π©πͺ
4server
2026-08-23 05:19:17
(1 week ago)
[SunAug2307:19:13.0342832026][security2:error][pid3415880:tid3416003][client172.71.190.219:0]ModSecu ...
show more
[SunAug2307:19:13.0342832026][security2:error][pid3415880:tid3416003][client172.71.190.219:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cbri.ch\"][uri\"/.env.bak\"][unique_id\"aoqC0chYNP7qglLC5bBA4wAAAAU\"]\,referer:https://www.google.com/search\?q=cbri.ch
show less
Port Scan
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-18 04:19:33
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.190.219 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.190.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 00:19:24.732047 2026] [security2:error] [pid 3543:tid 3543] [client 172.71.190.219:11762] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.villagestoner.com"] [uri "/.git/config"] [unique_id "aoPdTDgbSnNnNJlamB_ytgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-18 01:07:56
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.190.219 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.190.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 21:07:53.108086 2026] [security2:error] [pid 15508:tid 15508] [client 172.71.190.219:11664] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.drgas.xyz"] [uri "/.git/HEAD"] [unique_id "aoOwaetEqDwduQliZqg2qgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 23:32:08
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.190.219 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.190.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 19:32:02.025014 2026] [security2:error] [pid 27497:tid 27520] [client 172.71.190.219:12436] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.stateabbreviationlist.com"] [uri "/.git/config"] [unique_id "aoOZ8s0SdnG_YRsrAU-0YQAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 08:35:58
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.190.219 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.190.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 04:35:53.365192 2026] [security2:error] [pid 19383:tid 19383] [client 172.71.190.219:14142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.garrygwilt.com"] [uri "/.git/config"] [unique_id "aoLH6bBjQUBCIWP1ZzlMhQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 08:08:25
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.190.219 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.190.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 04:08:19.640606 2026] [security2:error] [pid 12737:tid 12737] [client 172.71.190.219:12776] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.masterpiecemorgans.com"] [uri "/.git/HEAD"] [unique_id "aoLBc-DEOeCb6jDfiueX0AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 06:13:20
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.190.219 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.190.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 02:13:13.181292 2026] [security2:error] [pid 4940:tid 4940] [client 172.71.190.219:12698] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.abramczuk.me"] [uri "/.git/HEAD"] [unique_id "aoFU-bmPiML51zaKCAvYOwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 05:22:30
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.190.219 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.190.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 01:22:25.356315 2026] [security2:error] [pid 21627:tid 21627] [client 172.71.190.219:12910] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.sarawatt.com"] [uri "/.git/HEAD"] [unique_id "aoFJEXD-waIH-d8bBWRqoAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 04:42:57
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.190.219 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.190.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 00:42:50.123982 2026] [security2:error] [pid 3726:tid 3726] [client 172.71.190.219:10203] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.wallpaperpro.com"] [uri "/.git/HEAD"] [unique_id "aoE_yvLRz7x1vzxBfc1WWwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 03:03:36
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.190.219 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.190.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 23:03:29.690554 2026] [security2:error] [pid 4892:tid 4892] [client 172.71.190.219:13152] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.jimmyshakes.org"] [uri "/.git/config"] [unique_id "aoEogQrixwRMmSA0TKU9tQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-08-11 21:59:52
(2 weeks ago)
Auto-ban: >3000 req/min op 2026-08-11
Web App Attack
SSH
Hacking
π§πͺ
madeit
2026-08-08 13:46:39
(3 weeks ago)
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-15 08:39:23
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.190.219 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.190.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:38:19.407267 2026] [security2:error] [pid 4940:tid 4940] [client 172.71.190.219:10288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.newlife12steprecovery.intnlc.org"] [uri "/.env.php"] [unique_id "agbbezPmuz6CbUqFkrRRhQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-15 08:24:04
(3 months ago)
(mod_security) mod_security (id:949110) triggered by 172.71.190.219 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 172.71.190.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:23:54.499062 2026] [security2:error] [pid 8074:tid 8074] [client 172.71.190.219:13041] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "akistech.com"] [uri "/.env.local"] [unique_id "agbYGpkjFweq8ZXs7yWS3QAAABI"], referer: https://www.google.com/search?q=akistech.com
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
SΓ©fora Srl
2026-05-12 16:02:37
(3 months ago)
Bad user agents ignoring web crawling rules. Draing bandwidth - detected by Fail2Ban in plesk-apache ...
show more
Bad user agents ignoring web crawling rules. Draing bandwidth - detected by Fail2Ban in plesk-apache-badbot jail
show less
Bad Web Bot