๐ง๐ช
madeit
2026-09-30 13:02:28
(3 days ago)
Web App Attack
๐ง๐ช
madeit
2026-09-01 11:15:27
(1 month ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 13:07:29
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.195.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.195.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 09:07:21.111595 2026] [security2:error] [pid 10661:tid 10661] [client 172.71.195.58:12911] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "openhouses.iainrealtor.com"] [uri "/.git/HEAD"] [unique_id "aoMHiYN9CZ9QwSc2cxeOQgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 08:20:51
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.195.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.195.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 04:20:43.165978 2026] [security2:error] [pid 10883:tid 10883] [client 172.71.195.58:11132] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ieas.org"] [uri "/.git/HEAD"] [unique_id "aoLEW1qKyUDGU4djsZpoXwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 07:51:46
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.195.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.195.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 03:51:38.016288 2026] [security2:error] [pid 26123:tid 26123] [client 172.71.195.58:9495] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.oahupc.com"] [uri "/.git/HEAD"] [unique_id "aoFsCgZtHgYcjKKnoutqcAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 06:46:24
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.195.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.195.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 02:46:16.937350 2026] [security2:error] [pid 1807:tid 1807] [client 172.71.195.58:12894] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.kraftrentals.com"] [uri "/.git/config"] [unique_id "aoFcuK0d6kLewnAWu3XABQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 05:41:03
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.195.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.195.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 01:40:55.266349 2026] [security2:error] [pid 24102:tid 24102] [client 172.71.195.58:10905] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ypsisda.net"] [uri "/.git/config"] [unique_id "aoFNZ4Rd8O5Mozd2BgIxmwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 02:59:19
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.195.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.195.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 22:59:13.307946 2026] [security2:error] [pid 13865:tid 13865] [client 172.71.195.58:11411] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bigislandhawaiirealestate.com"] [uri "/.git/HEAD"] [unique_id "aoEngU0ZN8hLZ_JbSxErfQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-08-14 14:28:11
(1 month ago)
[FriAug1416:28:06.4219142026][security2:error][pid2150991:tid2151009][client172.71.195.58:0]ModSecur ...
show more
[FriAug1416:28:06.4219142026][security2:error][pid2150991:tid2151009][client172.71.195.58:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"dsfiduciaria.ch\"][uri\"/.git/config\"][unique_id\"an8l9puxTXTtrv_E0H-KaQAAAM8\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ง๐ช
madeit
2026-08-09 10:02:33
(1 month ago)
Web App Attack
๐ณ๐ฑ
MM-bot
2026-06-21 06:33:26
(3 months ago)
URL-probe: HTTP/2 GET request on /bootstrap/cache/config.php (2026-06-21 08:33:26 UTC+2)
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-15 09:25:01
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.195.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.195.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 05:24:52.966940 2026] [security2:error] [pid 12271:tid 12271] [client 172.71.195.58:10448] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "josephnine.com"] [uri "/.env.php"] [unique_id "agbmZJvTTz3uUFRf7pph8wAAABE"], referer: https://www.google.com/search?q=josephnine.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 08:33:37
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.195.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.195.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:31:51.583682 2026] [security2:error] [pid 21224:tid 21224] [client 172.71.195.58:12504] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.old" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.drinktopit.sendalawyerletter.com"] [uri "/wp-config.old"] [unique_id "agbZ96uG7Sewxv786KeZQwAAABM"], referer: https://www.google.com/search?q=www.drinktopit.sendalawyerletter.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 06:39:39
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 172.71.195.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.195.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 02:39:25.890486 2026] [security2:error] [pid 19321:tid 19321] [client 172.71.195.58:12428] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wintercypher.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wintercypher.com"] [uri "/config/master.key"] [unique_id "aga_nRtsZxeDZqoNMdPDVAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 06:05:42
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.195.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.195.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 02:05:35.892618 2026] [security2:error] [pid 30165:tid 30165] [client 172.71.195.58:10780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.vaghyst.com"] [uri "/.env~"] [unique_id "aga3r7Ezr-7aZPspc5mHUgAAAAY"], referer: https://www.google.com/search?q=webmail.vaghyst.com
show less
Brute-Force
Bad Web Bot
Web App Attack