๐บ๐ธ
TPI-Abuse
2026-10-09 13:24:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.70.114.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.114.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 09:24:44.097103 2026] [security2:error] [pid 21024:tid 21024] [client 172.70.114.238:11187] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ospectra.com"] [uri "/.env"] [unique_id "asjrHK6vjTHTKcvM3q-1BgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 04:07:58
(4 days ago)
(mod_security) mod_security (id:949110) triggered by 172.70.114.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 172.70.114.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 00:07:53.235226 2026] [security2:error] [pid 18811:tid 18811] [client 172.70.114.238:12709] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "cpectec.com"] [uri "/.env"] [unique_id "asXFmaci2ocxDzwe0iVQ3QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 15:45:11
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.70.114.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.114.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 11:45:08.266160 2026] [security2:error] [pid 22285:tid 22285] [client 172.70.114.238:12588] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "disio.com"] [uri "/.env.production"] [unique_id "asUXhBh0VjQKzcjxDqar6gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-09-29 21:10:06
(1 week ago)
Web App Attack
๐ง๐ช
madeit
2026-09-15 19:22:18
(3 weeks ago)
Web App Attack
๐บ๐ธ
heyzg
2026-09-09 06:39:15
(1 month ago)
LLM Inference API Requests (Ollama) (observed): 1 HTTP
Hacking
Web App Attack
๐ง๐ช
madeit
2026-08-29 21:06:28
(1 month ago)
Web App Attack
๐ฎ๐ฉ
securejdprop
2026-08-21 07:00:10
(1 month ago)
This IP was detected by CrowdSec triggering custom/vpatch-bad-cloudflare.
Hacking
Anonymous
2026-07-26 20:22:13
(2 months ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐ฉ๐ช
acadeova
2026-07-23 08:23:30
(2 months ago)
๐จ Recon detected (nft drop)
SRC=172.70.114.238
Observed=TCP dpt=80 in=enp0s6 ttl=59
Time=recent(jour ...
show more
๐จ Recon detected (nft drop)
SRC=172.70.114.238
Observed=TCP dpt=80 in=enp0s6 ttl=59
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐ฉ๐ช
acadeova
2026-07-17 04:11:08
(2 months ago)
๐จ Recon detected (nft drop)
SRC=172.70.114.238
Observed=TCP dpt=80 in=enp0s6 ttl=59
Time=recent(jour ...
show more
๐จ Recon detected (nft drop)
SRC=172.70.114.238
Observed=TCP dpt=80 in=enp0s6 ttl=59
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-03-31 01:22:38
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.114.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.114.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 21:22:33.642738 2026] [security2:error] [pid 17486:tid 17486] [client 172.70.114.238:13501] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.microbikinitop.com"] [uri "/.env.json"] [unique_id "acsh2f5etJBdLSLRHkRAHgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-29 22:50:25
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.114.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.114.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 29 18:50:20.021307 2026] [security2:error] [pid 1964:tid 1964] [client 172.70.114.238:9752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kelting.net"] [uri "/.env.dist"] [unique_id "acmsrKIpbVX5zC8mbhHKtgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 08:20:32
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.114.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.114.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 04:20:25.440823 2026] [security2:error] [pid 12052:tid 12052] [client 172.70.114.238:10518] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.srtalent.indie100.com"] [uri "/.env.production.bak"] [unique_id "ab0DSSFo5A25UBZj8GYtigAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 07:41:51
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.114.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.114.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 03:41:41.323777 2026] [security2:error] [pid 27223:tid 27223] [client 172.70.114.238:11701] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.goatedlottosecrets.com"] [uri "/private/.env"] [unique_id "abz6Nazm8IKi_WrNdetVnQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack