๐บ๐ธ
TPI-Abuse
2026-10-08 15:34:33
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 11:34:17.998559 2026] [security2:error] [pid 20126:tid 20126] [client 172.71.183.97:10873] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "soglove.com"] [uri "/.env.old"] [unique_id "ase3-R4xrgnzts_DK4BgAAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 12:12:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 08:11:56.618017 2026] [security2:error] [pid 28091:tid 28091] [client 172.71.183.97:12693] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "enriquejezik.com"] [uri "/.git/config"] [unique_id "aseIjLIxifKHwyV7mkO_pQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-08 07:09:27
(1 day ago)
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 172.71.183.97 - - [08/Oct/2026:09:09:17 +0200] "GET /wp-config.php.old HTTP/2.0" 301 470 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 06:18:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 02:18:11.667902 2026] [security2:error] [pid 3840:tid 3869] [client 172.71.183.97:12936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.southtampaprinting.com"] [uri "/.env.production"] [unique_id "asc1o1yNHKJtVPszKReaDgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-08 05:44:35
(1 day ago)
Sensitive Configuration File Disclosure.
Hacking
๐ซ๐ท
dynamix
2026-10-08 05:37:04
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 04:58:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 00:58:04.380046 2026] [security2:error] [pid 13720:tid 13720] [client 172.71.183.97:12799] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mightyhoop.com"] [uri "/.env.old"] [unique_id "asci3MSEXBWve2WB4bwVbQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
dominioz
2026-10-08 04:13:21
(1 day ago)
2026-10-08 04:13:07 GET /%2f%2eaws%2fcredentials - - 172.71.183.97 HTTP/1.1 Mozilla/5.0+(Macintosh;+ ...
show more
2026-10-08 04:13:07 GET /%2f%2eaws%2fcredentials - - 172.71.183.97 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/122.0.0.0+Safari/537.36 - 301 0
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 04:05:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 00:04:57.182859 2026] [security2:error] [pid 30540:tid 30540] [client 172.71.183.97:10089] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "circlehealthcaregroup.com"] [uri "/.svn/entries"] [unique_id "ascWaQ_TvLY8_9WFL7fStgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 03:38:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 23:38:19.035018 2026] [security2:error] [pid 7686:tid 7686] [client 172.71.183.97:9966] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jdubindustries.com"] [uri "/wp-config.php"] [unique_id "ascQK_H1HoWgIDDGgolUpwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 01:23:41
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 172.71.183.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.183.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 21:23:10.027047 2026] [security2:error] [pid 15189:tid 15189] [client 172.71.183.97:9889] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||williamgilcher.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "williamgilcher.com"] [uri "/index.php.bak"] [unique_id "asbwfhoteH9wcGGwMiUD2gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 00:21:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 20:21:32.360674 2026] [security2:error] [pid 26342:tid 26342] [client 172.71.183.97:12979] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "resilientigm.com"] [uri "/.env.old"] [unique_id "asbiDI5jB-xG5XsrREIY2QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 23:11:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 19:11:09.427129 2026] [security2:error] [pid 19965:tid 19965] [client 172.71.183.97:10017] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "majersigns.com"] [uri "/wp-config.php.bak"] [unique_id "asbRjbdIi_i37pzppgTZFgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 22:45:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.183.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.183.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 18:45:17.267294 2026] [security2:error] [pid 10734:tid 10734] [client 172.71.183.97:12956] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jennyfiore.com"] [uri "/.env.staging"] [unique_id "asbLfT2V9nXl3G5lbXb2hAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-10-07 20:19:30
(1 day ago)
[WedOct0722:19:19.7382432026][security2:error][pid83599:tid83610][client172.71.183.97:0]ModSecurity: ...
show more
[WedOct0722:19:19.7382432026][security2:error][pid83599:tid83610][client172.71.183.97:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"710\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"4hosts.net\"][uri\"/.env.local\"][unique_id\"asapR_LSMpmNrhelD3tu4AAAAAc\"]
show less
Hacking
Web App Attack