๐บ๐ธ
TPI-Abuse
2026-08-17 08:50:51
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.222.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.222.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 04:50:47.777044 2026] [security2:error] [pid 23834:tid 23834] [client 172.71.222.248:11234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "freedomrailroad.com.coolingsprings.org"] [uri "/.git/config"] [unique_id "aoLLZ_YWA6psWW0tyk1sqQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 05:58:40
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.222.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.222.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 01:58:33.162002 2026] [security2:error] [pid 8935:tid 8935] [client 172.71.222.248:11960] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dossat.cl"] [uri "/.git/config"] [unique_id "aoKjCX3vsQpNs8-YSQVspQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 04:46:10
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.222.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.222.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 00:46:02.243855 2026] [security2:error] [pid 26408:tid 26424] [client 172.71.222.248:13005] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.gotlib.net"] [uri "/.git/HEAD"] [unique_id "aoKSCiOpH4xzEfpQK76AUAAAAM4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 05:09:49
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.222.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.222.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 01:09:45.134263 2026] [security2:error] [pid 5062:tid 5062] [client 172.71.222.248:10106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.chipnado.com"] [uri "/.git/HEAD"] [unique_id "aoFGGcvEKqBA5aRRvEAugAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 04:15:23
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.222.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.222.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 00:15:15.210090 2026] [security2:error] [pid 22529:tid 22529] [client 172.71.222.248:10278] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.usefulendeavors.org"] [uri "/.git/HEAD"] [unique_id "aoE5UxPmGisbf26DOdrfhAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 03:41:57
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.222.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.222.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 23:41:53.365028 2026] [security2:error] [pid 4599:tid 4599] [client 172.71.222.248:14224] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.franciscoforever.evolute.io"] [uri "/.git/config"] [unique_id "aoExgRAGc9_6YMUPuTnkPQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-15 03:32:31
(1 week ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-13 06:49:51
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.222.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.222.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 02:49:45.312033 2026] [security2:error] [pid 2319982:tid 2319982] [client 172.71.222.248:10959] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.splashstation.org"] [uri "/.git/config"] [unique_id "an1pCSh2KotGPO0q_I7AIwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
OptimusGO
2026-07-20 02:24:06
(1 month ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-20 03:24:06 UTC
Log evidence:
172.71.222.248 - - [20/Jul/2026:03:24:05 +0100] "GET / HTTP/1.1" 200 409 "-" "curl/7.29.0"
07/20/2026-03:24:05.559728 [**] [1:1000201:1] SCANNER: Bot-like User-Agent Detected [**] [Classification: Attempted Information Leak] [Priority: 2] {TCP} 172.71.222.248:13691 -> 185.127.18.66:80
show less
Port Scan
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-04-04 05:23:51
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.222.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.222.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 01:23:47.981272 2026] [security2:error] [pid 25781:tid 25781] [client 172.71.222.248:10285] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ballast-capital.com"] [uri "/core/.env"] [unique_id "adCgYxrstVNSLoACW1bbKwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 02:49:05
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.222.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.222.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 22:49:01.682998 2026] [security2:error] [pid 27691:tid 27691] [client 172.71.222.248:12784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.developerdove.com"] [uri "/.env_backup"] [unique_id "adB8HRsmdxFmSXnmtQvV9gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 21:27:15
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.222.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.222.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 17:27:13.416730 2026] [security2:error] [pid 7261:tid 7261] [client 172.71.222.248:13812] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "my1611.com"] [uri "/.git/refs/heads/main"] [unique_id "adAwsWoKTNk79BfgiSa2bAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 19:11:29
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.222.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.222.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 15:11:19.996534 2026] [security2:error] [pid 20324:tid 20324] [client 172.71.222.248:13863] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.murciafm.com"] [uri "/.env.development"] [unique_id "adAQ18V1IqtQMkB4lOscSQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 14:48:25
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.222.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.222.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 10:48:19.547907 2026] [security2:error] [pid 27243:tid 27243] [client 172.71.222.248:13296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "7bsuperfruit.com"] [uri "/.env1"] [unique_id "ac_TM0atcXxP_-YhOF7XFAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 13:44:44
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.222.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.222.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 09:44:40.357659 2026] [security2:error] [pid 5224:tid 5224] [client 172.71.222.248:14135] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "boat-registration-greece.com.boatregistrationdelaware.com"] [uri "/.env.development"] [unique_id "ac_ESMA8hVWCYES_SGS9HgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack