๐ซ๐ท
dynamix
2026-10-08 12:11:13
(8 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 09:43:21
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 05:43:14.292611 2026] [security2:error] [pid 610:tid 610] [client 172.71.183.58:13083] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vrmapping.net"] [uri "/.env.dev"] [unique_id "asdlsjsKexLvh2WiH3iWsQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 06:17:52
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 02:17:47.458855 2026] [security2:error] [pid 15465:tid 15465] [client 172.71.183.58:13120] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jerryhetrick.com"] [uri "/.env.staging"] [unique_id "asc1i2QosbhN9jz9OvT17AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 03:59:15
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 23:59:09.895582 2026] [security2:error] [pid 14015:tid 14015] [client 172.71.183.58:10130] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "captechtraining.com"] [uri "/wp-config.php.bak"] [unique_id "ascVDWXOSzHOpH0dfU4I_wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-10-08 03:53:42
(16 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 01:46:28
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 21:46:20.119341 2026] [security2:error] [pid 23526:tid 23545] [client 172.71.183.58:10846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arthansl.com"] [uri "/wp-config.php.save"] [unique_id "asb17OVKUgM-nzSURvCmPgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐น
Information Security
2026-10-08 01:29:03
(19 hours ago)
Web App Attack
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 01:09:04
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 21:08:54.762566 2026] [security2:error] [pid 22165:tid 22165] [client 172.71.183.58:9324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mvpbees.com"] [uri "/.htaccess"] [unique_id "asbtJkNwje-twMrnlAEcSwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-08 00:55:02
(19 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐ธ๐ช
Esko
2026-10-07 23:24:24
(21 hours ago)
172.71.183.58 - - [07/Oct/2026:23:24:24 +0000] "GET /index.php.txt HTTP/1.1" 488 0 "-" "Mozilla/5.0 ...
show more
172.71.183.58 - - [07/Oct/2026:23:24:24 +0000] "GET /index.php.txt HTTP/1.1" 488 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 21:59:06
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 172.71.183.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.183.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 17:58:59.089646 2026] [security2:error] [pid 2106:tid 2106] [client 172.71.183.58:11875] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||deafinitely.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "deafinitely.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asbAo9f1ATfbiRR0Yr_TJQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-07 21:06:36
(23 hours ago)
[08/Oct/2026:00:06:36 +0300] -- 172.71.183.58 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[08/Oct/2026:00:06:36 +0300] -- 172.71.183.58 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.save HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 19:14:42
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 172.71.183.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.183.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 15:14:18.683675 2026] [security2:error] [pid 30431:tid 30431] [client 172.71.183.58:9828] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||i-spose.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "i-spose.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asaaCokHBIR6OZcRNImClgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
p0tatosmash3r
2026-10-07 18:20:30
(1 day ago)
Honeypot-observed malicious activity: unauth data-store / config enumeration; data-store enumeration ...
show more
Honeypot-observed malicious activity: unauth data-store / config enumeration; data-store enumeration.
show less
Web App Attack
Bad Web Bot
๐จ๐ฆ
Roper123
2026-10-07 14:54:15
(1 day ago)
Web app exploits
Web App Attack