๐ง๐ช
madeit
2026-08-29 23:31:55
(6 hours ago)
Web App Attack
๐ง๐ช
madeit
2026-08-19 14:45:10
(1 week ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 11:18:38
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.134.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.134.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 07:18:32.625595 2026] [security2:error] [pid 29443:tid 29443] [client 172.70.134.198:11380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.uniquetreasuresshops.com"] [uri "/.git/HEAD"] [unique_id "aoLuCNZAGjyLKZI440p7bAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
acadeova
2026-08-16 03:12:15
(2 weeks ago)
๐จ Recon detected (nft drop)
SRC=172.70.134.198
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(jour ...
show more
๐จ Recon detected (nft drop)
SRC=172.70.134.198
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
Anonymous
2026-08-16 00:48:56
(2 weeks ago)
invalid request
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 17:44:35
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.134.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.134.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 13:44:30.217668 2026] [security2:error] [pid 314580:tid 314580] [client 172.70.134.198:9934] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.ichi51e.net"] [uri "/.git/HEAD"] [unique_id "antffvjakPkLCv06m2m2OwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-10 23:18:53
(2 weeks ago)
Web App Attack
๐ฌ๐ง
sandra361
2026-05-26 03:20:01
(3 months ago)
Port scan detected: 7 attempts across 1 ports (443). | Evidence: GHOST_SCAN:IN=enp1s0f0 OUT= SRC=172 ...
show more
Port scan detected: 7 attempts across 1 ports (443). | Evidence: GHOST_SCAN:IN=enp1s0f0 OUT= SRC=172.70.134.198 LEN=60 TOS=0x00 PREC=0x00 TTL=55 ID=64021 DF PROTO=TCP SPT=11058 DPT=443 WINDOW=65535 RES=0x00 SYN URGP=0
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-15 08:53:44
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 172.70.134.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.134.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:53:32.433510 2026] [security2:error] [pid 26094:tid 26195] [client 172.70.134.198:9356] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.advantageplusfranchisor.richardleeweatherman.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.advantageplusfranchisor.richardleeweatherman.com"] [uri "/terraform.tfstate.backup"] [unique_id "agbfDKnQoKzNAeOGsCUdkQAAAhA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-05-14 01:27:59
(3 months ago)
Try to access /.aws/credentials
Web App Attack
Anonymous
2026-05-12 13:27:33
(3 months ago)
invalid request
Bad Web Bot
Web App Attack
๐ฉ๐ช
Sรฉfora Srl
2026-04-25 08:01:39
(4 months ago)
Bad user agents ignoring web crawling rules. Draing bandwidth - detected by Fail2Ban in plesk-apache ...
show more
Bad user agents ignoring web crawling rules. Draing bandwidth - detected by Fail2Ban in plesk-apache-badbot jail
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-31 00:07:49
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.134.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.134.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 20:07:41.125534 2026] [security2:error] [pid 12790:tid 12790] [client 172.70.134.198:13153] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.efsews.com"] [uri "/.env.production.bak"] [unique_id "acsQTW0w8AIn_angeG-XCAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-30 15:03:32
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.134.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.134.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 11:03:22.452166 2026] [security2:error] [pid 390:tid 390] [client 172.70.134.198:10778] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.68sportsuniforms.liddlesports.com"] [uri "/backend/.env"] [unique_id "acqQulJ_mtjmnQk8jMJo7QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-30 12:34:23
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.134.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.134.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 08:34:15.545434 2026] [security2:error] [pid 17785:tid 17785] [client 172.70.134.198:11014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.tomweston.net"] [uri "/docker/.env"] [unique_id "acptxzTI3r7jegJTWzZGQAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack