๐บ๐ธ
TPI-Abuse
2026-10-08 17:21:03
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:20bc:605:ec4e:f30a (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:20bc:605:ec4e:f30a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 13:20:50.002135 2026] [security2:error] [pid 17385:tid 17385] [client 2400:cb00:555:1000:20bc:605:ec4e:f30a:9817] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jwilder.com"] [uri "/wp-config.php"] [unique_id "asfQ8ieMi2_WAfspqjveOgAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 17:04:32
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:20bc:605:ec4e:f30a (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:20bc:605:ec4e:f30a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 13:04:23.088863 2026] [security2:error] [pid 11114:tid 11126] [client 2400:cb00:555:1000:20bc:605:ec4e:f30a:10647] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "navinole.com"] [uri "/.env.local"] [unique_id "asfNF32qyENfRwCYmnOfCQAAAYo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 05:50:21
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 2400:cb00:555:1000:20bc:605:ec4e:f30a (Unknown) ...
show more
(mod_security) mod_security (id:210730) triggered by 2400:cb00:555:1000:20bc:605:ec4e:f30a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 01:50:12.539373 2026] [security2:error] [pid 2046:tid 2170] [client 2400:cb00:555:1000:20bc:605:ec4e:f30a:11101] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||propertyinspectorsinc.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "propertyinspectorsinc.com"] [uri "/index.php.bak"] [unique_id "ascvFEMrXa9GWWo1yvmFuQAAAQ4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 04:27:03
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:20bc:605:ec4e:f30a (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:20bc:605:ec4e:f30a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 00:26:58.561479 2026] [security2:error] [pid 12122:tid 12122] [client 2400:cb00:555:1000:20bc:605:ec4e:f30a:14236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tremulant.com"] [uri "/.env.bak"] [unique_id "ascbkrq9E5Ds3OxRGGALkwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 23:59:30
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:20bc:605:ec4e:f30a (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:20bc:605:ec4e:f30a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 19:59:19.174047 2026] [security2:error] [pid 2709:tid 2709] [client 2400:cb00:555:1000:20bc:605:ec4e:f30a:13180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "intergalactichuman.com"] [uri "/.env.staging"] [unique_id "asbc18hXYWQ1rQhVbSff8QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 22:41:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:20bc:605:ec4e:f30a (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:20bc:605:ec4e:f30a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 18:41:09.762879 2026] [security2:error] [pid 10646:tid 10646] [client 2400:cb00:555:1000:20bc:605:ec4e:f30a:9258] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jennyfiore.com"] [uri "/.env.local"] [unique_id "asbKhZffrhuTmytK1zx68wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 22:05:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:20bc:605:ec4e:f30a (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:20bc:605:ec4e:f30a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 18:05:33.188802 2026] [security2:error] [pid 8737:tid 8737] [client 2400:cb00:555:1000:20bc:605:ec4e:f30a:12296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fixitsmart.com"] [uri "/wp-config.php.bak"] [unique_id "asbCLUuFY2vJfP4wE7F65gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-07 09:52:25
(1 day ago)
2400:cb00:555:1000:20bc:605:ec4e:f30a - - [07/Oct/2026:06:52:22 -0300] "GET /index.php.bak HTTP/1.1" ...
show more
2400:cb00:555:1000:20bc:605:ec4e:f30a - - [07/Oct/2026:06:52:22 -0300] "GET /index.php.bak HTTP/1.1" 404 1129 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15"
...
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-10-07 04:14:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:20bc:605:ec4e:f30a (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:20bc:605:ec4e:f30a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 00:13:59.220864 2026] [security2:error] [pid 8347:tid 8347] [client 2400:cb00:555:1000:20bc:605:ec4e:f30a:11098] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.register-yacht-greece.com"] [uri "/.env.save"] [unique_id "asXHBxjoWVsbI0pyRl1U7AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 14:45:31
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:20bc:605:ec4e:f30a (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:20bc:605:ec4e:f30a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 10:45:24.229986 2026] [security2:error] [pid 16357:tid 16357] [client 2400:cb00:555:1000:20bc:605:ec4e:f30a:12533] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bikiniwatersports.com"] [uri "/wp-config.php.old"] [unique_id "asUJhNZ4ktlLkBJC1229ogAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 13:41:24
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:20bc:605:ec4e:f30a (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:20bc:605:ec4e:f30a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 09:41:18.086571 2026] [security2:error] [pid 13631:tid 13631] [client 2400:cb00:555:1000:20bc:605:ec4e:f30a:10163] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "askegroup.com"] [uri "/wp-config.php.bak"] [unique_id "asT6fiPDDJHXXyFeadXLQAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ParaBug
2026-10-06 13:37:03
(2 days ago)
2400:cb00:555:1000:20bc:605:ec4e:f30a - - [06/Oct/2026:15:37:02 +0200] "GET /.env.staging HTTP/1.1" ...
show more
2400:cb00:555:1000:20bc:605:ec4e:f30a - - [06/Oct/2026:15:37:02 +0200] "GET /.env.staging HTTP/1.1" 301 549 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
Phishing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 08:46:14
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 2400:cb00:555:1000:20bc:605:ec4e:f30a (Unknown) ...
show more
(mod_security) mod_security (id:210730) triggered by 2400:cb00:555:1000:20bc:605:ec4e:f30a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 04:46:08.008612 2026] [security2:error] [pid 3862:tid 3862] [client 2400:cb00:555:1000:20bc:605:ec4e:f30a:11341] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fingercult.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fingercult.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asS1UDXl4gUVRQQ2fJiO3wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 06:09:53
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:20bc:605:ec4e:f30a (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:20bc:605:ec4e:f30a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 02:09:48.608830 2026] [security2:error] [pid 23824:tid 23824] [client 2400:cb00:555:1000:20bc:605:ec4e:f30a:10030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mavrik12.com"] [uri "/.env.bak"] [unique_id "asSQrD4Br-MoXERYUgG8zgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 21:34:49
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:20bc:605:ec4e:f30a (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:20bc:605:ec4e:f30a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 17:34:24.580082 2026] [security2:error] [pid 8669:tid 8669] [client 2400:cb00:555:1000:20bc:605:ec4e:f30a:11586] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "radiointernational.net"] [uri "/.env.staging"] [unique_id "asQX4DEn7uG_WJRTlgA34gAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack