๐บ๐ธ
TPI-Abuse
2026-10-01 11:00:46
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 07:00:39.016031 2026] [security2:error] [pid 10240:tid 10240] [client 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc:11075] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.oposicionesyconcursos.es"] [uri "/.env.local"] [unique_id "ar49V4nsk1wJwiWFDflBTQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 03:57:06
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 23:57:00.853868 2026] [security2:error] [pid 8139:tid 8223] [client 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc:9951] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aafm.org"] [uri "/.git/HEAD"] [unique_id "ar3aDCtZhChgDFi9eShqFgAAAVQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 16:08:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 12:08:28.909320 2026] [security2:error] [pid 13223:tid 13223] [client 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc:12905] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "altoshp.com"] [uri "/wp-config.php"] [unique_id "ar0z_JNqo7mhVC2dmm0CgwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:19:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:19:41.674910 2026] [security2:error] [pid 25262:tid 25262] [client 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc:12255] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.loneoakhoney.com"] [uri "/.svn/entries"] [unique_id "arz-XWz09ILYmh16jgiSzAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 06:48:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 02:48:22.761781 2026] [security2:error] [pid 5045:tid 5045] [client 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc:11090] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cortona.ws"] [uri "/wp-config.php"] [unique_id "arywtrLXnsfs8zYaT3bfEQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 20:37:35
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 16:37:28.174353 2026] [security2:error] [pid 2131:tid 2131] [client 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc:11820] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "closedfortheseason.com"] [uri "/.git/HEAD"] [unique_id "arrQCJo4oF6RiVWbW3WcmQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 11:17:05
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 07:16:57.962601 2026] [security2:error] [pid 14903:tid 14953] [client 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc:9902] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dasperformance.com"] [uri "/.env.staging"] [unique_id "arpMqR6N5kMBHtZ_sSth0QAAAY8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 10:56:28
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 06:56:21.997301 2026] [security2:error] [pid 6798:tid 6798] [client 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc:12239] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michleen-collins.com"] [uri "/.svn/entries"] [unique_id "arpH1Wi6DvBWQxvLIosnegAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-15 21:59:57
(4 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-14.
show less
Web App Attack
SSH
Hacking
๐ฏ๐ต
S.O.B.A. Dev.
2025-10-18 13:52:30
(11 months ago)
Persistent port scanning or vulnerability scanning
Port Scan
Anonymous
2025-08-24 19:52:10
(1 year ago)
wp admin page access attempt
...
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-22 01:15:48
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 21 21:15:40.649509 2025] [security2:error] [pid 2082638:tid 2082638] [client 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc:33616] [client 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.embraceacademylv.com"] [uri "/.env"] [unique_id "aC56vAdvFpCT9zz5ovBgtwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-11 14:55:09
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 11 10:55:02.156890 2025] [security2:error] [pid 3042679:tid 3042679] [client 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc:61346] [client 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "redish.org"] [uri "/api/.env"] [unique_id "aCC6RlMIkLNVzx0wrKq4SwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-19 11:51:48
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc (Unknown ...
show more
(mod_security) mod_security (id:225170) triggered by 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 19 06:51:42.340742 2025] [security2:error] [pid 11466:tid 11466] [client 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc:35070] [client 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.pixacast.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.pixacast.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Z4znTtm9dduo2VXZUJzRTwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-02 16:29:57
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 02 11:29:49.438646 2025] [security2:error] [pid 439153:tid 439153] [client 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc:12816] [client 2400:cb00:555:1000:4ff2:ff92:5f43:9bfc] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "easy-byte.net"] [uri "/.git/config"] [unique_id "Z3a-_foM-sBdg1XOp7eRGwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack