π¬π§
sandra361
2026-09-04 00:57:32
(1 day ago)
Port scan detected: 6 attempts across 1 port (443). | Evidence: REAPER_TARPIT: IN=enp1s0f0 SRC=172.7 ...
show more
Port scan detected: 6 attempts across 1 port (443). | Evidence: REAPER_TARPIT: IN=enp1s0f0 SRC=172.70.111.213 LEN=40 TOS=0x00 PREC=0x00 TTL=55 ID=34581 DF PROTO=TCP SPT=9433 DPT=443 WINDOW=65535 RES=0x00 ACK RST URGP=0
show less
Port Scan
π©πͺ
Blexyel
2026-08-23 08:15:36
(1 week ago)
172.70.111.213 - - [23/Aug/2026:10:15:35 +0200] "GET /.git/config HTTP/1.1" 200 264 "-" "Mozilla/5.0 ...
show more
172.70.111.213 - - [23/Aug/2026:10:15:35 +0200] "GET /.git/config HTTP/1.1" 200 264 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)" "136.243.2.38"
...
show less
Brute-Force
Web App Attack
π§πͺ
madeit
2026-08-19 00:38:56
(2 weeks ago)
Web App Attack
π¦π±
router.al
2026-07-25 10:54:28
(1 month ago)
07/25/2026-10:54:27.907226 172.70.111.213 Protocol: 6 ET SCAN Laravel Debug Mode Information Disclos ...
show more
07/25/2026-10:54:27.907226 172.70.111.213 Protocol: 6 ET SCAN Laravel Debug Mode Information Disclosure Probe Inbound
show less
Port Scan
π³π±
COMPLEX
2026-07-24 02:02:02
(1 month ago)
Unsolicited TCP traffic | Action: DROP | Port 8443
Brute-Force
π³π΄
jad-abuse
2026-07-04 02:36:25
(2 months ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 1 hits.
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-25 23:39:05
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 25 19:38:58.678291 2026] [security2:error] [pid 6587:tid 6587] [client 172.70.111.213:11116] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.linzylyne.com"] [uri "/api/.env"] [unique_id "acRyEk6COY5nh1vu7hcFcgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-21 00:16:49
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 20:16:42.324297 2026] [security2:error] [pid 10517:tid 10517] [client 172.70.111.213:13466] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ondakompun.com"] [uri "/.env.bak"] [unique_id "ab3javzy-M0BpgwQoUl4rwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 06:11:50
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 02:11:44.768905 2026] [security2:error] [pid 8984:tid 8984] [client 172.70.111.213:9399] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.wsdtc.net"] [uri "/app/.env"] [unique_id "abzlIFRNuLzK0H-pD29djgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 05:51:02
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 01:50:56.720579 2026] [security2:error] [pid 18332:tid 18332] [client 172.70.111.213:10748] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.haywardcarpentry.com"] [uri "/.env.local"] [unique_id "abzgQIHfcDUnW0R6mHc2rAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 01:22:50
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 21:22:44.184469 2026] [security2:error] [pid 29051:tid 29079] [client 172.70.111.213:9440] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.daydreambeliever.us"] [uri "/.env.development"] [unique_id "abyhZPq4zbbIV6We42hZLgAAAow"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 00:46:59
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 20:46:51.453330 2026] [security2:error] [pid 16084:tid 16084] [client 172.70.111.213:13872] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.seeingblue.com"] [uri "/web/.env"] [unique_id "abyY-8x8mDCYiY664CShbQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 00:06:38
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 20:06:32.997427 2026] [security2:error] [pid 538:tid 538] [client 172.70.111.213:12926] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.technoware-lb.com"] [uri "/.env.tmp"] [unique_id "abyPiAvcIE_k6Xg68UKR6gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-19 10:16:30
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 06:16:15.734518 2026] [security2:error] [pid 30870:tid 30870] [client 172.70.111.213:12252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.notariaarauco.cl"] [uri "/www/.env"] [unique_id "abvM72EcFufTSTBGgu6gFwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-19 03:16:10
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 18 23:16:05.598589 2026] [security2:error] [pid 4503:tid 4503] [client 172.70.111.213:13832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.elderlyassociation.org"] [uri "/home/.env"] [unique_id "abtqdetUhgwawpQ_Hj6zOQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack