π§πͺ
madeit
2026-09-02 16:28:49
(19 hours ago)
Web App Attack
π―π΅
S.O.B.A. Dev.
2026-07-17 16:27:23
(1 month ago)
Persistent port scanning or vulnerability scanning
Port Scan
π―π΅
S.O.B.A. Dev.
2026-06-29 21:34:33
(2 months ago)
Persistent port scanning or vulnerability scanning
Port Scan
π³π±
homeshowdomain.nl
2026-06-24 22:00:45
(2 months ago)
Auto-ban: >3000 req/min op 2026-06-24
Web App Attack
SSH
Hacking
Anonymous
2026-06-07 17:00:35
(2 months ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
πΊπΈ
wimaxnz
2026-05-07 05:38:01
(3 months ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
πΊπΈ
TPI-Abuse
2026-03-29 20:43:18
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 29 16:43:07.147693 2026] [security2:error] [pid 18859:tid 18859] [client 172.70.115.172:11689] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.michaelandkatie.us"] [uri "/server/.env"] [unique_id "acmO20OfWIXLHC_i0zvbhQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 07:41:55
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 03:41:41.695134 2026] [security2:error] [pid 29580:tid 29580] [client 172.70.115.172:12268] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.goatedlottosecrets.com"] [uri "/.env.json"] [unique_id "abz6NceENJdxoxUf7Y4vvgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 03:57:55
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 23:57:48.521724 2026] [security2:error] [pid 21191:tid 21191] [client 172.70.115.172:10847] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.abuscalledfreedom.com"] [uri "/.env.dev.local"] [unique_id "abzFvCnqyjoZAhKMbNzTUQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 03:31:51
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 23:31:15.189697 2026] [security2:error] [pid 25326:tid 25326] [client 172.70.115.172:11204] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mickeyinvitations.com"] [uri "/.env.old"] [unique_id "aby_g6OeF6gBGgQn4JAXHAAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 02:13:31
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 22:13:24.323789 2026] [security2:error] [pid 24837:tid 24837] [client 172.70.115.172:10375] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.temi.handyrehab.com"] [uri "/config/.env"] [unique_id "abytRHa7Qxv7NWJe6jHnWgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 01:07:27
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 21:07:20.578158 2026] [security2:error] [pid 21446:tid 21446] [client 172.70.115.172:9624] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.67ronin.com"] [uri "/server/.env"] [unique_id "abydyIa7_ft-mAKtgkbuswAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 00:26:38
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 20:26:34.457324 2026] [security2:error] [pid 19857:tid 19857] [client 172.70.115.172:12554] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.susanoneill.us"] [uri "/.env.prod"] [unique_id "abyUOlYvCw_tRG0clMzIOgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-24 04:33:15
(10 months ago)
[Fri Oct 24 06:33:12.421604 2025] [authz_core:error] [pid 24617] [client 172.70.115.172:11831] AH016 ...
show more
[Fri Oct 24 06:33:12.421604 2025] [authz_core:error] [pid 24617] [client 172.70.115.172:11831] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: https://www.google.com/
[Fri Oct 24 06:33:13.376606 2025] [authz_core:error] [pid 24617] [client 172.70.115.172:11831] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: https://www.google.com/
[Fri Oct 24 06:33:14.383676 2025] [authz_core:error] [pid 24617] [client 172.70.115.172:11831] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: https://www.google.com/
...
show less
Web App Attack
π«π·
sterile.network
2025-09-16 14:18:01
(11 months ago)
Blocked by UFW on ropanel1 [8443/tcp]
Source port: 11126
TTL: 46
Packet length: 60
TOS: 0x00
Port Scan