π§πͺ
madeit
2026-09-07 16:00:46
(1 month ago)
Web App Attack
π§πͺ
madeit
2026-08-20 23:42:41
(1 month ago)
Web App Attack
π―π΅
S.O.B.A. Dev.
2026-08-20 09:30:41
(1 month ago)
Persistent port scanning or vulnerability scanning
Port Scan
π§πͺ
madeit
2026-08-09 15:27:21
(2 months ago)
Web App Attack
π©πͺ
acadeova
2026-08-08 19:18:57
(2 months ago)
π¨ Recon detected (nft drop)
SRC=172.69.71.47
Observed=TCP dpt=80 in=enp0s6 ttl=56
Time=recent(journa ...
show more
π¨ Recon detected (nft drop)
SRC=172.69.71.47
Observed=TCP dpt=80 in=enp0s6 ttl=56
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
π³π±
homeshowdomain.nl
2026-07-29 22:07:42
(2 months ago)
Auto-ban: >3000 req/min op 2026-07-29
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-06-21 04:25:22
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.71.47 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.71.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 00:25:14.501348 2026] [security2:error] [pid 28988:tid 29009] [client 172.69.71.47:12688] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dermatologycoloradosprings.com.aafm.us"] [uri "/.env.backup"] [unique_id "ajdnqhBPgLC6hNl1KYb9OwAAAQI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-17 00:34:45
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.71.47 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.71.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 20:34:40.148901 2026] [security2:error] [pid 24854:tid 24941] [client 172.69.71.47:13915] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.giorgiogranozio.com"] [uri "/.git/HEAD"] [unique_id "ajHroPDEcuzoFfIBtOmcsgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
myagent.site
2026-03-31 07:22:28
(6 months ago)
Blocking for trying to access an exploit file: /.env.bak
Hacking
πΊπΈ
myagent.site
2026-03-20 01:50:51
(6 months ago)
Blocking for trying to access an exploit file: /.env.save
Hacking
πΊπΈ
chrisj
2026-02-12 21:16:04
(7 months ago)
[Thu Feb 12 21:14:48.094546 2026] [proxy_fcgi:error] [pid 745344:tid 745344] [client 172.69.71.47:13 ...
show more
[Thu Feb 12 21:14:48.094546 2026] [proxy_fcgi:error] [pid 745344:tid 745344] [client 172.69.71.47:13432] AH01071: Got error 'Primary script unknown'
[Thu Feb 12 21:15:11.507384 2026] [proxy_fcgi:error] [pid 745344:tid 745344] [client 172.69.71.47:13432] AH01071: Got error 'Primary script unknown'
[Thu Feb 12 21:16:04.698015 2026] [proxy_fcgi:error] [pid 746905:tid 746905] [client 172.69.71.47:11665] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Anonymous
2025-12-15 18:23:33
(9 months ago)
[Mon Dec 15 19:23:32.491878 2025] [authz_core:error] [pid 22596] [client 172.69.71.47:11211] AH01630 ...
show more
[Mon Dec 15 19:23:32.491878 2025] [authz_core:error] [pid 22596] [client 172.69.71.47:11211] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon Dec 15 19:23:33.294613 2025] [authz_core:error] [pid 22596] [client 172.69.71.47:11211] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon Dec 15 19:23:33.567246 2025] [authz_core:error] [pid 22596] [client 172.69.71.47:11211] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2025-06-07 13:51:01
(1 year ago)
(mod_security) mod_security (id:240335) triggered by 172.69.71.47 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 172.69.71.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 07 09:50:57.474237 2025] [security2:error] [pid 575700:tid 575700] [client 172.69.71.47:60248] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 69.49.228.101 (0+1 hits since last alert)|www.nursetammytalks.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.nursetammytalks.com"] [uri "/xmlrpc.php"] [unique_id "aERDwZKLPnRrD2HcBk7DRwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-06-02 09:18:12
(1 year ago)
(mod_security) mod_security (id:240335) triggered by 172.69.71.47 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 172.69.71.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 02 05:18:09.238017 2025] [security2:error] [pid 3262080:tid 3262080] [client 172.69.71.47:49812] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.185.4.20 (+1 hits since last alert)|rodrigoaldecoa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rodrigoaldecoa.com"] [uri "/xmlrpc.php"] [unique_id "aD1sUZDay8X1ohDbLwFBEAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-05-13 08:00:04
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH