๐ซ๐ท
dynamix
2026-10-11 03:24:53
(38 minutes ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
dynamix
2026-10-10 00:02:52
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ง๐ช
madeit
2026-09-26 07:49:09
(2 weeks ago)
Web App Attack
๐ง๐ช
madeit
2026-09-14 00:57:25
(3 weeks ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 12:26:03
(1 month ago)
(mod_security) mod_security (id:949110) triggered by 172.71.191.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 172.71.191.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 08:25:54.478202 2026] [security2:error] [pid 11431:tid 11431] [client 172.71.191.99:11309] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "pleasejustfixit.org.cescfoundation.org"] [uri "/.env"] [unique_id "aomVUlK2xEyA1o5JC3DamAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
chrisj
2026-08-22 03:06:26
(1 month ago)
[Sat Aug 22 03:06:25.673955 2026] [proxy_fcgi:error] [pid 1286687:tid 1286689] [remote 172.71.191.99 ...
show more
[Sat Aug 22 03:06:25.673955 2026] [proxy_fcgi:error] [pid 1286687:tid 1286689] [remote 172.71.191.99:14181] AH01071: Got error 'Primary script unknown'
[Sat Aug 22 03:06:25.754201 2026] [proxy_fcgi:error] [pid 1286687:tid 1286690] [remote 172.71.191.99:14181] AH01071: Got error 'Primary script unknown'
[Sat Aug 22 03:06:25.968628 2026] [proxy_fcgi:error] [pid 1286687:tid 1286696] [remote 172.71.191.99:14181] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
๐บ๐ธ
chrisj
2026-08-18 19:42:23
(1 month ago)
[Tue Aug 18 19:42:21.562141 2026] [proxy_fcgi:error] [pid 1182721:tid 1182723] [remote 172.71.191.99 ...
show more
[Tue Aug 18 19:42:21.562141 2026] [proxy_fcgi:error] [pid 1182721:tid 1182723] [remote 172.71.191.99:12528] AH01071: Got error 'Primary script unknown'
[Tue Aug 18 19:42:22.681314 2026] [proxy_fcgi:error] [pid 1182721:tid 1182724] [remote 172.71.191.99:12528] AH01071: Got error 'Primary script unknown'
[Tue Aug 18 19:42:23.440435 2026] [proxy_fcgi:error] [pid 1182721:tid 1182725] [remote 172.71.191.99:12528] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-18 03:53:59
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.191.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.191.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 23:53:52.453985 2026] [security2:error] [pid 7805:tid 7805] [client 172.71.191.99:12957] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "laurenandfrank.com"] [uri "/.git/config"] [unique_id "aoPXUKGPucF6gv7RbwoECwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 22:57:18
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.191.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.191.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 18:57:12.332284 2026] [security2:error] [pid 11248:tid 11248] [client 172.71.191.99:9366] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.meganmurph.com"] [uri "/.git/config"] [unique_id "aoORyAxQvfS9qPaEmDvVLgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 07:31:34
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.191.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.191.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 03:31:30.198101 2026] [security2:error] [pid 23388:tid 23388] [client 172.71.191.99:12323] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.clustershow.com"] [uri "/.git/HEAD"] [unique_id "aoK40iGdBCK5ntzOtJhYegAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 06:52:04
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.191.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.191.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 02:52:00.547256 2026] [security2:error] [pid 6393:tid 6393] [client 172.71.191.99:13836] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.8two7.com"] [uri "/.git/HEAD"] [unique_id "aoFeEMSwuos_H71Jg4O90AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 02:57:37
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.191.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.191.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 22:57:28.777619 2026] [security2:error] [pid 23282:tid 23282] [client 172.71.191.99:12689] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.garnersystems.com"] [uri "/.git/HEAD"] [unique_id "aoEnGAi4fzD_fDcGuE1m_wAAAH8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 01:43:52
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.191.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.191.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 21:43:46.175244 2026] [security2:error] [pid 5378:tid 5378] [client 172.71.191.99:9240] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.roselockecasting.com"] [uri "/.git/HEAD"] [unique_id "aoEV0oEkRj-fOsxwpAe57AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
chrisj
2026-08-14 19:10:55
(1 month ago)
[Fri Aug 14 19:10:55.010940 2026] [proxy_fcgi:error] [pid 1013975:tid 1013985] [remote 172.71.191.99 ...
show more
[Fri Aug 14 19:10:55.010940 2026] [proxy_fcgi:error] [pid 1013975:tid 1013985] [remote 172.71.191.99:12822] AH01071: Got error 'Primary script unknown'
[Fri Aug 14 19:10:55.133013 2026] [proxy_fcgi:error] [pid 1013975:tid 1013986] [remote 172.71.191.99:12822] AH01071: Got error 'Primary script unknown'
[Fri Aug 14 19:10:55.455541 2026] [proxy_fcgi:error] [pid 1013975:tid 1013993] [remote 172.71.191.99:12822] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
๐ฉ๐ช
FeG Deutschland
2026-08-12 08:01:05
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack