๐ง๐ช
madeit
2026-09-26 07:47:53
(2 days ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 10:30:59
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.174.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.174.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 06:30:50.796147 2026] [security2:error] [pid 28750:tid 28750] [client 172.70.174.128:12041] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.elsmithpest.com"] [uri "/.git/config"] [unique_id "aowdWt-gDUqtA9vGn22-ngAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-21 20:04:04
(1 month ago)
[Fri Aug 21 22:04:03.656441 2026] [authz_core:error] [pid 13286] [client 172.70.174.128:13051] AH016 ...
show more
[Fri Aug 21 22:04:03.656441 2026] [authz_core:error] [pid 13286] [client 172.70.174.128:13051] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri Aug 21 22:04:03.773118 2026] [authz_core:error] [pid 13286] [client 172.70.174.128:13051] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri Aug 21 22:04:03.888828 2026] [authz_core:error] [pid 13286] [client 172.70.174.128:13051] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
Anonymous
2026-08-21 12:56:49
(1 month ago)
[Fri Aug 21 14:56:47.513116 2026] [authz_core:error] [pid 11491] [client 172.70.174.128:12033] AH016 ...
show more
[Fri Aug 21 14:56:47.513116 2026] [authz_core:error] [pid 11491] [client 172.70.174.128:12033] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri Aug 21 14:56:47.976902 2026] [authz_core:error] [pid 11491] [client 172.70.174.128:12033] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri Aug 21 14:56:48.561302 2026] [authz_core:error] [pid 11491] [client 172.70.174.128:12033] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
Anonymous
2026-08-20 14:56:25
(1 month ago)
[Thu Aug 20 16:56:24.489835 2026] [authz_core:error] [pid 17452] [client 172.70.174.128:9526] AH0163 ...
show more
[Thu Aug 20 16:56:24.489835 2026] [authz_core:error] [pid 17452] [client 172.70.174.128:9526] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu Aug 20 16:56:24.844444 2026] [authz_core:error] [pid 17452] [client 172.70.174.128:9526] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu Aug 20 16:56:25.076913 2026] [authz_core:error] [pid 17452] [client 172.70.174.128:9526] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
Anonymous
2026-08-18 04:52:02
(1 month ago)
[Tue Aug 18 06:52:02.168671 2026] [authz_core:error] [pid 25494] [client 172.70.174.128:10291] AH016 ...
show more
[Tue Aug 18 06:52:02.168671 2026] [authz_core:error] [pid 25494] [client 172.70.174.128:10291] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Aug 18 06:52:02.276319 2026] [authz_core:error] [pid 25494] [client 172.70.174.128:10291] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Aug 18 06:52:02.384159 2026] [authz_core:error] [pid 25494] [client 172.70.174.128:10291] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐ฉ๐ช
acadeova
2026-06-12 01:46:01
(3 months ago)
๐จ Recon detected (nft drop)
SRC=172.70.174.128
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(jour ...
show more
๐จ Recon detected (nft drop)
SRC=172.70.174.128
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐ฌ๐ง
pinguin
2026-04-12 23:06:32
(5 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-06 17:50:26
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.174.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.174.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 13:50:21.352842 2026] [security2:error] [pid 312370:tid 312370] [client 172.70.174.128:13285] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.jnpmarinesolutions.com"] [uri "/root/.env"] [unique_id "adPyXaOv7q0mE3uCTZdFXAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 13:52:41
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.174.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.174.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 09:52:33.913159 2026] [security2:error] [pid 115658:tid 115658] [client 172.70.174.128:11753] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.geriterry.com"] [uri "/.env.old"] [unique_id "adO6ocClPL_WaJckb9w3BQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 18:08:47
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.174.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.174.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 14:08:39.027454 2026] [security2:error] [pid 15594:tid 15594] [client 172.70.174.128:11241] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.scienceandhumanitiespress.com"] [uri "/.git/refs/heads/main"] [unique_id "adKlJ9cKxk8kLvNjHemptAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 05:27:14
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.174.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.174.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 01:27:08.274769 2026] [security2:error] [pid 11845:tid 11845] [client 172.70.174.128:11086] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.jessicabaer.com"] [uri "/.env.dev"] [unique_id "adHyrCQaTFSvDzBFxMi94wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 20:53:49
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.174.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.174.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 16:53:43.646350 2026] [security2:error] [pid 28360:tid 28360] [client 172.70.174.128:12761] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.creartest.com"] [uri "/.env~"] [unique_id "adF6V8neNtHCENkbYRBsrAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 19:35:54
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.174.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.174.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 15:35:51.271510 2026] [security2:error] [pid 4822:tid 4822] [client 172.70.174.128:13824] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "letceteragifts.kathrynmcbride.com"] [uri "/config/.env"] [unique_id "adFoF2AoxHL-bykqNb6DUwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 09:34:19
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.174.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.174.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 05:34:10.411368 2026] [security2:error] [pid 1234:tid 1374] [client 172.70.174.128:11398] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.straight8inc.com"] [uri "/.env.orig"] [unique_id "adDbEoxXdGbDWVBcF4h97wAAANA"]
show less
Brute-Force
Bad Web Bot
Web App Attack