๐บ๐ธ
TPI-Abuse
2026-10-08 16:34:41
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 12:34:35.594503 2026] [security2:error] [pid 10119:tid 10119] [client 172.70.115.180:13169] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tckgbookkeeping.biz"] [uri "/.env"] [unique_id "asfGG9yPc7l93IHjuU6y8gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 08:38:13
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 04:38:07.150699 2026] [security2:error] [pid 5162:tid 5162] [client 172.70.115.180:13593] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "acquivest.net"] [uri "/.htaccess"] [unique_id "asdWb7hc3GRVfMeRqMywLwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 15:03:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 11:03:14.636254 2026] [security2:error] [pid 1403:tid 1403] [client 172.70.115.180:10334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cdromline.com"] [uri "/.env.dev"] [unique_id "asZfMncXGeyIDZk05lx7VAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 04:58:58
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 00:58:51.735185 2026] [security2:error] [pid 14863:tid 14863] [client 172.70.115.180:10352] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "epicjellyfish.com"] [uri "/.htaccess"] [unique_id "asMui2iM8iBN1Fv8fAnzwAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 20:29:27
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 172.70.115.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.115.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 16:29:23.083710 2026] [security2:error] [pid 15136:tid 15157] [client 172.70.115.180:12415] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||farmerlabor.org|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "farmerlabor.org"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asK3Iy9URxpl-D7YsBUyDwAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฐ
sbk97 (https://sayor.net)
2026-10-04 07:42:20
(4 days ago)
SAYOR honeypot: observed attack /sites/default/files/
Brute-Force
๐ง๐ช
madeit
2026-09-28 11:53:10
(1 week ago)
Web App Attack
๐ง๐ช
madeit
2026-09-18 18:34:42
(2 weeks ago)
Web App Attack
๐บ๐ธ
johnkarlhill
2026-09-14 18:45:29
(3 weeks ago)
WebKnight blocked malicious web request on johnkarlhill.com
Brute-Force
SSH
๐ฉ๐ช
Vegascosmetics
2026-09-09 17:35:58
(4 weeks ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possi ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possible exploited host). Evidence: AttackPattern: /wp-includes/ (Match: /wp-includes/)
show less
Hacking
Exploited Host
Web App Attack
๐ง๐ช
madeit
2026-09-06 16:35:48
(1 month ago)
Web App Attack
๐บ๐ธ
mawan
2026-08-21 15:12:42
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฎ๐ฉ
securejdprop
2026-08-21 10:08:02
(1 month ago)
This IP was detected by CrowdSec triggering custom/vpatch-bad-cloudflare.
Hacking
๐ง๐ช
madeit
2026-08-21 08:47:08
(1 month ago)
Web App Attack
Anonymous
2026-08-16 22:45:46
(1 month ago)
Automatic report - Vulnerability scan
/forum7/memberlist.php?mode=viewprofile&u=4&sid=f1c3abe66b4c6b ...
show more
Automatic report - Vulnerability scan
/forum7/memberlist.php?mode=viewprofile&u=4&sid=f1c3abe66b4c6ba6941f0408e9b1a98a
show less
Web App Attack