๐บ๐ธ
TPI-Abuse
2026-10-01 03:33:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 23:33:18.782878 2026] [security2:error] [pid 23160:tid 23160] [client 172.71.183.213:10275] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.soonerstone.com"] [uri "/.git/HEAD"] [unique_id "ar3UfnlsCsdNITEzMNhZdQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 15:24:36
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:24:33.550241 2026] [security2:error] [pid 17892:tid 17892] [client 172.71.183.213:10404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "paulpasquali.com"] [uri "/.env"] [unique_id "ar0psbkfyTssEHFbRILwfAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ฐ
donkzquixote
2026-09-30 14:18:35
(2 days ago)
Scan for exploitable WordPress files/information, or other brute force attempts.
Web App Attack
๐ฉ๐ช
altenglaner
2026-09-30 12:35:57
(2 days ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 02:51:13
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 172.71.183.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.183.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 22:51:07.387492 2026] [security2:error] [pid 15917:tid 15917] [client 172.71.183.213:10653] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.damonmarks.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.damonmarks.com"] [uri "/index.php.bak"] [unique_id "arx5GzD7AsFiGUo8hDIsHgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 20:47:46
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 16:47:41.519347 2026] [security2:error] [pid 27475:tid 27516] [client 172.71.183.213:9462] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "onenessrecords.com"] [uri "/.env.production"] [unique_id "arwj7WPybf0DxqWVYt6C3QAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 17:42:01
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 13:41:54.299598 2026] [security2:error] [pid 16930:tid 16942] [client 172.71.183.213:13992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gilesrentalcars.com"] [uri "/.env"] [unique_id "arv4YkV-I8z-1Xe_8tgmggAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 16:06:51
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 12:06:45.393077 2026] [security2:error] [pid 31106:tid 31106] [client 172.71.183.213:12608] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.register-yacht-uk.com"] [uri "/.env"] [unique_id "arviFSP1iP91zEzbvDs_BgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
cg-design.co.uk
2026-09-29 15:34:15
(3 days ago)
(mod_security) mod_security triggered on hostname [redacted] 172.71.183.213 (-)
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-29 02:44:31
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 22:44:22.696953 2026] [security2:error] [pid 21785:tid 21785] [client 172.71.183.213:11743] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bluegrassexpressband.com"] [uri "/.env.staging"] [unique_id "arsmBuZTehhIspcs6fr39gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-28 20:35:05
(3 days ago)
/.env.backup
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 15:31:30
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 11:31:24.611724 2026] [security2:error] [pid 28249:tid 28249] [client 172.71.183.213:14251] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "natural-history-conservation.com"] [uri "/.env"] [unique_id "arqITAq4kEYpzoJ1lt_SjwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 11:11:06
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 07:10:57.219369 2026] [security2:error] [pid 9390:tid 9390] [client 172.71.183.213:11037] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.midway-island.com"] [uri "/.env"] [unique_id "arpLQZOShp4W73yPXyZZAwAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-26 13:26:58
(6 days ago)
[26/Sep/2026:16:26:58 +0300] -- 172.71.183.213 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.en ...
show more
[26/Sep/2026:16:26:58 +0300] -- 172.71.183.213 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.backup HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
Lee Daniel
2026-09-26 08:48:52
(6 days ago)
172.71.183.213 - - [26/Sep/2026:04:48:51 -0400] "GET /.aws/credentials HTTP/1.1" 404 6293 "-" "Mozil ...
show more
172.71.183.213 - - [26/Sep/2026:04:48:51 -0400] "GET /.aws/credentials HTTP/1.1" 404 6293 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack