๐ง๐ช
madeit
2026-10-03 22:07:26
(4 days ago)
Web App Attack
๐ง๐ท
chronos
2026-09-13 16:57:10
(3 weeks ago)
2026-09-13 13:42:14 UTC-3||Unauthorized connection attempt detected for port scanning
Port Scan
๐ง๐ช
madeit
2026-09-12 16:57:15
(3 weeks ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 15:47:35
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.223.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.223.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 11:47:29.020988 2026] [security2:error] [pid 15255:tid 15273] [client 172.71.223.59:13873] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.culturallyyours.org"] [uri "/.git/config"] [unique_id "aoMtEQyzmVfedpI_e-80CgAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 06:14:42
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.223.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.223.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 02:14:37.774489 2026] [security2:error] [pid 32119:tid 32119] [client 172.71.223.59:12589] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.isyourcorporationsafe.com"] [uri "/.git/HEAD"] [unique_id "aoKmzYr4NmbUZuXkKPIt2AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-14 20:04:18
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.223.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.223.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 16:04:10.049853 2026] [security2:error] [pid 1233619:tid 1233619] [client 172.71.223.59:10091] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "starstrategy.ltd"] [uri "/.git/HEAD"] [unique_id "an90ug2D5o_YrVcaoSa0EQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 05:47:52
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.223.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.223.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 01:47:44.098137 2026] [security2:error] [pid 2311873:tid 2311873] [client 172.71.223.59:14320] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.tonylai.com"] [uri "/.git/HEAD"] [unique_id "anq3gAYTDTNBdOUxOI7EkAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-08 02:36:19
(1 month ago)
Web App Attack
๐ฉ๐ช
acadeova
2026-08-07 20:02:53
(2 months ago)
๐จ Recon detected (nft drop)
SRC=172.71.223.59
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journ ...
show more
๐จ Recon detected (nft drop)
SRC=172.71.223.59
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
Anonymous
2026-07-29 07:00:00
(2 months ago)
Apache probe; attempts=22; exact paths: /.env | /.env.bak | /.env.dev | /.env.example | /.env.old | ...
show more
Apache probe; attempts=22; exact paths: /.env | /.env.bak | /.env.dev | /.env.example | /.env.old | /.env.php.bak | /.env.production | /.git-credentials | /.git/HEAD | /.git/config | /.openclaw/.env | /actuator/configprops | /admin/.env | /api/.env | /backend/.env | /config/.env | /laravel/.env | /public/.env | /web/.env
show less
Web App Attack
๐บ๐ธ
mawan
2026-06-14 22:58:10
(3 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 06:38:00
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.223.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.223.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 02:37:51.204911 2026] [security2:error] [pid 7730:tid 7730] [client 172.71.223.59:13612] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.thenorwoods.name"] [uri "/.git/refs/heads/main"] [unique_id "adCxv9SfTHuzQ80hW5Y_zAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 17:23:10
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.223.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.223.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 13:23:04.399049 2026] [security2:error] [pid 6090:tid 6090] [client 172.71.223.59:10764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.catzpaw.com"] [uri "/.env.staging"] [unique_id "ac_3eEHvi_jPxVScTWE0oAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-02 18:35:56
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.223.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.223.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 14:35:47.092792 2026] [security2:error] [pid 18376:tid 18376] [client 172.71.223.59:12501] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.thebeeplace.com"] [uri "/.env~"] [unique_id "ac63A9g0UdTtehhmf5kURgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-01 23:54:33
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.223.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.223.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 01 19:54:29.344712 2026] [security2:error] [pid 22568:tid 22568] [client 172.71.223.59:11465] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.seebeexee.com"] [uri "/.env.tmp"] [unique_id "ac2wNRUvQjwa8-GvHjC5GwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack