πΊπΈ
TPI-Abuse
2026-10-10 06:20:58
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:a797:949:5bb0:150b (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:a797:949:5bb0:150b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 02:20:50.592208 2026] [security2:error] [pid 20888:tid 20888] [client 2400:cb00:994:1000:a797:949:5bb0:150b:10913] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aspechorizon.com"] [uri "/wp-config.php.old"] [unique_id "asnZQtH8kUSXLZ7LSCgd6AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-10 02:26:31
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:a797:949:5bb0:150b (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:a797:949:5bb0:150b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 22:26:24.493955 2026] [security2:error] [pid 16029:tid 16029] [client 2400:cb00:994:1000:a797:949:5bb0:150b:11889] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "suffolksystems.com"] [uri "/.env.dev"] [unique_id "asmiUH_od0DkckaAWoFpPAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 23:34:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:a797:949:5bb0:150b (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:a797:949:5bb0:150b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 19:34:17.454620 2026] [security2:error] [pid 31582:tid 31582] [client 2400:cb00:994:1000:a797:949:5bb0:150b:12343] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.starcrestsales.com"] [uri "/.env.backup"] [unique_id "asl5-fcUStbPJmA0p3j2GAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 17:27:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:a797:949:5bb0:150b (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:a797:949:5bb0:150b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 13:27:29.135884 2026] [security2:error] [pid 23707:tid 23707] [client 2400:cb00:994:1000:a797:949:5bb0:150b:9557] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.epicjellyfish.com"] [uri "/.svn/entries"] [unique_id "askkAcnSuw_c1SSW3E-D9gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 05:24:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:a797:949:5bb0:150b (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:a797:949:5bb0:150b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 01:24:16.541765 2026] [security2:error] [pid 4511:tid 4511] [client 2400:cb00:994:1000:a797:949:5bb0:150b:10452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.adurpartners.com"] [uri "/.git/config"] [unique_id "ash6gGSj1C-O9wQp0SAz8gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 14:03:45
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:a797:949:5bb0:150b (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:a797:949:5bb0:150b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 10:03:36.351276 2026] [security2:error] [pid 26260:tid 26282] [client 2400:cb00:994:1000:a797:949:5bb0:150b:13170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amazinglips.com"] [uri "/.env"] [unique_id "aseiuHOKXjy8oqilpEo54gAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 07:11:55
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:a797:949:5bb0:150b (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:a797:949:5bb0:150b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 03:11:48.768202 2026] [security2:error] [pid 26999:tid 26999] [client 2400:cb00:994:1000:a797:949:5bb0:150b:9954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bakerimaging.com"] [uri "/wp-config.php"] [unique_id "asdCNIRw_FI2r0taUsLmdAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 06:41:30
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:a797:949:5bb0:150b (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:a797:949:5bb0:150b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 02:41:21.513134 2026] [security2:error] [pid 13644:tid 13644] [client 2400:cb00:994:1000:a797:949:5bb0:150b:12332] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "knoxvillelimos.com"] [uri "/wp-config.php"] [unique_id "asc7EcBrgeGFiBL4lo6wkgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 03:44:13
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:a797:949:5bb0:150b (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:a797:949:5bb0:150b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 23:44:06.763001 2026] [security2:error] [pid 24663:tid 24663] [client 2400:cb00:994:1000:a797:949:5bb0:150b:9552] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "damonmarks.com"] [uri "/.htaccess"] [unique_id "ascRhiY0s1p2KD6ZBl89xwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 11:36:55
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:a797:949:5bb0:150b (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:a797:949:5bb0:150b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 07:36:49.015354 2026] [security2:error] [pid 14805:tid 14807] [client 2400:cb00:994:1000:a797:949:5bb0:150b:11323] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hotairwelder.com"] [uri "/.git/config"] [unique_id "asYu0aCF7sfLKPcQq7Y1lQAAAMA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 10:57:42
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:a797:949:5bb0:150b (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:a797:949:5bb0:150b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 06:57:33.806783 2026] [security2:error] [pid 9635:tid 9635] [client 2400:cb00:994:1000:a797:949:5bb0:150b:14087] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "santasfavorites.com"] [uri "/.env.save"] [unique_id "asYlnSAc53fwpg3EeKs_FQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 03:25:41
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:a797:949:5bb0:150b (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:a797:949:5bb0:150b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 23:25:34.191044 2026] [security2:error] [pid 31374:tid 31374] [client 2400:cb00:994:1000:a797:949:5bb0:150b:10566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3n1ent.com"] [uri "/.env"] [unique_id "asW7rqvZbmoKWOZIUCFKmAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 01:54:31
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:a797:949:5bb0:150b (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:a797:949:5bb0:150b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 21:54:22.957576 2026] [security2:error] [pid 2970360:tid 2970366] [client 2400:cb00:994:1000:a797:949:5bb0:150b:10016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aussiepens.com"] [uri "/.env.dev"] [unique_id "asWmThL0NWaabTRIDcBWDwAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-05 18:37:20
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:a797:949:5bb0:150b (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:a797:949:5bb0:150b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 14:37:11.073113 2026] [security2:error] [pid 3825:tid 3825] [client 2400:cb00:994:1000:a797:949:5bb0:150b:12022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brbcash.com"] [uri "/.env.production"] [unique_id "asPuV87aGq7NDgMiwgYAjAAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π―π΅
S.O.B.A. Dev.
2026-10-02 09:06:46
(1 week ago)
Persistent port scanning or vulnerability scanning
Port Scan