๐บ๐ธ
TPI-Abuse
2026-05-30 09:12:24
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 82.24.212.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 82.24.212.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 05:12:15.571332 2026] [security2:error] [pid 9273:tid 9273] [client 82.24.212.149:47565] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jeffjastro.com"] [uri "/sftp-config.json"] [unique_id "ahqp72u9U2Nv_KRLViu_XgAAAAM"], referer: https://www.google.com/search?q=jeffjastro.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-28 22:03:42
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-27.
show less
Web App Attack
SSH
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-05-27 22:00:20
(1 week ago)
Auto-ban: >3000 req/min op 2026-05-27
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-27 17:42:32
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 82.24.212.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 82.24.212.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 13:42:27.473482 2026] [security2:error] [pid 10810:tid 10885] [client 82.24.212.149:56191] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "birdhousefarms.com"] [uri "/wp-config.php"] [unique_id "ahctAwin-z81fTtfAjB-DQAAAJM"], referer: https://www.google.com/search?q=birdhousefarms.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-05-27 03:52:54
(1 week ago)
[WedMay2705:52:52.6850642026][security2:error][pid1082002:tid1082312][client82.24.212.149:0]ModSecur ...
show more
[WedMay2705:52:52.6850642026][security2:error][pid1082002:tid1082312][client82.24.212.149:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"cpu-services.ch\"][uri\"/.env.development.local\"][unique_id\"ahZqlHq1OLB-hb2AZuyCnQAAAQM\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 00:21:31
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 82.24.212.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 82.24.212.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 20:21:25.115946 2026] [security2:error] [pid 8357:tid 8357] [client 82.24.212.149:50467] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/config/parameters.yml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trendingnowsales.com.wholesalelivelobsters.com"] [uri "/app/config/parameters.yml"] [unique_id "ahY5BZ-7GiX4E__K7hDahAAAAAE"], referer: https://www.google.com/search?q=trendingnowsales.com.wholesalelivelobsters.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 17:54:01
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 82.24.212.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 82.24.212.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 13:53:46.031684 2026] [security2:error] [pid 22605:tid 22605] [client 82.24.212.149:33817] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||krugmans.net|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "krugmans.net"] [uri "/terraform.tfstate.backup"] [unique_id "ahXeKgZSdtuXKzFnMwQB3gAAAAU"], referer: https://www.google.com/search?q=krugmans.net
show less
Brute-Force
Bad Web Bot
Web App Attack