๐บ๐ธ
TPI-Abuse
2026-10-08 05:41:59
(49 minutes ago)
(mod_security) mod_security (id:210730) triggered by 172.71.183.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.183.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 01:41:47.498250 2026] [security2:error] [pid 11657:tid 11657] [client 172.71.183.77:9954] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.stoneageartifacts.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.stoneageartifacts.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asctGz0ulOzpmWLYv8u48gAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 03:12:22
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 23:12:16.511336 2026] [security2:error] [pid 25669:tid 25669] [client 172.71.183.77:9281] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tcmu.org"] [uri "/.env.backup"] [unique_id "ascKELhZd9baznqePIMFegAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 01:08:19
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 21:08:08.847121 2026] [security2:error] [pid 25202:tid 25212] [client 172.71.183.77:12774] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sailcleaner.com"] [uri "/.svn/entries"] [unique_id "asbs-L3QtO2XMYcgzoSd5gAAAQg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-08 00:25:21
(6 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 23:40:06
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 19:39:50.806484 2026] [security2:error] [pid 23990:tid 23990] [client 172.71.183.77:13640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cruisingforsex.com"] [uri "/.env.save"] [unique_id "asbYRqXo2hTgsDQIw82-pAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 23:10:44
(7 hours ago)
(mod_security) mod_security (id:949110) triggered by 172.71.183.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 172.71.183.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 19:10:34.581389 2026] [security2:error] [pid 1552:tid 1552] [client 172.71.183.77:13969] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "21oaksfarm.com"] [uri "/%2eenv"] [unique_id "asbRar3fQeiUoR9gOV7mHgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 22:01:04
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 18:00:58.478436 2026] [security2:error] [pid 12972:tid 12972] [client 172.71.183.77:10819] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "televisonic.com"] [uri "/.env.save"] [unique_id "asbBGhEhuYOm4seU7YBUcQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 21:41:24
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 17:41:16.710079 2026] [security2:error] [pid 23216:tid 23216] [client 172.71.183.77:10971] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davidtempleofdeliverance.org"] [uri "/.env.save"] [unique_id "asa8fOtpAf8wuPUE4TEFaQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 19:03:44
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 15:03:39.886345 2026] [security2:error] [pid 26433:tid 26433] [client 172.71.183.77:9977] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "safeharbourfund.com"] [uri "/.git/HEAD"] [unique_id "asaXi5jVrokQ4Fe2DULKGQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 11:16:58
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 07:16:48.102207 2026] [security2:error] [pid 25452:tid 25452] [client 172.71.183.77:10895] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "riedmannfamily.com"] [uri "/.env.staging"] [unique_id "asYqIGrwPqIwiL0mpqL4WAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 06:39:20
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 02:39:15.024837 2026] [security2:error] [pid 32522:tid 32522] [client 172.71.183.77:13817] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cook-islands-boat-registration.com"] [uri "/.env.old"] [unique_id "asXpE1Dup3ZfiI-OsL3mjAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
gszasz
2026-10-07 06:03:08
(1 day ago)
[Wed Oct 07 01:00:53.684307 2026] [authz_core:error] [pid 5227:tid 5258] [client 172.71.183.77:13083 ...
show more
[Wed Oct 07 01:00:53.684307 2026] [authz_core:error] [pid 5227:tid 5258] [client 172.71.183.77:13083] AH01630: client denied by server configuration: /srv/magnetic17.physics.muni.cz/www/.htaccess
[Wed Oct 07 01:33:31.510337 2026] [authz_core:error] [pid 4991:tid 5133] [client 172.71.183.77:11455] AH01630: client denied by server configuration: /srv/magnetic17.physics.muni.cz/www/.htaccess
[Wed Oct 07 08:03:08.095705 2026] [authz_core:error] [pid 51912:tid 51950] [client 172.71.183.77:12056] AH01630: client denied by server configuration: /srv/magnetic17.physics.muni.cz/www/.htaccess
...
show less
Brute-Force
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-07 05:58:07
(1 day ago)
[07/Oct/2026:08:58:07 +0300] -- 172.71.183.77 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[07/Oct/2026:08:58:07 +0300] -- 172.71.183.77 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.staging HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-10-07 05:14:27
(1 day ago)
6 attacks on env grabbing URLs:
GET /.env.production HTTP/1.1
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-07 02:13:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 22:13:10.011805 2026] [security2:error] [pid 6069:tid 6069] [client 172.71.183.77:9400] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.register-yacht-cook-islands.com"] [uri "/wp-config.php.save"] [unique_id "asWqto2jIl3IYwpybmvMwgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack