๐ซ๐ท
dynamix
2026-09-18 04:11:05
(5 hours ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-17 21:59:12
(11 hours ago)
Auto-ban: >3000 req/min op 2026-09-17
Web App Attack
SSH
Hacking
๐ซ๐ท
conseilgouz
2026-09-14 20:37:58
(3 days ago)
sae-17 : Tentative accรจs ร un rรฉpertoire cachรฉ=>/.dev.vars(/)
Hacking
Anonymous
2026-09-11 19:59:57
(6 days ago)
172.70.142.205 - - [11/Sep/2026:21:59:57 +0200] "GET /. HTTP/2.0" 301 169 "https:///search?q=" "Mozi ...
show more
172.70.142.205 - - [11/Sep/2026:21:59:57 +0200] "GET /. HTTP/2.0" 301 169 "https:///search?q=" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
show less
Web App Attack
๐ฉ๐ช
4server
2026-09-08 11:28:40
(1 week ago)
[TueSep0813:28:37.6967502026][security2:error][pid1532559:tid1532604][client172.70.142.205:0]ModSecu ...
show more
[TueSep0813:28:37.6967502026][security2:error][pid1532559:tid1532604][client172.70.142.205:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"bestrestmaterassi.ch\"][uri\"/.env.production.local\"][unique_id\"ap_xZWFdfQoCIg7JtCJlKQAAAkY\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ง๐ช
madeit
2026-09-06 09:32:20
(1 week ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 03:48:22
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.142.205 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.142.205 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 23:48:14.930577 2026] [security2:error] [pid 22871:tid 22877] [client 172.70.142.205:10844] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.hkyiquan.org"] [uri "/.git/config"] [unique_id "aoKEfjFrCj5uB6qvEoepVAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 02:48:22
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.142.205 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.142.205 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 22:48:18.318116 2026] [security2:error] [pid 11454:tid 11454] [client 172.70.142.205:11134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.carmichaellaw.org"] [uri "/.git/HEAD"] [unique_id "aoJ2cghl9bKcP1Y-x1z3jAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 00:34:48
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.142.205 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.142.205 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 20:34:41.856776 2026] [security2:error] [pid 16290:tid 16290] [client 172.70.142.205:9386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.yanchuk.org"] [uri "/.git/HEAD"] [unique_id "aoJXIec6Y4mwAR9u-TIhcAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 08:43:40
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.142.205 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.142.205 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 04:43:33.721958 2026] [security2:error] [pid 31502:tid 31502] [client 172.70.142.205:10949] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cuulvid.com.stlouisdave.com"] [uri "/.git/HEAD"] [unique_id "aoF4NWzbP13_rAcIxbRIcgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 04:19:41
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.142.205 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.142.205 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 00:19:34.102592 2026] [security2:error] [pid 3491712:tid 3491712] [client 172.70.142.205:13587] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "techsuite7.net"] [uri "/.git/HEAD"] [unique_id "anqi1gIEKgo_w1TCIJ2bwgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
OptimusGO
2026-08-05 17:35:35
(1 month ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-08-05 18:35:35 UTC
Log evidence:
172.70.142.205 - - [05/Aug/2026:18:35:33 +0100] "GET /wp-includes/css/buttons.css HTTP/1.1" 404 118 "-" "Go-http-client/1.1"
08/05/2026-18:35:34.124662 [**] [1:1000201:1] SCANNER: Bot-like User-Agent Detected [**] [Classification: Attempted Information Leak] [Priority: 2] {TCP} 172.70.142.205:14036 -> 185.127.18.66:80
08/05/2026-18:35:34.124662 [**] [1:2060252:1] ET INFO Go-http-client User-Agent Observed Inbound [**] [Classification: Misc activity] [Priority: 3] {TCP} 172.70.142.205:14036 -> 185.127.18.66:80
show less
Port Scan
Brute-Force
๐บ๐ธ
mawan
2026-07-25 11:39:01
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-01 13:33:51
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 172.70.142.205 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.142.205 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 09:33:30.438899 2026] [security2:error] [pid 27469:tid 27593] [client 172.70.142.205:45103] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||writeonce.org|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "writeonce.org"] [uri "/apache2.conf"] [unique_id "akUXKrLYHGN4ZBgThoNzIAAAAQc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-04-21 22:07:18
(4 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack