๐บ๐ธ
TPI-Abuse
2026-08-17 23:15:56
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.134.76 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.134.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 19:15:51.330427 2026] [security2:error] [pid 32227:tid 32227] [client 172.70.134.76:11755] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.cmcnow.net"] [uri "/.git/config"] [unique_id "aoOWJwafI0wzThi7MC2-dQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 15:32:25
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.134.76 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.134.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 11:32:18.455585 2026] [security2:error] [pid 27239:tid 27261] [client 172.70.134.76:11713] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kandooo.com"] [uri "/.git/HEAD"] [unique_id "aoMpgoM49n4kaog4nnjaHwAAAVQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 13:58:19
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.134.76 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.134.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 09:58:11.319954 2026] [security2:error] [pid 6086:tid 6086] [client 172.70.134.76:12236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cain2016.org"] [uri "/.git/HEAD"] [unique_id "aoMTc1CCOke8eiTU_C2KCQAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 10:35:00
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.134.76 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.134.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:34:53.508985 2026] [security2:error] [pid 10699:tid 10699] [client 172.70.134.76:13865] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.lightbender.net"] [uri "/.git/HEAD"] [unique_id "aoLjzX0zC9bkTFyPUi_kDQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 00:32:42
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.134.76 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.134.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 20:32:36.624662 2026] [security2:error] [pid 7213:tid 7213] [client 172.70.134.76:12235] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.manty.com"] [uri "/.git/HEAD"] [unique_id "aoJWpD9k_wZ_ciVtCpF6zAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-08-16 17:03:30
(3 weeks ago)
172.70.134.76 - - [16/Aug/2026:20:03:30 +0300] "GET /wp-admin/css/ HTTP/1.1" 301 162 "-" "-"
...
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-13 20:09:08
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.134.76 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.134.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 16:09:00.355217 2026] [security2:error] [pid 5157:tid 5157] [client 172.70.134.76:10016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "evolutionmedical.help"] [uri "/.git/config"] [unique_id "an4kXJumKpAStSO3C2Uc7QAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-08-13 18:47:40
(3 weeks ago)
172.70.134.76 - - [13/Aug/2026:21:47:40 +0300] "GET /.git/config HTTP/1.1" 301 162 "-" "Mozilla/5.0 ...
show more
172.70.134.76 - - [13/Aug/2026:21:47:40 +0300] "GET /.git/config HTTP/1.1" 301 162 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Amzn-SearchBot/0.1) Chrome/119.0.6045.214 Safari/537.36"
...
show less
Hacking
Web App Attack
๐ฉ๐ช
4server
2026-08-13 05:35:45
(3 weeks ago)
[ThuAug1307:35:39.1047072026][security2:error][pid4060836:tid4060841][client172.70.134.76:0]ModSecur ...
show more
[ThuAug1307:35:39.1047072026][security2:error][pid4060836:tid4060841][client172.70.134.76:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"kiteinvest.ch\"][uri\"/.git/config\"][unique_id\"an1XqzFqX_g3IWXjEUlpFgAAAAI\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ง๐ช
madeit
2026-08-11 08:44:39
(4 weeks ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 01:46:47
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.134.76 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.134.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 21:46:42.544122 2026] [security2:error] [pid 3343494:tid 3343494] [client 172.70.134.76:9309] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.sfpantry.com"] [uri "/.git/config"] [unique_id "anp_AjUBfXdFXcDCeHk1twAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 10:11:43
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.134.76 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.134.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 06:11:35.702801 2026] [security2:error] [pid 17626:tid 17626] [client 172.70.134.76:9501] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "test.flightclaimservices.com"] [uri "/.env.php"] [unique_id "agbxV6-96RkYDz9ChkhT0AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 00:43:25
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.134.76 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.134.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 20:43:18.015018 2026] [security2:error] [pid 25356:tid 25356] [client 172.70.134.76:12314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.agapeaccounting.com"] [uri "/config/.env.local"] [unique_id "acsYphGzmxaqhekIbLxfSwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-30 11:47:20
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.134.76 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.134.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 07:47:05.699480 2026] [security2:error] [pid 4298:tid 4298] [client 172.70.134.76:11500] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.liddlesports.com"] [uri "/.env.backup"] [unique_id "acpiuVOkGsZN8ZF1G0JL-wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-30 09:52:39
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.134.76 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.134.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 05:52:33.728678 2026] [security2:error] [pid 6478:tid 6478] [client 172.70.134.76:13720] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hawaiireservations.com.kh6jim.com"] [uri "/app/.env"] [unique_id "acpH4SVyVFB63gCMRS1uCAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack