Anonymous
2026-10-07 11:32:58
(2 hours ago)
2026/10/07 11:28:20 [error] 3693535#3693535: *113537 [client 172.71.183.220] ModSecurity: Access den ...
show more
2026/10/07 11:28:20 [error] 3693535#3693535: *113537 [client 172.71.183.220] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.30.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "yobookz.com"] [uri "/wp-config.php"] [unique_id "179137250054.213278"] [ref ""], client: 172.71.183.220, server: yobookz.com, request: "GET /wp-config.php HTTP/2.0", host: "yobookz.com"
2026/10/07 11:28:22 [error] 3693535#3693535: *113537 [client 172.71.183.220] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-07 09:54:18
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.220 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 05:54:11.864786 2026] [security2:error] [pid 12876:tid 12876] [client 172.71.183.220:12401] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.voodooshop.com"] [uri "/wp-config.php"] [unique_id "asYWw3c36JJOx8uzgRArgAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-07 09:24:22
(4 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 08:19:01
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.220 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 04:18:53.424338 2026] [security2:error] [pid 6373:tid 6373] [client 172.71.183.220:11839] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jockoenterprises.com"] [uri "/wp-config.php.save"] [unique_id "asYAbWD8Zhlc5ZhUU0ju1QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 07:19:58
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.220 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 03:19:35.027760 2026] [security2:error] [pid 928:tid 928] [client 172.71.183.220:10799] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tonydelov.com"] [uri "/wp-config.php.bak"] [unique_id "asXyh7fJP7emuEEsNmKDpQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 04:03:01
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.220 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 00:02:35.492648 2026] [security2:error] [pid 29396:tid 29396] [client 172.71.183.220:9796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jeffautry.com"] [uri "/.env.old"] [unique_id "asXEW4UzuML8gRGbiD84EwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 02:36:53
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.220 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 22:36:27.378836 2026] [security2:error] [pid 10751:tid 10751] [client 172.71.183.220:13145] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "evolutionmedical.help"] [uri "/.env.save"] [unique_id "asWwK_MIVATdlFvD6F_zgAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-07 02:29:22
(11 hours ago)
[07/Oct/2026:05:29:21 +0300] -- 172.71.183.220 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.gi ...
show more
[07/Oct/2026:05:29:21 +0300] -- 172.71.183.220 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git-credentials HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 23:29:34
(14 hours ago)
(mod_security) mod_security (id:949110) triggered by 172.71.183.220 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 172.71.183.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 19:29:22.670291 2026] [security2:error] [pid 25986:tid 25986] [client 172.71.183.220:10237] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "cpectec.com"] [uri "/.env.local"] [unique_id "asWEUmy6wC8wjcjXk7WYpwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-10-06 22:19:45
(15 hours ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 13:44:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.220 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 09:44:54.985954 2026] [security2:error] [pid 11195:tid 11195] [client 172.71.183.220:12197] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "officechristmascards.com"] [uri "/wp-config.php.bak"] [unique_id "asT7VlOrluyoTGyeY-kfCgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 12:53:55
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 172.71.183.220 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.183.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 08:53:52.599917 2026] [security2:error] [pid 18735:tid 18735] [client 172.71.183.220:11379] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||desertalfas.org|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "desertalfas.org"] [uri "/index.php.bak"] [unique_id "asTvYHkptz3xtVKoVFDaNAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 02:40:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.220 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 22:40:45.699037 2026] [security2:error] [pid 32487:tid 32487] [client 172.71.183.220:9686] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "landjudging.com"] [uri "/.env.old"] [unique_id "asRfrbFJgE2ani_YgaxSqgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 23:13:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.220 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 19:13:07.659113 2026] [security2:error] [pid 7519:tid 7519] [client 172.71.183.220:12611] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.achildsspace.com"] [uri "/.env"] [unique_id "asQvA6F5MQubBxsB9fX0SwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-05 06:24:24
(2 days ago)
[05/Oct/2026:09:24:23 +0300] -- 172.71.183.220 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp- ...
show more
[05/Oct/2026:09:24:23 +0300] -- 172.71.183.220 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-content/plugins/woocommerce/readme.txt HTTP/1.1
show less
Bad Web Bot
Web App Attack