๐ฏ๐ต
S.O.B.A. Dev.
2026-07-15 07:23:04
(1 week ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐ฒ๐ฝ
octageeks.com
2026-07-09 04:09:59
(2 weeks ago)
Wordpress malicious attack:[octawp]
Web App Attack
๐ฉ๐ช
F242
2026-05-18 10:19:12
(2 months ago)
Wordpress soft lock
Web App Attack
๐บ๐ธ
LotPhantom
2026-04-28 17:57:26
(2 months ago)
2026/04/28 17:57:26 [error] 1764731#1764731: *4684 access forbidden by rule, client: 172.70.111.159, ...
show more
2026/04/28 17:57:26 [error] 1764731#1764731: *4684 access forbidden by rule, client: 172.70.111.159, server: wynnesmiles.com, request: "GET /.git/config HTTP/2.0", host: "wynnesmiles.com"
...
show less
Web App Attack
Anonymous
2026-04-21 00:43:22
(3 months ago)
[Tue Apr 21 02:43:21.291530 2026] [authz_core:error] [pid 15217] [client 172.70.111.159:13896] AH016 ...
show more
[Tue Apr 21 02:43:21.291530 2026] [authz_core:error] [pid 15217] [client 172.70.111.159:13896] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Apr 21 02:43:21.401926 2026] [authz_core:error] [pid 15217] [client 172.70.111.159:13896] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Apr 21 02:43:21.509578 2026] [authz_core:error] [pid 15217] [client 172.70.111.159:13896] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 05:56:32
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 01:56:28.191353 2026] [security2:error] [pid 13344:tid 13344] [client 172.70.111.159:11187] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.teenybikinigirls.com"] [uri "/.env.development.local"] [unique_id "actiDKYNiWFPZZ82yCSe9wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
octageeks.com
2026-03-31 04:09:02
(3 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
mnsf
2026-03-26 01:05:41
(3 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 21:54:50
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 17:54:44.430271 2026] [security2:error] [pid 27658:tid 27658] [client 172.70.111.159:9552] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.picayunity.com"] [uri "/.env.dist"] [unique_id "ab8TpLPPHVuG_QgBw3-nGgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 04:47:17
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 00:47:13.749875 2026] [security2:error] [pid 19919:tid 19919] [client 172.70.111.159:10639] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.verdadesreales.com"] [uri "/www/.env"] [unique_id "ab4i0cSrBI0Z9muPwXF0nAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 04:04:30
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 00:04:23.009319 2026] [security2:error] [pid 8415:tid 8415] [client 172.70.111.159:11846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dluxe.group"] [uri "/.envrc"] [unique_id "ab4YxyQWYscEOcOP8hMyywAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 07:11:15
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 03:11:09.977838 2026] [security2:error] [pid 5987:tid 5987] [client 172.70.111.159:12757] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.aisoftwaretools.com"] [uri "/web/.env"] [unique_id "abzzDaBaCW94Vd7OYaDClAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 06:28:37
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 02:28:29.997113 2026] [security2:error] [pid 17595:tid 17595] [client 172.70.111.159:13704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rheemhvac.savingshvac.com"] [uri "/.env.staging"] [unique_id "abzpDezJ3fXQUlQ-wZIAmQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 02:17:05
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 22:17:01.902551 2026] [security2:error] [pid 350:tid 350] [client 172.70.111.159:13866] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "solve4this.com"] [uri "/core/.env"] [unique_id "abyuHWcEIdLVTrXItye22AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 11:27:14
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:27:00.699477 2026] [security2:error] [pid 1372463:tid 1372463] [client 172.70.111.159:12797] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.joqlawncare.com"] [uri "/root/.env"] [unique_id "abvdhOwwbZ99qkqQTE7NIAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack