๐บ๐ธ
TPI-Abuse
2026-09-30 10:22:34
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 06:22:28.675631 2026] [security2:error] [pid 9630:tid 9650] [client 172.71.183.29:14250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "laradioactivitat.com"] [uri "/wp-config.php"] [unique_id "arzi5NKzO979YClGXiGKXgAAAIw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 23:35:11
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 19:35:07.639497 2026] [security2:error] [pid 5749:tid 5749] [client 172.71.183.29:11956] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.claireashton.com"] [uri "/.git/HEAD"] [unique_id "arxLKxOol6iYKE28MzkJ4gAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 08:26:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 04:26:13.006318 2026] [security2:error] [pid 7244:tid 7244] [client 172.71.183.29:9282] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.disenowebprofesional.com"] [uri "/.env.production"] [unique_id "art2Jbeavbh4KPwk870KXgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 05:10:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 01:10:45.171700 2026] [security2:error] [pid 3970:tid 3970] [client 172.71.183.29:11572] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "qavideo.com"] [uri "/.env.production"] [unique_id "artIVb-H-CxM4NTGWyVQJQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 18:30:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 14:30:51.873052 2026] [security2:error] [pid 18364:tid 18364] [client 172.71.183.29:11379] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crowmoonmarketing.com"] [uri "/.env.local"] [unique_id "arqyW-KrgU9h93B5y62jUAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 07:43:35
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 03:43:29.568381 2026] [security2:error] [pid 10816:tid 10816] [client 172.71.183.29:13376] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "universitydental.org"] [uri "/.svn/entries"] [unique_id "aroaoWRfmdR24lNOBsrYGQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-09-27 14:11:35
(3 days ago)
Wordpress hacking attempt
Web App Attack
๐บ๐ธ
craudiovizai
2026-09-27 06:30:36
(3 days ago)
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. ...
show more
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. Blocked at the edge.
show less
Web App Attack
Bad Web Bot
๐ฉ๐ช
MusicLibrary
2026-09-26 13:32:36
(4 days ago)
Probing foreign-stack admin panels / known exploit paths (Joomla, phpMyAdmin, phpunit, OWA, etc.)
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 13:31:39
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 09:31:32.887368 2026] [security2:error] [pid 4050:tid 4124] [client 172.71.183.29:12478] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "larryfoussconstruction.com"] [uri "/.env.backup"] [unique_id "arfJNBeZ7DrgD6li4pm5aQAAAYg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-26 12:25:18
(4 days ago)
[26/Sep/2026:15:25:18 +0300] -- 172.71.183.29 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[26/Sep/2026:15:25:18 +0300] -- 172.71.183.29 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /config.json HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ต๐ฑ
gandaflux
2026-09-26 11:52:16
(4 days ago)
172.71.183.29 [redacted-domain] - [26/Sep/2026:13:52:05 +0200] "GET /.env.local HTTP/2.0" 403 158 "- ...
show more
172.71.183.29 [redacted-domain] - [26/Sep/2026:13:52:05 +0200] "GET /.env.local HTTP/2.0" 403 158 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15"
172.71.183.29 [redacted-domain] - [26/Sep/2026:13:52:05 +0200] "GET /.env.backup HTTP/2.0" 403 158 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15"
172.71.183.29 [redacted-domain] - [26/Sep/2026:13:52:12 +0200] "GET /.git/HEAD HTTP/2.0" 403 158 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 08:48:01
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 04:47:53.518693 2026] [security2:error] [pid 6578:tid 6578] [client 172.71.183.29:9547] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.malta-boat-registration.com"] [uri "/.env.production"] [unique_id "areGuWqPS6RqBLFcvenf4wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-09-25 03:38:20
(5 days ago)
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-09-24 21:46:08
(5 days ago)
Wordpress hacking attempt
Web App Attack