" "2a06:98c0:3600::103" edge="172.71.183.172"
172.71.183.172 - - [07/Oct/2026:16:51:40 +0000] "GET /.aws/credentials HTTP/2.0" 403 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15" "2a06:98c0:360
...
show less
Web App Attack
๐จ๐ฆ
Roper123
2026-10-07 14:51:51
(14 hours ago)
Web app exploits
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 12:05:14
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 08:05:00.523259 2026] [security2:error] [pid 12328:tid 12328] [client 172.71.183.172:11155] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michaelwakim.com"] [uri "/.git/HEAD"] [unique_id "asY1bJZdvHXsJVDLjNNRFwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-10-07 11:50:19
(18 hours ago)
172.71.183.172 - - [07/Oct/2026:11:49:16 +0000] "GET /.ssh/id_rsa HTTP/2.0" 403 0 "-" "Mozilla/5.0 ( ...
show more
172.71.183.172 - - [07/Oct/2026:11:49:16 +0000] "GET /.ssh/id_rsa HTTP/2.0" 403 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36" "2a06:98c0:3600::103" edge="172.71.183.172"
172.71.183.172 - - [07/Oct/2026:11:49:16 +0000] "GET /wp-config.php.old HTTP/2.0" 403 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36" "2a06:98c0:3600::103" edge="172.71.183.172"
172.71.183.172 - - [07/Oct/2026:11:49:16 +0000] "GET /wp-config.php.save HTTP/2.0" 403 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15" "2a06:98c0:3600::103" edge="172.71.183.172"
172.71.183.172 - - [07/Oct/2026:11:49:18 +0000] "GET /.index.php.swp HTTP/2.0" 403 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36" "2a06:98c0:3600::103" edge="172.71.183.172"
172.71.183.1
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 10:37:54
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 06:37:46.666186 2026] [security2:error] [pid 6374:tid 6374] [client 172.71.183.172:12813] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tonydelov.com"] [uri "/.htaccess"] [unique_id "asYg-p2VTIflmsaAPw-2sAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack