๐บ๐ธ
TPI-Abuse
2026-10-09 14:24:09
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:dd60:673f:5db9:b511 (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:dd60:673f:5db9:b511 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 10:24:05.261008 2026] [security2:error] [pid 30903:tid 30903] [client 2400:cb00:555:1000:dd60:673f:5db9:b511:12881] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tpdtuberental.com"] [uri "/.env.save"] [unique_id "asj5BeqclrJTFniD1y2ZiAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 08:16:22
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:dd60:673f:5db9:b511 (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:dd60:673f:5db9:b511 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 04:16:10.460413 2026] [security2:error] [pid 15597:tid 15597] [client 2400:cb00:555:1000:dd60:673f:5db9:b511:10413] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "altruaglobalsolutions.com"] [uri "/.env.save"] [unique_id "asiiykPK6_spsDzZoERo6QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 02:28:02
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 2400:cb00:555:1000:dd60:673f:5db9:b511 (Unknown ...
show more
(mod_security) mod_security (id:210730) triggered by 2400:cb00:555:1000:dd60:673f:5db9:b511 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 22:27:55.240138 2026] [security2:error] [pid 6796:tid 6796] [client 2400:cb00:555:1000:dd60:673f:5db9:b511:10880] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.bitcoinsubscribers.com|F|2"] [data ".env.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.bitcoinsubscribers.com"] [uri "/.env.bak"] [unique_id "asb_qzP0QYiovQDeMe9OzQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 18:40:07
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:dd60:673f:5db9:b511 (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:dd60:673f:5db9:b511 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 14:40:00.733399 2026] [security2:error] [pid 2699:tid 2699] [client 2400:cb00:555:1000:dd60:673f:5db9:b511:9991] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ncogtrains.com"] [uri "/.env.production"] [unique_id "asaSANSxymow-Bg7pruSWQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-10-07 13:20:18
(2 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-10-07 13:19:15
(2 days ago)
2400:cb00:555:1000:dd60:673f:5db9:b511 - - [07/Oct/2026:15:19:12 +0200] "GET /wp-config.php.bak HTTP ...
show more
2400:cb00:555:1000:dd60:673f:5db9:b511 - - [07/Oct/2026:15:19:12 +0200] "GET /wp-config.php.bak HTTP/1.1" 301 600 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0"
2400:cb00:555:1000:dd60:673f:5db9:b511 - - [07/Oct/2026:02:21:44 +0200] "GET /.svn/entries HTTP/1.1" 301 590 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
2400:cb00:555:1000:dd60:673f:5db9:b511 - - [07/Oct/2026:02:21:44 +0200] "GET /.terraform/terraform.tfstate.backup HTTP/1.1" 301 636 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
2400:cb00:555:1000:dd60:673f:5db9:b511 - - [07/Oct/2026:03:24:29 +0200] "GET /%252f%252eaws%252fcredentials HTTP/1.1" 301 612 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
2400:cb00:555:1000:dd60:673f:5db9:b511 - - [07/Oct/2026:03:24:30 +0200] "GET /.git
show less
Web App Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-07 02:30:26
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:dd60:673f:5db9:b511 (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:dd60:673f:5db9:b511 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 22:30:22.173749 2026] [security2:error] [pid 2294:tid 2294] [client 2400:cb00:555:1000:dd60:673f:5db9:b511:12894] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jsommer.com"] [uri "/.env.bak"] [unique_id "asWuvvPO8dB_v2QNg8ylbQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-10-07 02:16:23
(2 days ago)
[WedOct0704:16:16.3793112026][security2:error][pid3053345:tid3053356][client2400:cb00:555:1000:dd60: ...
show more
[WedOct0704:16:16.3793112026][security2:error][pid3053345:tid3053356][client2400:cb00:555:1000:dd60:673f:5db9:b511:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"710\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"4hosts.net\"][uri\"/.git/HEAD\"][unique_id\"asWrcJJUHRde4oHY1z2UFgAAAQk\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 11:44:55
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:dd60:673f:5db9:b511 (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:dd60:673f:5db9:b511 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 07:44:49.271084 2026] [security2:error] [pid 17201:tid 17201] [client 2400:cb00:555:1000:dd60:673f:5db9:b511:10864] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sabbathschoolguide.com"] [uri "/.htaccess"] [unique_id "asTfMXenj-_veSsqJEJHLAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 23:40:30
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:dd60:673f:5db9:b511 (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:dd60:673f:5db9:b511 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 19:40:26.183904 2026] [security2:error] [pid 19544:tid 19551] [client 2400:cb00:555:1000:dd60:673f:5db9:b511:13202] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rogamur.com"] [uri "/wp-config.php.bak"] [unique_id "asQ1au944sO8S-7bg5p1UAAAAIM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 06:46:54
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:dd60:673f:5db9:b511 (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:dd60:673f:5db9:b511 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 02:46:48.259261 2026] [security2:error] [pid 12080:tid 12080] [client 2400:cb00:555:1000:dd60:673f:5db9:b511:11023] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oldkentuckyhams.org"] [uri "/.env.backup"] [unique_id "asNH2Pyg8EU42bI0i0uJvQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 01:15:30
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:dd60:673f:5db9:b511 (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:dd60:673f:5db9:b511 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 21:15:23.205002 2026] [security2:error] [pid 2043:tid 2043] [client 2400:cb00:555:1000:dd60:673f:5db9:b511:10834] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "franzexpress.com"] [uri "/.env.production"] [unique_id "ar20K5AYEdJqidZws3gTqgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-09-30 18:09:19
(1 week ago)
[WedSep3020:09:14.7093862026][security2:error][pid2502870:tid2502893][client2400:cb00:555:1000:dd60: ...
show more
[WedSep3020:09:14.7093862026][security2:error][pid2502870:tid2502893][client2400:cb00:555:1000:dd60:673f:5db9:b511:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"710\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.motogiro.com\"][uri\"/.env.local\"][unique_id\"ar1QSnGLIj3fjCBSH-IAJQAAAFU\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 03:52:34
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:dd60:673f:5db9:b511 (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:dd60:673f:5db9:b511 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 23:52:26.486323 2026] [security2:error] [pid 25754:tid 25754] [client 2400:cb00:555:1000:dd60:673f:5db9:b511:10010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "photokarine.com"] [uri "/wp-config.php.bak"] [unique_id "aryHevOeCbffrRUgvsULuAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 10:04:09
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:dd60:673f:5db9:b511 (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:dd60:673f:5db9:b511 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 06:04:06.218191 2026] [security2:error] [pid 19656:tid 19656] [client 2400:cb00:555:1000:dd60:673f:5db9:b511:11850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.northfortworthalliance.com"] [uri "/.env.staging"] [unique_id "aruNFhVPUBl9sD3Sq7JgBgAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack