πΊπΈ
TPI-Abuse
2026-07-28 11:15:13
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 51.158.161.38 (38-161-158-51.rev.scw.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 51.158.161.38 (38-161-158-51.rev.scw.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 07:15:07.170124 2026] [security2:error] [pid 2838971:tid 2838971] [client 51.158.161.38:58714] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "unified-dispatch.com"] [uri "/.git/HEAD"] [unique_id "amiPO5EUVyDTvDXALvwuCAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
dpsbs
2026-06-02 15:04:40
(1 month ago)
multiple ips intrustions detected
Hacking
π¨π
backslash
2026-05-23 05:21:05
(2 months ago)
Bad Web Bot
π©πͺ
Carsten
2026-04-25 17:08:03
(3 months ago)
GET [docker-compose.yml]
Port Scan
π§πͺ
voormedia
2026-04-25 06:14:50
(3 months ago)
Accessed trap at '/docker-compose.yml'
Web App Attack
π©πͺ
burlacu.org
2026-03-06 18:00:06
(4 months ago)
Nginx multi-log analysis detected: scanner_tool. Evidence: Malicious scanner (multi-log) with scanne ...
show more
Nginx multi-log analysis detected: scanner_tool. Evidence: Malicious scanner (multi-log) with scanner detected occurrences. Blocked automatically.
show less
Port Scan
Hacking
πΊπΈ
TPI-Abuse
2026-02-17 21:31:02
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 51.158.161.38 (38-161-158-51.rev.scw.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 51.158.161.38 (38-161-158-51.rev.scw.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 17 16:30:58.810499 2026] [security2:error] [pid 31477:tid 31477] [client 51.158.161.38:37584] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "littlewizard.com.wizind.com"] [uri "/.env"] [unique_id "aZTeEsKZib6m9ugdm3UBZQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-17 21:11:31
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 51.158.161.38 (38-161-158-51.rev.scw.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 51.158.161.38 (38-161-158-51.rev.scw.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 17 16:11:22.516161 2026] [security2:error] [pid 28382:tid 28382] [client 51.158.161.38:37246] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aandsmetal.com"] [uri "/.env"] [unique_id "aZTZety6FiREnynD-YYE5AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-31 17:13:06
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 51.158.161.38 (38-161-158-51.rev.scw.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 51.158.161.38 (38-161-158-51.rev.scw.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 31 12:12:59.469369 2026] [security2:error] [pid 9472:tid 9472] [client 51.158.161.38:48916] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.trilliantsolutions.com"] [uri "/.env"] [unique_id "aX44G8jYvhBUkA1ofR8eOwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π±π»
garmtech.com
2026-01-31 16:58:44
(5 months ago)
IM360 WAF: Laravel .env file access
Web App Attack
π¨π
Kepler-1649c
2026-01-27 18:32:00
(6 months ago)
Detected Attack: Nmap.Script.Scanner
Hacking
πΊπΈ
TPI-Abuse
2026-01-07 20:31:44
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 51.158.161.38 (38-161-158-51.rev.scw.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 51.158.161.38 (38-161-158-51.rev.scw.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 07 15:31:40.901096 2026] [security2:error] [pid 5136:tid 5136] [client 51.158.161.38:58140] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "otfes.com"] [uri "/.env"] [unique_id "aV7CrKs9_XPY51ZHYQglZwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-10-16 05:10:40
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 51.158.161.38 (38-161-158-51.rev.scw.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 51.158.161.38 (38-161-158-51.rev.scw.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 16 01:10:33.674745 2025] [security2:error] [pid 31469:tid 31469] [client 51.158.161.38:41458] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.achildsspace.com"] [uri "/.git/HEAD"] [unique_id "aPB-Sa4nloKbw8RzExrvVgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2025-10-15 21:07:18
(9 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2025-10-15 20:10:03
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 51.158.161.38 (38-161-158-51.rev.scw.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 51.158.161.38 (38-161-158-51.rev.scw.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 15 16:09:57.647461 2025] [security2:error] [pid 21299:tid 21299] [client 51.158.161.38:51524] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dev.budgetguard.com"] [uri "/.git/HEAD"] [unique_id "aO__lQHJbVRemN6iUGkv2wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack