π»π³
cimee
2026-09-11 02:48:56
(1 day ago)
This IP accessed the path /.env.local, which is banned.
Bad Web Bot
Web App Attack
π§πͺ
madeit
2026-09-01 02:56:18
(1 week ago)
Web App Attack
π¨π
4server
2026-08-21 04:01:05
(3 weeks ago)
[FriAug2106:01:01.3612772026][security2:error][pid4052398:tid4052654][client172.70.174.101:0]ModSecu ...
show more
[FriAug2106:01:01.3612772026][security2:error][pid4052398:tid4052654][client172.70.174.101:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"465\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"webmail.verticalti.ch\"][uri\"/.git/HEAD\"][unique_id\"aofNfWpn2IhVlh6LiIiPsgAAABQ\"]
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 14:52:34
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.174.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.174.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 10:52:29.293374 2026] [security2:error] [pid 21026:tid 21026] [client 172.70.174.101:13017] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.mitchellamazing.com"] [uri "/.git/HEAD"] [unique_id "aoMgLS5RRzw2WE5hemxVfAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 12:31:59
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.174.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.174.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 08:31:53.248104 2026] [security2:error] [pid 26925:tid 26925] [client 172.70.174.101:13299] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.zodiacgate.com"] [uri "/.git/HEAD"] [unique_id "aoL_OXzE2DiHw-01OzfTngAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 05:09:42
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.174.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.174.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 01:09:35.215421 2026] [security2:error] [pid 24733:tid 24733] [client 172.70.174.101:10635] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.aticom.es"] [uri "/.git/HEAD"] [unique_id "aoFGD0OwsCuT0-pJgQXJ6AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
madeit
2026-08-09 10:20:16
(1 month ago)
Web App Attack
π©πͺ
acadeova
2026-08-02 03:09:28
(1 month ago)
π¨ Recon detected (nft drop)
SRC=172.70.174.101
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(jour ...
show more
π¨ Recon detected (nft drop)
SRC=172.70.174.101
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-05-15 08:10:21
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.174.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.174.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:10:06.229286 2026] [security2:error] [pid 29480:tid 29480] [client 172.70.174.101:10221] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alexlacruz.com"] [uri "/.env.dusk.local"] [unique_id "agbU3pwAzbj7R2T0oImU3AAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mawan
2026-04-21 06:46:53
(4 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-07 07:01:27
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.174.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.174.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 03:01:17.323108 2026] [security2:error] [pid 1021385:tid 1021385] [client 172.70.174.101:12349] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.digdesign.com"] [uri "/.env.tmp"] [unique_id "adSrvTLAadC8kj0I1SjayQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-06 11:04:53
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.174.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.174.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 07:04:43.555622 2026] [security2:error] [pid 1375:tid 1375] [client 172.70.174.101:14137] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.twilighthackers.com"] [uri "/.env.production"] [unique_id "adOTS9zTdSzoNiihisqqiQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-04 09:45:19
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.174.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.174.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 05:45:13.820976 2026] [security2:error] [pid 1234:tid 1360] [client 172.70.174.101:12759] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "madring.live.venezuelaguia.com"] [uri "/.env.php"] [unique_id "adDdqYxXdGbDWVBcF4h-mgAAAMg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-04 07:49:31
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.174.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.174.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 03:49:19.754496 2026] [security2:error] [pid 16150:tid 16150] [client 172.70.174.101:11378] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "179vfs.com.extreme-atv.com"] [uri "/.env.tmp"] [unique_id "adDCf6vuYGNz120sIWSXhgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-04 04:42:08
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.174.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.174.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 00:42:02.605932 2026] [security2:error] [pid 9780:tid 9780] [client 172.70.174.101:9866] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.80corvette.com"] [uri "/.env.orig"] [unique_id "adCWmsEb5fVyDnP3rh6oBwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack