๐ง๐ช
madeit
2026-09-06 21:14:51
(1 day ago)
Web App Attack
๐ง๐ช
madeit
2026-08-26 21:40:21
(1 week ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 02:39:53
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.142.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.142.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 22:39:45.151382 2026] [security2:error] [pid 18980:tid 18980] [client 172.70.142.163:9626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.heidiurbanski.buffaloweddingdeejay.com"] [uri "/.git/HEAD"] [unique_id "aoPF8TQdL4Vb5dcxBwe6qgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 08:22:06
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.142.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.142.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 04:21:59.702324 2026] [security2:error] [pid 14268:tid 14268] [client 172.70.142.163:10127] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.relayer.net"] [uri "/.git/config"] [unique_id "aoLEp-Xv9X4VvE0lLatvSgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 07:34:48
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.142.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.142.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 03:34:44.437249 2026] [security2:error] [pid 23381:tid 23381] [client 172.70.142.163:12135] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.aboutio.com"] [uri "/.git/config"] [unique_id "aoK5lBQ0tcjrr1e_S25jjAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 03:42:56
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.142.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.142.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 23:42:47.198640 2026] [security2:error] [pid 27378:tid 27378] [client 172.70.142.163:9337] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clearenergyinternational.com.mroxygen.org"] [uri "/.git/config"] [unique_id "aoKDN50NR8wwAsREmuvFTgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-16 19:25:19
(3 weeks ago)
"GET /.git/HEAD HTTP/2.0"
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 06:06:24
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.142.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.142.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 02:06:16.593727 2026] [security2:error] [pid 1842:tid 1842] [client 172.70.142.163:13083] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.vincetronics.com"] [uri "/.git/HEAD"] [unique_id "aoFTWLFLNsxHCoLq3yYrFgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-15 16:33:39
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.142.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.142.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 12:33:33.363341 2026] [security2:error] [pid 13277:tid 13277] [client 172.70.142.163:11334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dandksupply.com"] [uri "/.git/config"] [unique_id "aoCU3ZgHe_kbw6yE5r-WkgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-08-12 08:04:45
(3 weeks ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
mawan
2026-07-24 18:07:48
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฌ๐ง
OptimusGO
2026-07-02 07:20:07
(2 months ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-02 08:20:07 UTC
Log evidence:
07/02/2026-08:20:03.721363 [**] [1:1000103:1] SECURITY Management Port Probe - CRITICAL [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 172.70.142.163:10083 -> 185.127.18.66:8080
show less
Port Scan
Brute-Force
Anonymous
2026-07-01 20:17:49
(2 months ago)
Web App Attack
Brute-Force
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-05-10 04:08:05
(3 months ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐ฉ๐ช
F242
2026-04-24 22:09:11
(4 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack