Anonymous
2026-08-25 18:13:07
(1 day ago)
Attack detected: 172.71.232.134 [2026-08-25]
Categories: 21
--- wp2shell/batch exploit (1 hits) ---
...
show more
Attack detected: 172.71.232.134 [2026-08-25]
Categories: 21
--- wp2shell/batch exploit (1 hits) ---
172.71.232.134 - - [25/Aug/2026:17:55:40 +0000] "POST /wp-json/batch/v1 HTTP/2.0" 207 854 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 12:58:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.134 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 08:58:06.866848 2026] [security2:error] [pid 3135:tid 3200] [client 172.71.232.134:13625] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.clinicadelparabrisas.com"] [uri "/.git/config"] [unique_id "ao2RXhTGW6cxxVJNpxexHAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 07:54:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.134 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 03:54:39.380335 2026] [security2:error] [pid 6052:tid 6052] [client 172.71.232.134:14208] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jwphotodesign.com"] [uri "/.git/HEAD"] [unique_id "ao1KP51UHC_-o-TaSPp9pAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-08-24 15:50:58
(2 days ago)
[MonAug2417:50:54.9501572026][security2:error][pid4154325:tid4154507][client172.71.232.134:0]ModSecu ...
show more
[MonAug2417:50:54.9501572026][security2:error][pid4154325:tid4154507][client172.71.232.134:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"cpanel.leonitraslochi.ch\"][uri\"/.git/HEAD\"][unique_id\"aoxoXluVGw9V2dNEXsVv9wAAAQk\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 08:37:14
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.134 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 04:37:06.075534 2026] [security2:error] [pid 27636:tid 27636] [client 172.71.232.134:9373] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.gbcwoodbine.org"] [uri "/.git/HEAD"] [unique_id "aowCstPXRiuV_kgPM_ZhEgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 03:46:02
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.134 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 23:45:55.322443 2026] [security2:error] [pid 20737:tid 20737] [client 172.71.232.134:11153] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "americaskitchencoach.com"] [uri "/.git/config"] [unique_id "aou-czzfWKIr-0IO2SdV7QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 23:45:52
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.134 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 19:45:48.000514 2026] [security2:error] [pid 3702:tid 3702] [client 172.71.232.134:14139] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sermonofsong.talkingmess.com"] [uri "/.git/HEAD"] [unique_id "aouGKzQjeBk9fg_bP1C9XAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-08-23 22:32:37
(2 days ago)
[MonAug2400:32:31.6268022026][security2:error][pid198521:tid198582][client172.71.232.134:0]ModSecuri ...
show more
[MonAug2400:32:31.6268022026][security2:error][pid198521:tid198582][client172.71.232.134:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"mail.atelier-lara.ch\"][uri\"/.git/config\"][unique_id\"aot0_5uMpbYN95CLktYumQAAAIA\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 09:58:11
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.134 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 05:58:05.582704 2026] [security2:error] [pid 20950:tid 20956] [client 172.71.232.134:12135] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.topo.switchbl8.nl"] [uri "/.git/config"] [unique_id "aorELQkxFRrb7Y8gzXoJzAAAAIQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 23:18:11
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.134 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 19:18:03.601443 2026] [security2:error] [pid 953:tid 953] [client 172.71.232.134:11611] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.wintercypher.com"] [uri "/.git/HEAD"] [unique_id "aoouKxBlqIUX2ru-GnkDDQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 20:13:25
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.134 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 16:13:18.223818 2026] [security2:error] [pid 642:tid 642] [client 172.71.232.134:11020] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "starvationacres.us"] [uri "/.git/HEAD"] [unique_id "aooC3pY33kV4Z_bG_5tQ7wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 05:01:30
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.134 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 01:01:24.948784 2026] [security2:error] [pid 16059:tid 16059] [client 172.71.232.134:13282] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kaibeth.com"] [uri "/.git/config"] [unique_id "aoktJGoh_F4XAeAm0tbagAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 03:23:05
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.134 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 23:23:00.239078 2026] [security2:error] [pid 3153:tid 3153] [client 172.71.232.134:10265] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.frank-klimas.com"] [uri "/.git/config"] [unique_id "aokWFBLrsO7n8IRh15eIiwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 10:36:49
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.134 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 06:36:45.111891 2026] [security2:error] [pid 21433:tid 21433] [client 172.71.232.134:12178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "savannah-house.com"] [uri "/.git/config"] [unique_id "aogqPQCUMtY7uuHrUu1GigAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-21 07:07:16
(5 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack