๐ซ๐ท
dynamix
2026-10-11 11:21:57
(6 hours ago)
Multiple WAF Violations
Web App Attack
๐ต๐ฑ
Budyn
2026-09-30 02:33:28
(1 week ago)
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_4 | Action: AWS API Call | Token: 3a2 ...
show more
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_4 | Action: AWS API Call | Token: 3a228y9iwzbmqpgsnaaic99y3 | Client Tool: (no user-agent specified)
show less
Hacking
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-09-29 03:38:09
(1 week ago)
Web App Attack
๐ง๐ช
madeit
2026-09-08 10:27:03
(1 month ago)
Web App Attack
Anonymous
2026-08-18 16:31:19
(1 month ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-08-17 08:02:41
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.190.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.190.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 04:02:37.905590 2026] [security2:error] [pid 3537:tid 3537] [client 172.71.190.28:12085] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "goldcountrygermanamericanclub.org"] [uri "/.git/HEAD"] [unique_id "aoLAHdSmV34ssxP9GkSJqwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 06:53:00
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.190.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.190.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 02:52:51.633499 2026] [security2:error] [pid 836:tid 836] [client 172.71.190.28:13797] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.sidegigfab.com"] [uri "/.git/config"] [unique_id "aoKvw2cVfFRy8mdMvH9ovQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 06:02:57
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.190.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.190.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 02:02:53.724706 2026] [security2:error] [pid 22827:tid 22827] [client 172.71.190.28:12089] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ae5cp.kreweofhyatt.com"] [uri "/.git/HEAD"] [unique_id "aoKkDdR4xuIYUToMY6_sKgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 07:57:39
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.190.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.190.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 03:57:34.888286 2026] [security2:error] [pid 6587:tid 6587] [client 172.71.190.28:11435] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.mixmediallc.com"] [uri "/.git/HEAD"] [unique_id "aoFtboCQVeu-cX1LXrM4zgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 07:22:05
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.190.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.190.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 03:21:59.871598 2026] [security2:error] [pid 8851:tid 8863] [client 172.71.190.28:12749] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kyme.bestofthis.com"] [uri "/.git/config"] [unique_id "aoFlFxIsl8-yQNFx5KWyQAAAAQY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 04:38:04
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.190.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.190.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 00:37:59.007789 2026] [security2:error] [pid 6563:tid 6563] [client 172.71.190.28:12989] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fibroscopie.net"] [uri "/.git/config"] [unique_id "aoE-pyYL55eQijH7ro_WJgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-11 13:00:56
(2 months ago)
Web App Attack
Anonymous
2026-07-27 01:23:44
(2 months ago)
172.71.190.28 - - [27/Jul/2026:03:23:44 +0200] "GET /.env.example HTTP/1.1" 403 1738 "-" "Mozilla/5. ...
show more
172.71.190.28 - - [27/Jul/2026:03:23:44 +0200] "GET /.env.example HTTP/1.1" 403 1738 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
172.71.190.28 - - [27/Jul/2026:03:23:44 +0200] "GET /.env.example HTTP/1.1" 403 737 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
172.71.190.28 - - [27/Jul/2026:03:23:44 +0200] "GET /.env.dev HTTP/1.1" 403 1738 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
172.71.190.28 - - [27/Jul/2026:03:23:44 +0200] "GET /.env.dev HTTP/1.1" 403 737 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
172.71.190.28 - - [27/Jul/2026:03:23:44 +0200] "GET /.env.stage HTTP/1.1" 403 1738 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
172.71.190.28 - - [27/Jul/2026:03:23:44 +0200]
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-07-06 09:26:30
(3 months ago)
172.71.190.28 - - [06/Jul/2026:11:26:29 +0200] "GET /.env.dist HTTP/1.1" 403 1738 "-" "Mozilla/5.0 ( ...
show more
172.71.190.28 - - [06/Jul/2026:11:26:29 +0200] "GET /.env.dist HTTP/1.1" 403 1738 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
172.71.190.28 - - [06/Jul/2026:11:26:29 +0200] "GET /.env.dist HTTP/1.1" 403 737 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
172.71.190.28 - - [06/Jul/2026:11:26:29 +0200] "GET /.env.swp HTTP/1.1" 403 1738 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
172.71.190.28 - - [06/Jul/2026:11:26:29 +0200] "GET /.env.swp HTTP/1.1" 403 737 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
172.71.190.28 - - [06/Jul/2026:11:26:29 +0200] "GET /.env~ HTTP/1.1" 403 1738 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
172.71.1
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 07:32:33
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.190.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.190.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 03:32:05.737957 2026] [security2:error] [pid 2880:tid 2880] [client 172.71.190.28:10445] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ifilemuseum.title26.com"] [uri "/.env.bak"] [unique_id "agbL9aID_rZyI9m85dVNiwAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack