๐ฉ๐ช
4server
2026-08-23 05:11:16
(2 hours ago)
[SunAug2307:11:11.6190872026][security2:error][pid3411131:tid3411208][client172.71.191.75:0]ModSecur ...
show more
[SunAug2307:11:11.6190872026][security2:error][pid3411131:tid3411208][client172.71.191.75:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"bluecirclecapital.ch.136-243-54-122.cpanel.site\"][uri\"/.env.bak\"][unique_id\"aoqA75vyG06NjDIJrJ1kHQAAAJA\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 13:30:14
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.191.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.191.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 09:30:06.723214 2026] [security2:error] [pid 4562:tid 4562] [client 172.71.191.75:10749] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.3n1ent.com"] [uri "/.git/config"] [unique_id "aoMM3red-WlIfslqrsrdNQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-17 12:55:45
(5 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 07:10:47
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.191.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.191.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 03:10:39.097116 2026] [security2:error] [pid 1596:tid 1596] [client 172.71.191.75:14281] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rochesterhistorical.org"] [uri "/.git/HEAD"] [unique_id "aoKz7-68Y0rmVcLF59UOPQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 05:47:08
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.191.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.191.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 01:47:02.773838 2026] [security2:error] [pid 32313:tid 32313] [client 172.71.191.75:12474] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "californialending.biz.californiaappraisers.net"] [uri "/.git/HEAD"] [unique_id "aoKgVnW9Abto9GGop9KYmwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 08:04:20
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.191.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.191.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 04:04:14.944297 2026] [security2:error] [pid 27084:tid 27084] [client 172.71.191.75:13014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "americanlegion935.com"] [uri "/.git/HEAD"] [unique_id "aoFu_sNNJ9j-ysu5BJlpGgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 05:35:47
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.191.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.191.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 01:35:41.573396 2026] [security2:error] [pid 3887:tid 3958] [client 172.71.191.75:13199] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.zoomtexas.com"] [uri "/.git/HEAD"] [unique_id "anq0rQpeXp3p0PTp0i4RLwAAAUs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-09 10:24:14
(1 week ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 10:10:55
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.191.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.191.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 06:10:48.562441 2026] [security2:error] [pid 16802:tid 16802] [client 172.71.191.75:11311] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.test.flightclaimservices.com"] [uri "/.env.vercel"] [unique_id "agbxKAlAa9a6w8fdVuJcHwAAAAk"], referer: https://www.google.com/search?q=www.test.flightclaimservices.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 09:21:27
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.191.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.191.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 05:20:15.312259 2026] [security2:error] [pid 851:tid 851] [client 172.71.191.75:13978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "keysenterprise.keysenterprise.net"] [uri "/.env.save"] [unique_id "agblTy_4ZUrlaOIcpaBq0gAAAA0"], referer: https://www.google.com/search?q=keysenterprise.keysenterprise.net
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 07:43:58
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.191.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.191.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 03:43:52.452583 2026] [security2:error] [pid 8013:tid 8013] [client 172.71.191.75:12869] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "frankweyer.com"] [uri "/.env.dusk.local"] [unique_id "agbOuOu4MjhhBmtz6joslwAAAAo"], referer: https://www.google.com/search?q=frankweyer.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 06:56:28
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.191.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.191.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 02:56:25.194112 2026] [security2:error] [pid 1672:tid 1679] [client 172.71.191.75:11852] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "uniquelynoel.com"] [uri "/.env.development.local"] [unique_id "agbDmc7OxNn1UXZbHWm_TQAAAAQ"], referer: https://www.google.com/search?q=uniquelynoel.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-09 14:35:37
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.191.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.191.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 10:35:34.588620 2026] [security2:error] [pid 20944:tid 20950] [client 172.71.191.75:14326] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "particulierlb.com"] [uri "/.git/config"] [unique_id "af9GNvxuA2fQt1NX-5aK0AAAAMQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Prepaid-Host.com
2026-04-27 09:52:38
(3 months ago)
Web Exploit detected | Events: 1 | First seen: 2026-04-27 09:52 UTC | Last seen: 2026-04-27 09:52 UT ...
show more
Web Exploit detected | Events: 1 | First seen: 2026-04-27 09:52 UTC | Last seen: 2026-04-27 09:52 UTC | Sample: Web Exploit detected by fail2ban jail 'plesk-apache-badbot': 1 failed attempt(s) from 172.71.191.75
Web Exploit detected by fail2ban jail 'plesk-apache-badbot': 1 failed attempt(s) from 172.71.191.75
show less
Web App Attack
๐บ๐ธ
mnsf
2026-04-08 18:05:08
(4 months ago)
Scanning/Probing (14)
Brute-Force
Web App Attack