๐ฎ๐ฉ
securejdprop
2026-08-28 17:46:15
(3 weeks ago)
This IP was detected by CrowdSec triggering custom/vpatch-bad-cloudflare.
Hacking
๐ฎ๐น
CoreTech srl
2026-08-22 12:18:55
(3 weeks ago)
cloudlinux2 fail2ban: 2026-08-22 14:14:08,288 fail2ban.filter [1480]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-22 14:14:08,288 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 103.13.43.18 - 2026-08-22 14:14:08cloudlinux2 fail2ban: 2026-08-22 14:15:03,432 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 172.71.190.138 - 2026-08-22 14:15:03cloudlinux2 fail2ban: 2026-08-22 14:15:03,716 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 104.28.196.79 - 2026-08-22 14:15:03cloudlinux2 fail2ban: 2026-08-22 14:15:03,703 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 104.22.101.82 - 2026-08-22 14:15:03cloudlinux2 fail2ban: 2026-08-22 14:15:03,685 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 104.28.196.79 - 2026-08-22 14:15:03cloudlinux2 fail2ban: 2026-08-22 14:15:03,520 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 104.28.196.79 - 2026-08-22 14:15:03cloudlinux2 fail2ban: 2026-08-22 14:15:03,939 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 104.28.196.79 - 2026-08-22 14:
show less
Brute-Force
๐ซ๐ท
Baking333
2026-08-19 13:49:01
(4 weeks ago)
[redacted] 172.71.190.138 - - [19/Aug/2026:14:48:40 +0100] "GET /apps/api/.env HTTP/2.0" 301 81 "-" ...
show more
[redacted] 172.71.190.138 - - [19/Aug/2026:14:48:40 +0100] "GET /apps/api/.env HTTP/2.0" 301 81 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://[redacted]/bot" [redacted] 172.71.190.138 - - [19/Aug/2026:14:48:49 +0100] "GET /_next/../.env HTTP/2.0" 301 78 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://[redacted]/bot)"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 11:34:42
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.190.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.190.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 07:34:34.181858 2026] [security2:error] [pid 13349:tid 13375] [client 172.71.190.138:13233] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.truthjusticecommission.com"] [uri "/.git/config"] [unique_id "aoLxyt3f_o84l0fKKasXqAAAAZc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 05:55:07
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.190.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.190.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 01:54:59.953951 2026] [security2:error] [pid 26434:tid 26434] [client 172.71.190.138:11511] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pumps.aguasolar.com"] [uri "/.git/HEAD"] [unique_id "aoKiMxPAVeZEgGfMAbYFBAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-16 10:34:41
(1 month ago)
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-16 06:51:02
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-12 02:58:49
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.190.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.190.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 22:58:42.269131 2026] [security2:error] [pid 1074371:tid 1074371] [client 172.71.190.138:13308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stonesandbones.theillustrator.net"] [uri "/.git/config"] [unique_id "anvhYriW8AEr0zAPe0RffwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 12:20:06
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.190.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.190.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 08:19:57.240117 2026] [security2:error] [pid 3979437:tid 3979437] [client 172.71.190.138:12988] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.qualuedata.com"] [uri "/.git/HEAD"] [unique_id "ansTbTUhUiVdUcVFCrxwhgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-08-09 20:34:08
(1 month ago)
[redacted] 172.71.190.138 - - [09/Aug/2026:21:33:56 +0100] "GET /@fs/home/admin/.aws/credentials?raw ...
show more
[redacted] 172.71.190.138 - - [09/Aug/2026:21:33:56 +0100] "GET /@fs/home/admin/.aws/credentials?raw?? HTTP/2.0" 301 209 "-" "Mozilla/5.0 (compatible; Google-Extended/1.0; +http://[redacted]/[redacted])" [redacted] 172.71.190.138 - - [09/Aug/2026:21:34:01 +0100] "GET /fr/@fs/home/admin/.aws/credentials/?raw?? HTTP/2.0" 404 131118 "https://[redacted]/@fs/home/admin/.aws/credentials?raw??" "Mozilla/5.0 (compatible; Google-Extended/1.0; +http://[redacted]/[redacted])"
show less
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-07 03:57:40
(1 month ago)
Web App Attack
Anonymous
2026-07-26 10:21:22
(1 month ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
Anonymous
2026-07-19 22:23:00
(1 month ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
mnsf
2026-04-07 20:05:06
(5 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-02 21:53:33
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.190.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.190.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 17:53:25.796303 2026] [security2:error] [pid 22540:tid 22540] [client 172.71.190.138:11181] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michaelpmcgrath.com"] [uri "/public/.env"] [unique_id "ac7lVbt3zDWvwRdFYwi2ugAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack