๐บ๐ธ
TPI-Abuse
2026-10-11 00:45:51
(41 minutes ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 20:45:46.483564 2026] [security2:error] [pid 9541:tid 9541] [client 172.71.183.79:10046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wea-inc.com"] [uri "/.env.bak"] [unique_id "asrcOg_6bibwiKQPTW8AMQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 23:43:34
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 19:43:28.385633 2026] [security2:error] [pid 15652:tid 15652] [client 172.71.183.79:12638] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pfs-nj.com"] [uri "/.env.backup"] [unique_id "asrNoH8TQP3M-L2dwVoVxAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-10 23:15:30
(2 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
Hary74656
2026-10-10 18:48:53
(6 hours ago)
Fail2Ban on schani.hostmi.at: jail=apache-modsecurity, failures=3.
[earlier text truncated]
und_anom ...
show more
Fail2Ban on schani.hostmi.at: jail=apache-modsecurity, failures=3.
[earlier text truncated]
und_anomaly_score. [file "/opt/owasp-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.30.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "aschi.at"] [uri "/index.php.save"] [unique_id "asqIjh5vYMJIrAet6LTnEgAA1Rg"]
[Sat Oct 10 20:48:52.543126 2026] [vhost aschi.at] [security2:error] [pid 363030:tid 140590279775936] [client 172.71.183.79:9610] [realclient 172.71.183.79:9610] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/opt/owasp-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.30.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "aschi.at"] [uri "/.index.php.swp"] [unique_id "asqIlB5vYMJIrAet6LTnIAAA2BE"]
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 11:16:47
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 07:16:39.724082 2026] [security2:error] [pid 18885:tid 18913] [client 172.71.183.79:12453] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "leadingedgesupply.com"] [uri "/.env.save"] [unique_id "asoel7YucE_E7iikhHlWhwAAARc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 01:55:03
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 21:54:52.070092 2026] [security2:error] [pid 14572:tid 14572] [client 172.71.183.79:11109] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mcbrearty.org"] [uri "/.env"] [unique_id "asma7DpHSG_6N7zGoat_cAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
Gem
2026-10-09 22:08:01
(1 day ago)
Unauthorized web scan.
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-09 15:05:11
(1 day ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 12:03:03
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 172.71.183.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.183.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 08:02:56.360184 2026] [security2:error] [pid 22527:tid 22527] [client 172.71.183.79:10247] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||curts.net|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "curts.net"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asjX8EFG8oJoRn7x5qRSYAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
crispi
2026-10-09 10:39:46
(1 day ago)
Port scan from 172.71.183.79
Port Scan
๐ฎ๐ฉ
David Koswari
2026-10-08 06:39:00
(2 days ago)
REQ_BLOCKED_ACL
DDoS Attack
FTP Brute-Force
Ping of Death
Port Scan
Hacking
SQL Injection
Spoofing
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
IoT Targeted
๐บ๐ธ
TPI-Abuse
2026-10-08 03:31:54
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 23:31:47.125925 2026] [security2:error] [pid 4276:tid 4276] [client 172.71.183.79:9606] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dreamingofatlantis.com"] [uri "/.env.bak"] [unique_id "ascOo0vIXyvYFtPb-m34BgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 03:15:00
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 23:14:50.676840 2026] [security2:error] [pid 7186:tid 7186] [client 172.71.183.79:13941] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "netstatsolutions.com"] [uri "/.env.production"] [unique_id "ascKqkgxlNbqtV8mhV_9DQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 01:23:31
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 21:23:25.390081 2026] [security2:error] [pid 14897:tid 14919] [client 172.71.183.79:11440] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "peoplecomeup.net"] [uri "/.env.old"] [unique_id "asbwjfEVZSeFiiHjJsqFAgAAAU4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-08 00:21:11
(3 days ago)
172.71.183.79 - - [08/Oct/2026:02:21:08 +0200] "GET /. HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Macintosh ...
show more
172.71.183.79 - - [08/Oct/2026:02:21:08 +0200] "GET /. HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15"
show less
Web App Attack