πΊπΈ
TPI-Abuse
2026-10-07 19:06:16
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 15:06:10.009312 2026] [security2:error] [pid 9787:tid 9787] [client 172.71.183.178:13914] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "disneylawsuit.com"] [uri "/wp-config.php.old"] [unique_id "asaYIhUjg2zSSqrubPkVxQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
p0tatosmash3r
2026-10-07 18:17:08
(22 hours ago)
Honeypot-observed malicious activity: unauth data-store / config enumeration; data-store enumeration ...
show more
Honeypot-observed malicious activity: unauth data-store / config enumeration; data-store enumeration.
show less
Web App Attack
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-10-07 14:55:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 10:54:53.660292 2026] [security2:error] [pid 12796:tid 12802] [client 172.71.183.178:14327] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "certifiedprojectmanager.net"] [uri "/.env.backup"] [unique_id "asZdPc2_uG2AtAKabQwvJQAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 13:40:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 09:40:38.078138 2026] [security2:error] [pid 437:tid 437] [client 172.71.183.178:11724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stukabird.com"] [uri "/.env"] [unique_id "asZL1rFdaw1XKsiNUHFh4wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-07 07:27:15
(1 day ago)
Sensitive Configuration File Disclosure.
Hacking
πΊπΈ
TPI-Abuse
2026-10-06 20:57:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 16:57:04.157524 2026] [security2:error] [pid 14777:tid 14777] [client 172.71.183.178:10667] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jsommer.com"] [uri "/.svn/entries"] [unique_id "asVgoO9qY0dqut4sWEor-gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-06 13:08:54
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 09:08:33.180913 2026] [security2:error] [pid 27058:tid 27058] [client 172.71.183.178:11427] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kmelson.com"] [uri "/.env.local"] [unique_id "asTy0XmUILtux9Qg2GKu8QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-06 10:50:04
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 06:49:48.143021 2026] [security2:error] [pid 31407:tid 31407] [client 172.71.183.178:12772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "honeybeeplace.com"] [uri "/.htaccess"] [unique_id "asTSTCmBwFTpg4c_3lmFjwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
bohl-aiG5aef
2026-10-06 09:58:41
(2 days ago)
Suricata Alert [SID:2031502] ET INFO Request to Hidden Environment File - Inbound
Hacking
πΊπΈ
TPI-Abuse
2026-10-05 22:54:06
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 18:53:58.839606 2026] [security2:error] [pid 23224:tid 23224] [client 172.71.183.178:9316] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "horsesaw.com"] [uri "/.git/HEAD"] [unique_id "asQqhoyYYzGQmhKb7H3QpgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
altenglaner
2026-10-05 22:22:32
(2 days ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
πΊπ¦
URAN Publishing Service
2026-10-01 14:54:03
(1 week ago)
[01/Oct/2026:17:54:03 +0300] -- 172.71.183.178 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[01/Oct/2026:17:54:03 +0300] -- 172.71.183.178 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env HTTP/1.1
show less
Bad Web Bot
Web App Attack
πͺπΈ
bohl-aiG5aef
2026-10-01 08:19:54
(1 week ago)
Suricata Alert [SID:2031502] ET INFO Request to Hidden Environment File - Inbound
Hacking
πΊπΈ
TPI-Abuse
2026-10-01 07:48:07
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 03:48:01.485589 2026] [security2:error] [pid 19651:tid 19651] [client 172.71.183.178:13912] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stickittomebuttons.com"] [uri "/.env.production"] [unique_id "ar4QMQ3Jons_ySHgwn6aJAAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
altenglaner
2026-10-01 07:05:41
(1 week ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack