๐ง๐ช
madeit
2026-09-22 22:18:35
(5 hours ago)
Web App Attack
๐ง๐ช
madeit
2026-08-30 09:07:22
(3 weeks ago)
Web App Attack
๐ง๐ช
madeit
2026-08-16 02:10:11
(1 month ago)
Web App Attack
Anonymous
2026-06-30 22:34:12
(2 months ago)
suricata IPS/IDS detection, ruleset ET EXPLOIT GraphQL Introspection Query Attempt
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-25 02:38:05
(2 months ago)
(mod_security) mod_security (id:949110) triggered by 172.70.111.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 172.70.111.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 22:37:57.946849 2026] [security2:error] [pid 4990:tid 4990] [client 172.70.111.212:21577] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "crazycontrols.com"] [uri "/.env.development.local"] [unique_id "ajyUhaugu_drc1xIvpVKFAAAAA8"], referer: https://www.google.com/search?q=crazycontrols.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
wimaxnz
2026-06-13 06:22:53
(3 months ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
๐จ๐ณ
ThreatBook.io
2026-04-23 00:04:19
(5 months ago)
2026-04-22 22:31:28 /
2026-04-22 03:21:01 /aaa9
2026-04-22 04:13:54 /aaa9
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-30 09:01:46
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 05:01:39.022056 2026] [security2:error] [pid 3718:tid 3718] [client 172.70.111.212:14117] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.purplebikinis.com"] [uri "/docker/.env"] [unique_id "aco78xTkwW8fRb4fYYEXWQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-22 13:13:59
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 22 09:13:53.786484 2026] [security2:error] [pid 2467:tid 2467] [client 172.70.111.212:12252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.theknowledgemaster.com"] [uri "/.env.container"] [unique_id "ab_rEQNej5cfYqYR-_LfqgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-03-21 23:05:14
(6 months ago)
Scanning/Probing (13)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 04:44:43
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 00:44:36.499339 2026] [security2:error] [pid 14423:tid 14423] [client 172.70.111.212:14214] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.verdadesreales.com"] [uri "/admin/.env"] [unique_id "ab4iNIed33Tcy1MysqZyuwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 05:32:20
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 01:32:16.675223 2026] [security2:error] [pid 11143:tid 11143] [client 172.70.111.212:13975] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "newsite.harbouronline.com"] [uri "/.env.test"] [unique_id "abzb4DyBGfQSnfZ2r1zvtwAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 04:31:25
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 00:31:18.443885 2026] [security2:error] [pid 29559:tid 29559] [client 172.70.111.212:13833] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "goarrow.accpp.link"] [uri "/.env_config"] [unique_id "abzNljluaA0vW-PRAiOtIQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 02:53:40
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 22:53:37.419055 2026] [security2:error] [pid 18086:tid 18086] [client 172.70.111.212:14188] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.agrollum.com"] [uri "/.env.save"] [unique_id "aby2sdBPippvkmb0WXNYBwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 02:06:04
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 22:05:59.145835 2026] [security2:error] [pid 12661:tid 12661] [client 172.70.111.212:12188] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "irishsetterclubofseattle.com"] [uri "/.env.old"] [unique_id "abyrhyzT4BfOz4uSEZGczgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack