๐ซ๐ท
dynamix
2026-09-03 12:45:03
(6 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:02:18
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:02:10.029427 2026] [security2:error] [pid 32550:tid 32550] [client 172.71.232.143:14171] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "galvanizetm.com"] [uri "/.git/HEAD"] [unique_id "apaioha8Zu4pHGSwCijwXQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-08-29 10:56:00
(1 week ago)
[SatAug2912:55:56.3960772026][security2:error][pid3992216:tid3992284][client172.71.232.143:0]ModSecu ...
show more
[SatAug2912:55:56.3960772026][security2:error][pid3992216:tid3992284][client172.71.232.143:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"gm-swiss.ch\"][uri\"/.git/config\"][unique_id\"apK6vNuB4t9EYeB8KlNJlAAAAQI\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 11:19:43
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 07:19:36.582095 2026] [security2:error] [pid 17728:tid 17728] [client 172.71.232.143:12374] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.divingmachines.com"] [uri "/.git/HEAD"] [unique_id "apFuyP3bi1xkOBIWSaf_RAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 07:14:24
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 03:14:16.685631 2026] [security2:error] [pid 30542:tid 30542] [client 172.71.232.143:9825] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.panadata.com"] [uri "/.git/HEAD"] [unique_id "apE1SOwLFrfVnHp7SgSJcAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 01:10:30
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 21:10:26.421507 2026] [security2:error] [pid 32395:tid 32395] [client 172.71.232.143:13185] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tracytappan.net"] [uri "/.git/config"] [unique_id "apDgAr2eKOoneFIdfnZNEQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 22:31:08
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 18:31:03.008912 2026] [security2:error] [pid 9448:tid 9448] [client 172.71.232.143:13228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nmposters.vabq.com"] [uri "/.git/HEAD"] [unique_id "apC6p82veGgfkzVb2VKOmgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 09:38:15
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 05:38:11.304597 2026] [security2:error] [pid 17137:tid 17137] [client 172.71.232.143:13388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.adults-biz.com"] [uri "/.git/HEAD"] [unique_id "ao60A4exHFLrL7KtDNdZTwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 04:58:14
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 00:58:07.375041 2026] [security2:error] [pid 3164429:tid 3164444] [client 172.71.232.143:12916] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.seips.org"] [uri "/.git/HEAD"] [unique_id "ao5yX_lPLW7E8xMpNSdHlAAAAYk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 00:18:35
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 20:18:28.251014 2026] [security2:error] [pid 31339:tid 31360] [client 172.71.232.143:11475] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "designshopadmin.com"] [uri "/.git/config"] [unique_id "ao4w1C-ns88FHih7RRl2eQAAAUA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 14:44:23
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 10:44:18.561817 2026] [security2:error] [pid 16339:tid 16373] [client 172.71.232.143:10269] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.lightsondisplay.com"] [uri "/.git/HEAD"] [unique_id "ao2qQvXbs8x6BRuE7LcBiAAAAI0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-24 20:58:07
(2 weeks ago)
[24/Aug/2026:23:58:06 +0300] -- 172.71.232.143 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.gi ...
show more
[24/Aug/2026:23:58:06 +0300] -- 172.71.232.143 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 23:53:29
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 19:53:23.966966 2026] [security2:error] [pid 18534:tid 18534] [client 172.71.232.143:13245] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.gowithevergreen.com"] [uri "/.git/HEAD"] [unique_id "aouH891si2C6sXrs2Sl-GwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
ALPHANET
2026-08-23 23:19:19
(2 weeks ago)
web exploits
Hacking
Exploited Host
Web App Attack
๐จ๐ญ
dalslab ltd
2026-08-23 20:51:22
(2 weeks ago)
172.71.232.143 - - [23/Aug/2026:22:51:21 +0200] "POST /RSC/dhvu7jlk2us9exe.txt HTTP/1.1" 405 154 "-" ...
show more
172.71.232.143 - - [23/Aug/2026:22:51:21 +0200] "POST /RSC/dhvu7jlk2us9exe.txt HTTP/1.1" 405 154 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
172.71.232.143 - - [23/Aug/2026:22:51:21 +0200] "POST /RSC/R/3njr47g3nqe60eb.txt HTTP/1.1" 405 154 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
172.71.232.143 - - [23/Aug/2026:22:51:21 +0200] "POST /laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 405 154 "-" "curl/8.7.1"
172.71.232.143 - - [23/Aug/2026:22:51:21 +0200] "POST /zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 405 154 "-" "curl/8.7.1"
172.71.232.143 - - [23/Aug/2026:22:51:21 +0200] "POST /lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 405 154 "-" "curl/8.7.1"
...
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack