๐ง๐ช
madeit
2026-09-07 03:27:16
(10 hours ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 15:47:33
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.222.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.222.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 11:47:28.596184 2026] [security2:error] [pid 24852:tid 24852] [client 172.71.222.191:9774] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.intelligent-design.net"] [uri "/.git/config"] [unique_id "aoMtECtZwZaJlIswzo4X-gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-16 23:38:25
(3 weeks ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 06:01:44
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.222.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.222.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 02:01:35.416968 2026] [security2:error] [pid 30978:tid 30995] [client 172.71.222.191:13993] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.layoverlocations.com"] [uri "/.git/config"] [unique_id "aoFSPyaG0mm0q8dHph1sdAAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-18 10:02:44
(2 months ago)
[Thu Jun 18 12:02:42.573736 2026] [authz_core:error] [pid 6292] [client 172.71.222.191:11509] AH0163 ...
show more
[Thu Jun 18 12:02:42.573736 2026] [authz_core:error] [pid 6292] [client 172.71.222.191:11509] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu Jun 18 12:02:43.196175 2026] [authz_core:error] [pid 6292] [client 172.71.222.191:11509] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu Jun 18 12:02:43.490792 2026] [authz_core:error] [pid 6292] [client 172.71.222.191:11509] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 09:51:56
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 172.71.222.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.222.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 05:51:48.026360 2026] [security2:error] [pid 13218:tid 13218] [client 172.71.222.191:9482] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||drstiso.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "drstiso.com"] [uri "/backup.sql"] [unique_id "agbstK8DCP7J4ligrHDpZwAAACo"], referer: https://www.google.com/search?q=drstiso.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-09 14:25:27
(3 months ago)
[Sat May 09 16:25:26.117986 2026] [authz_core:error] [pid 21309] [client 172.71.222.191:10078] AH016 ...
show more
[Sat May 09 16:25:26.117986 2026] [authz_core:error] [pid 21309] [client 172.71.222.191:10078] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sat May 09 16:25:26.430430 2026] [authz_core:error] [pid 21309] [client 172.71.222.191:10078] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sat May 09 16:25:26.543996 2026] [authz_core:error] [pid 21309] [client 172.71.222.191:10078] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
Anonymous
2026-04-26 11:16:48
(4 months ago)
[Sun Apr 26 13:16:47.744516 2026] [authz_core:error] [pid 29525] [client 172.71.222.191:9436] AH0163 ...
show more
[Sun Apr 26 13:16:47.744516 2026] [authz_core:error] [pid 29525] [client 172.71.222.191:9436] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sun Apr 26 13:16:47.856640 2026] [authz_core:error] [pid 29525] [client 172.71.222.191:9436] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sun Apr 26 13:16:48.038108 2026] [authz_core:error] [pid 29525] [client 172.71.222.191:9436] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
Anonymous
2026-04-18 21:23:24
(4 months ago)
[Sat Apr 18 23:23:23.939632 2026] [authz_core:error] [pid 31305] [client 172.71.222.191:11186] AH016 ...
show more
[Sat Apr 18 23:23:23.939632 2026] [authz_core:error] [pid 31305] [client 172.71.222.191:11186] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sat Apr 18 23:23:24.053473 2026] [authz_core:error] [pid 31305] [client 172.71.222.191:11186] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sat Apr 18 23:23:24.163832 2026] [authz_core:error] [pid 31305] [client 172.71.222.191:11186] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 20:27:01
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.222.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.222.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 16:26:54.937874 2026] [security2:error] [pid 12058:tid 12058] [client 172.71.222.191:10009] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.gowithevergreen.com"] [uri "/.env.production"] [unique_id "adAijvh4dMuQgcYoUCmkNQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 10:23:41
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.222.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.222.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 06:23:35.476938 2026] [security2:error] [pid 15825:tid 15825] [client 172.71.222.191:9919] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gdrankin.com"] [uri "/.env.development"] [unique_id "ac-VJ89Funb3g-RcSu473gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 01:06:06
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.222.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.222.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 21:05:57.943512 2026] [security2:error] [pid 8173:tid 8191] [client 172.71.222.191:13712] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.pflagabq.org"] [uri "/.env.old"] [unique_id "ac8SdSYdRaF4JnPJNt99YgAAAM4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-02 18:41:25
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.222.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.222.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 14:41:17.182285 2026] [security2:error] [pid 12370:tid 12370] [client 172.71.222.191:10359] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gslandservices.soviaenterprises.com"] [uri "/.env"] [unique_id "ac64Tc1DvRVccijqAEwFKwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-02 13:46:10
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.222.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.222.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 09:46:01.670727 2026] [security2:error] [pid 7788:tid 7788] [client 172.71.222.191:10964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.gamedayincentives.com"] [uri "/.env.backup"] [unique_id "ac5zGYKZfbqewo6EA6zozwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-02 12:00:36
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.222.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.222.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 08:00:27.752189 2026] [security2:error] [pid 31516:tid 31516] [client 172.71.222.191:9608] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.evannine.com"] [uri "/.env.example"] [unique_id "ac5aWwiJMHN1cDYDcE4vrwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack