Anonymous
2026-05-19 15:47:02
(2 months ago)
Web App Attack
Brute-Force
Web App Attack
πΊπ¦
URAN Publishing Service
2026-04-23 21:27:32
(2 months ago)
172.70.111.204 - - [24/Apr/2026:00:27:23 +0300] "GET /wp-includes/Text/Diff/Renderer/ HTTP/1.1" 404 ...
show more
172.70.111.204 - - [24/Apr/2026:00:27:23 +0300] "GET /wp-includes/Text/Diff/Renderer/ HTTP/1.1" 404 768 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
172.70.111.204 - - [24/Apr/2026:00:27:32 +0300] "GET /wp-content/languages/ HTTP/1.1" 404 768 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
...
show less
Web App Attack
Anonymous
2026-04-13 13:43:00
(3 months ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-30 08:59:26
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.204 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.204 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 04:59:23.019218 2026] [security2:error] [pid 13573:tid 13573] [client 172.70.111.204:10606] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.purplebikinis.com"] [uri "/.env.bak"] [unique_id "aco7a5hzwETUq5vIcSQY5gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-30 00:22:34
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.204 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.204 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 29 20:22:28.789333 2026] [security2:error] [pid 16026:tid 16026] [client 172.70.111.204:9388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.michaelprussin.com"] [uri "/.env.docker"] [unique_id "acnCRBLgh32HCIZoOy818AAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π¦
yukon.ca
2026-03-24 21:46:08
(3 months ago)
Web Server Enforcement Violation: Web Server Exposed Git Repository Information Disclosure
Port:80
Hacking
Exploited Host
πΊπΈ
TPI-Abuse
2026-03-20 06:45:41
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.204 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.204 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 02:45:33.376972 2026] [security2:error] [pid 25123:tid 25123] [client 172.70.111.204:12612] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.partnersforaccess.net"] [uri "/.env.dist"] [unique_id "abztDcpRNze0xQkBVkOD4gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 04:42:49
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.204 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.204 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 00:42:44.303780 2026] [security2:error] [pid 24718:tid 24718] [client 172.70.111.204:12025] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.gracebaptisthartsville.com"] [uri "/web/.env"] [unique_id "abzQRMN_UYmTX1FZkzaqEAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 02:16:17
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.204 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.204 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 22:16:13.702478 2026] [security2:error] [pid 14160:tid 14160] [client 172.70.111.204:13370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.drgas.xyz"] [uri "/docker/.env"] [unique_id "abyt7cy0_gQ0CvF1rBc-AgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 01:21:53
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.204 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.204 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 21:21:48.545514 2026] [security2:error] [pid 1331:tid 1331] [client 172.70.111.204:11049] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.johnberk.com"] [uri "/app/.env"] [unique_id "abyhLKl9Im3weIUCBpDdlwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-19 12:00:10
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.204 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.204 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 08:00:06.098597 2026] [security2:error] [pid 21072:tid 21072] [client 172.70.111.204:9711] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lg.cloudex.link"] [uri "/home/.env"] [unique_id "abvlRomhP1YUOnuI-WMXYQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-19 11:28:27
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.204 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.204 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:28:20.200730 2026] [security2:error] [pid 1372325:tid 1372325] [client 172.70.111.204:10995] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.joqlawncare.com"] [uri "/app/.env"] [unique_id "abvd1MpylswYv8wFs6yk9gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-19 10:20:45
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.204 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.204 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 06:20:29.518713 2026] [security2:error] [pid 17118:tid 17118] [client 172.70.111.204:13276] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "platformintelligence.com"] [uri "/.env.tmp"] [unique_id "abvN7Tny5RKtVkOaql7vVQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-19 08:56:59
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.204 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.204 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 04:56:47.074775 2026] [security2:error] [pid 4034:tid 4034] [client 172.70.111.204:11046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.mphq.net"] [uri "/.env"] [unique_id "abu6T5kWqtHUZl0OvvNbVwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-19 07:56:37
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.204 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.204 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 03:56:29.037790 2026] [security2:error] [pid 414:tid 468] [client 172.70.111.204:9401] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ioqm.com"] [uri "/.env.orig"] [unique_id "abusLQD2EXiwFtB79Al9XgAAAQ8"]
show less
Brute-Force
Bad Web Bot
Web App Attack