๐บ๐ธ
TPI-Abuse
2026-09-30 15:42:18
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:42:10.810066 2026] [security2:error] [pid 29734:tid 29734] [client 172.71.183.41:11201] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "caralis.com"] [uri "/.env.local"] [unique_id "ar0t0igpkFrgmCYzjFtv6gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 13:56:06
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:56:00.074999 2026] [security2:error] [pid 4034:tid 4034] [client 172.71.183.41:10604] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.n3fjp.com"] [uri "/.env.backup"] [unique_id "ar0U8N2ROk2TmRuL_1EtcwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 13:20:05
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 172.71.183.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.183.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:19:57.275170 2026] [security2:error] [pid 6891:tid 6891] [client 172.71.183.41:11107] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||performingartsguild.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "performingartsguild.com"] [uri "/index.php.bak"] [unique_id "ar0MfX1AiJ4CJvJE9bNeuAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:50:19
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:50:13.777826 2026] [security2:error] [pid 19126:tid 19126] [client 172.71.183.41:13805] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.margroberts.com"] [uri "/.svn/entries"] [unique_id "ar0FhfUBJvlHepAlkkeAYQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-30 12:09:30
(17 hours ago)
[30/Sep/2026:15:09:29 +0300] -- 172.71.183.41 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[30/Sep/2026:15:09:29 +0300] -- 172.71.183.41 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.staging HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 04:23:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 00:23:53.326695 2026] [security2:error] [pid 13311:tid 13311] [client 172.71.183.41:11695] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "binglawoffice.com"] [uri "/.svn/entries"] [unique_id "aryO2QnakrBbJlCuZ4TZKwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 03:57:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 23:57:05.961195 2026] [security2:error] [pid 1058:tid 1058] [client 172.71.183.41:12471] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3beeze.com"] [uri "/.svn/entries"] [unique_id "aryIkaa4u7t_Y5vwuIdlIwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 15:22:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 11:22:50.862214 2026] [security2:error] [pid 19279:tid 19279] [client 172.71.183.41:9772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ferrarapanfitness.com"] [uri "/.env.backup"] [unique_id "arvXyogD0Rp_dxub-tQ1-QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
Erpelstolz
2026-09-29 03:29:57
(2 days ago)
external host: 172.71.183.41 - - [29/Sep/2026:05:29:57 +0200] "GET /wp-content/plugins/woocommerce/r ...
show more
external host: 172.71.183.41 - - [29/Sep/2026:05:29:57 +0200] "GET /wp-content/plugins/woocommerce/readme.txt HTTP/1.1" 404 6217 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0" CF-Ray:a427e80bb8ae0bb0-AMS CF-IP:-
show less
Web App Attack
๐ฉ๐ช
bescared
2026-09-28 23:40:08
(2 days ago)
F2B - Malicious activity detected. URL Probing. -8ff06ede-
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 18:30:20
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 14:30:10.517298 2026] [security2:error] [pid 24564:tid 24564] [client 172.71.183.41:14127] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "naomipyle.com"] [uri "/.env.staging"] [unique_id "arqyMlbDFPiajQLrKzXyZgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 16:22:27
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 12:22:21.339306 2026] [security2:error] [pid 1821:tid 1821] [client 172.71.183.41:10785] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "croixlac.com"] [uri "/.env.production"] [unique_id "arqUPeCM6d8PxmMka_FCXQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-09-28 12:58:44
(2 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, source_backup, git_exposure, aws_creds. Observed by 1 sensor(s); 5 hits.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 12:26:38
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 08:26:31.521809 2026] [security2:error] [pid 20998:tid 20998] [client 172.71.183.41:11095] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drjaymissdiana.com"] [uri "/.env.local"] [unique_id "arpc9wllNdNmTTZdcixLvgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-28 07:55:11
(2 days ago)
[MonSep2809:55:09.4284062026][security2:error][pid570752:tid570841][client172.71.183.41:0]ModSecurit ...
show more
[MonSep2809:55:09.4284062026][security2:error][pid570752:tid570841][client172.71.183.41:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.restaurantgandria.ch\"][uri\"/.env.local\"][unique_id\"arodXbyGWO7S7_LH3ulcAgAAAMM\"]
show less
Port Scan
Brute-Force
Web App Attack