๐ฉ๐ช
4server
2026-09-28 17:05:22
(3 days ago)
[MonSep2819:05:17.3656132026][security2:error][pid1137222:tid1137342][client172.70.142.87:0]ModSecur ...
show more
[MonSep2819:05:17.3656132026][security2:error][pid1137222:tid1137342][client172.70.142.87:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"hdcadvisory.ch.136-243-54-122.cpanel.site\"][uri\"/.docker/config.json\"][unique_id\"arqeTRl4LH6CGxcKShSvLAAAAQc\"]\,referer:https://www.google.com/search\?q=hdcadvisory.ch.136-243-54-122.cpanel.site
show less
Port Scan
Brute-Force
Web App Attack
๐ง๐ช
madeit
2026-09-18 18:26:31
(1 week ago)
Web App Attack
๐ง๐ช
madeit
2026-09-01 12:50:03
(1 month ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 07:11:40
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.142.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.142.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 03:11:33.745092 2026] [security2:error] [pid 15969:tid 15969] [client 172.70.142.87:9567] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.gapanda.com"] [uri "/.git/config"] [unique_id "aoK0JQLsdl7jMuBlkzSsnAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
kumiko
2026-08-16 22:01:57
(1 month ago)
[2026-08-17 01:01:55] Probing for dotfiles
"GET /.git/config HTTP/2.0" 403
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 08:15:55
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.142.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.142.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 04:15:48.537774 2026] [security2:error] [pid 26125:tid 26125] [client 172.70.142.87:13993] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.k-h-w.com"] [uri "/.git/HEAD"] [unique_id "aoFxtCFtcgozbTf3zDMiSQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 06:07:06
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.142.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.142.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 02:06:58.186032 2026] [security2:error] [pid 28206:tid 28206] [client 172.70.142.87:10648] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "karishma.byles.net"] [uri "/.git/config"] [unique_id "aoFTghz6lKBPbV1WJ4az_AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-07-25 11:39:00
(2 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
mawan
2026-04-21 22:06:22
(5 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ซ๐ท
Campus France
2026-02-05 07:37:33
(7 months ago)
172.70.142.87 - - [05/Feb/2026:08:37:23 +0100] "POST /wp-login.php HTTP/1.1" 301 650 "https://barwoo ...
show more
172.70.142.87 - - [05/Feb/2026:08:37:23 +0100] "POST /wp-login.php HTTP/1.1" 301 650 "https://barwoodd.site/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Safari/605.1.15"
172.70.142.87 - - [05/Feb/2026:08:37:25 +0100] "POST /wp-login.php HTTP/1.1" 301 650 "https://barwoodd.site/wp-login.php" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36"
172.70.142.87 - - [05/Feb/2026:08:37:28 +0100] "POST /wp-login.php HTTP/1.1" 301 650 "https://barwoodd.site/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
172.70.142.87 - - [05/Feb/2026:08:37:30 +0100] "POST /wp-login.php HTTP/1.1" 301 650 "https://barwoodd.site/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36"
172.70.142.87 - - [05/Feb/2026:08:37:33 +0100] "POST /wp-login
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
mawan
2025-12-22 09:41:38
(9 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
mawan
2025-12-16 20:03:51
(9 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
mawan
2025-12-15 14:25:42
(9 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฎ๐ฉ
hermawan
2025-11-27 07:55:33
(10 months ago)
[Thu Nov 27 11:40:06.991179 2025] [security2:error] [pid 551762:tid 139901050648256] [client 172.70. ...
show more
[Thu Nov 27 11:40:06.991179 2025] [security2:error] [pid 551762:tid 139901050648256] [client 172.70.142.87:34714] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "CF-RAY" at REQUEST_HEADERS_NAMES:Cf-Ray. [file "/etc/modsecurity/coreruleset-4.20.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "399"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: CF-RAY found within REQUEST_HEADERS_NAMES:Cf-Ray: Cf-Ray request_line = GET /images/gempa/webp/20251109100133.mmi.jpg.webp HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/gempa/webp/20251109100133.mmi.jpg.webp"] [unique_id "aSfWJpufXBJ3o8SsjQzDmAAABwA"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[551816] [QVRvG0znN08] [aSfWJpufXBJ3o8SsjQzDmAAABwA] keep_alive=[1] [2025-11-27 11:40:06.991193] [R:aSfWJpufXBJ3o8SsjQzDmAAABwA] Host:'staklim-jatim.bmkg.go.id' ACCEPT:'image/jpeg,image/png,image/gif;q=0.1,image/*;q=0.1' Accept-Encoding
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-11-26 07:59:23
(10 months ago)
[Wed Nov 26 14:27:30.125669 2025] [security2:error] [pid 1349156:tid 140675239544512] [client 172.70 ...
show more
[Wed Nov 26 14:27:30.125669 2025] [security2:error] [pid 1349156:tid 140675239544512] [client 172.70.142.87:26820] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "CF-RAY" at REQUEST_HEADERS_NAMES:Cf-Ray. [file "/etc/modsecurity/coreruleset-4.20.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "394"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: CF-RAY found within REQUEST_HEADERS_NAMES:Cf-Ray: Cf-Ray request_line = GET /images/Klimatologi/Infografis/Infografis-Iklim/Dasarian/2025/10_Oktober_2025/Das-II/Infografis_Dasarian_Iklim_Jawa_Timur_Update_20_Oktober_2025-600.webp HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/images/Klimatologi/Infografis/Infografis-Iklim/Dasarian/2025/10_Oktober_2025/Das-II/Infografis_Dasarian_Iklim_Jawa_Timur_Update_20_Oktober_2025-600.webp"] [unique_id "aSar4kgG1o4OTOExW8n-1gAAVRY"] [staklim-malang.info] [staklim-malang.info] top=[1349179] [rDg6VPoG/rY] [aSar4kgG1o4
...
show less
Hacking
Web App Attack