πΊπΈ
mawan
2026-06-24 21:02:12
(3 days ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-15 11:17:04
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 07:16:58.857684 2026] [security2:error] [pid 3420:tid 3420] [client 172.68.245.45:9989] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rockinr.org"] [uri "/sftp-config.json"] [unique_id "agcAqv_otLUOOPUcQzBEowAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-15 08:41:39
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:41:18.210714 2026] [security2:error] [pid 4004:tid 4004] [client 172.68.245.45:14073] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "periodthreads.com"] [uri "/.env.development.local"] [unique_id "agbcLpz_kgFc2TKHa3YrxAAAAAU"], referer: https://www.google.com/search?q=periodthreads.com
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
oncord
2026-04-16 07:28:10
(2 months ago)
Form spam
Web Spam
πΊπΈ
mnsf
2026-04-07 12:05:46
(2 months ago)
Scanning/Probing (15)
Brute-Force
Web App Attack
πΊπΈ
mnsf
2026-04-03 10:05:44
(2 months ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-31 00:41:55
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 20:41:48.460953 2026] [security2:error] [pid 18150:tid 18150] [client 172.68.245.45:13124] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clubfansite.com.creartest.com"] [uri "/backend/.env"] [unique_id "acsYTBqRPwqZY84UIy6T7AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
www.mammazone.it
2026-03-30 17:49:23
(2 months ago)
fabiodirauso.it:80 172.68.245.45 - - [30/Mar/2026:19:49:20 +0200] "HEAD /old/ HTTP/1.1" 200 280 "-" ...
show more
fabiodirauso.it:80 172.68.245.45 - - [30/Mar/2026:19:49:20 +0200] "HEAD /old/ HTTP/1.1" 200 280 "-" "Mozilla/5.0 (Linux; Android 14; Xiaomi 14 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.6478.33 Mobile Safari/537.36"
fabiodirauso.it:80 172.68.245.45 - - [30/Mar/2026:19:49:22 +0200] "HEAD /backup/ HTTP/1.1" 200 280 "-" "Mozilla/5.0 (Linux; Android 14; Xiaomi 14 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.6478.33 Mobile Safari/537.36"
...
show less
Hacking
πΊπΈ
TPI-Abuse
2026-03-30 08:23:30
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 04:23:20.873656 2026] [security2:error] [pid 24883:tid 24883] [client 172.68.245.45:9864] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.jeanlouisdarville.com"] [uri "/web/.env"] [unique_id "acoy-B_UOiv2qDnhg3O7GAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-30 06:59:32
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 02:59:27.461490 2026] [security2:error] [pid 16238:tid 16238] [client 172.68.245.45:13215] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.iee-usa.com"] [uri "/.env2"] [unique_id "acofTzQigrNHFvu4vKKSYwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-30 05:50:44
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 01:50:40.450384 2026] [security2:error] [pid 10315:tid 10327] [client 172.68.245.45:13107] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.nederbragt.net"] [uri "/.env.local"] [unique_id "acoPMKlcoI7Aei_7Qhl1gAAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-30 05:14:18
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 01:14:11.893373 2026] [security2:error] [pid 27583:tid 27583] [client 172.68.245.45:11065] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.vendor21.com"] [uri "/.env2"] [unique_id "acoGo1-ojgw4JJAIo1nBawAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-30 04:13:43
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 00:13:38.295135 2026] [security2:error] [pid 5123:tid 5123] [client 172.68.245.45:11206] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "myatherapy.abecasis.com"] [uri "/.env.staging"] [unique_id "acn4cgltafu2pYaoB8jfRAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-30 01:02:40
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 29 21:02:35.043123 2026] [security2:error] [pid 27605:tid 27605] [client 172.68.245.45:12903] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.robcruickshank.com"] [uri "/admin/.env"] [unique_id "acnLq9j08rsvo4606ogrPgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-29 22:19:22
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 29 18:19:16.062950 2026] [security2:error] [pid 19511:tid 19511] [client 172.68.245.45:11382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.swelpix.com"] [uri "/.env.save"] [unique_id "acmlZOAyWz4WtIL-JvaedwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack