๐ง๐ช
madeit
2026-09-05 13:20:33
(5 days ago)
Web App Attack
๐ฎ๐ฉ
securejdprop
2026-08-24 23:01:49
(2 weeks ago)
This IP was detected by CrowdSec triggering custom/vpatch-bad-cloudflare.
Hacking
๐ง๐ช
madeit
2026-08-22 22:24:33
(2 weeks ago)
Web App Attack
๐ง๐ช
madeit
2026-08-06 05:27:56
(1 month ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-30 01:16:31
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.209 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 29 21:16:25.498477 2026] [security2:error] [pid 7439:tid 7439] [client 172.70.115.209:12089] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.puckerbackbikini.com"] [uri "/var/www/html/.env"] [unique_id "acnO6Sj4hu1iHAcRqsGjZAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-29 19:54:25
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.209 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 29 15:54:19.497088 2026] [security2:error] [pid 13053:tid 13053] [client 172.70.115.209:10141] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.fruitinthedesert.com"] [uri "/docker/.env"] [unique_id "acmDa6B7oY0LqFzmq7iFpQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
LotPhantom
2026-03-20 16:43:01
(5 months ago)
2026/03/20 16:42:59 [error] 2491776#2491776: *167720 access forbidden by rule, client: 172.70.115.20 ...
show more
2026/03/20 16:42:59 [error] 2491776#2491776: *167720 access forbidden by rule, client: 172.70.115.209, server: wynnesmiles.bridginggaps.tech, request: "GET /.env.tmp HTTP/2.0", host: "wynnesmiles.bridginggaps.tech"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 09:01:13
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.209 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 05:01:05.642776 2026] [security2:error] [pid 31411:tid 31473] [client 172.70.115.209:10988] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blackhillsproperty.omegaoak.com"] [uri "/.env.local"] [unique_id "ab0M0Teqrz252n0gEl_FeQAAAMU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 05:26:33
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.209 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 01:26:20.524519 2026] [security2:error] [pid 2606:tid 2606] [client 172.70.115.209:10534] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "esmital.cl"] [uri "/.env.dist"] [unique_id "abzafIhmciyN3bGQnNIgPgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 02:14:11
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.209 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 22:14:03.750246 2026] [security2:error] [pid 27956:tid 27956] [client 172.70.115.209:9445] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.temi.handyrehab.com"] [uri "/.env.dist"] [unique_id "abytawGa04jwywe99Y8_rgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 01:02:10
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.209 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 21:02:03.887882 2026] [security2:error] [pid 19530:tid 19530] [client 172.70.115.209:14058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.technologymoods.com"] [uri "/.env.json"] [unique_id "abyci3efKShAVunUz6yiswAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 00:29:52
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.209 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 20:29:48.714238 2026] [security2:error] [pid 5932:tid 5932] [client 172.70.115.209:9507] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.musiclips4spotify.com"] [uri "/.env.bak"] [unique_id "abyU_ExqcKeYRD4K79Lo_AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-25 07:50:26
(6 months ago)
| SQL injection attempt.
Web App Attack
Hacking
SQL Injection
๐ฉ๐ช
abdubhai
2026-01-02 13:27:53
(8 months ago)
172.70.115.209 - - [02/Jan/2026:
...
Brute-Force
Anonymous
2025-09-09 05:55:28
(1 year ago)
[Tue Sep 09 07:55:27.177718 2025] [authz_core:error] [pid 4197] [client 172.70.115.209:9480] AH01630 ...
show more
[Tue Sep 09 07:55:27.177718 2025] [authz_core:error] [pid 4197] [client 172.70.115.209:9480] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Sep 09 07:55:27.348741 2025] [authz_core:error] [pid 4197] [client 172.70.115.209:9480] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Sep 09 07:55:27.523655 2025] [authz_core:error] [pid 4197] [client 172.70.115.209:9480] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack