๐บ๐ธ
TPI-Abuse
2026-10-06 16:31:16
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 172.70.231.69 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.231.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 12:31:10.407631 2026] [security2:error] [pid 24827:tid 24827] [client 172.70.231.69:12087] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||erinrusso.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "erinrusso.com"] [uri "/index.php.bak"] [unique_id "asUiTo_jLMGKAb_RqTI0MQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 17:03:35
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 172.70.231.69 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.231.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 13:03:32.327245 2026] [security2:error] [pid 10200:tid 10200] [client 172.70.231.69:13659] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.normteslaa.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.normteslaa.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asKG5N0bPFbqU-wJ19EE_AAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 09:14:41
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.70.231.69 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.231.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 05:14:37.841735 2026] [security2:error] [pid 1853:tid 1869] [client 172.70.231.69:9664] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "captainpurpleproductions.com"] [uri "/wp-config.php.old"] [unique_id "asIY_SRNNqBLwHwFcrvIUAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-14 20:21:43
(1 month ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐ณ๐ฑ
COMPLEX
2026-07-30 00:36:36
(2 months ago)
Unsolicited TCP traffic | Action: DROP | Port 8443
Brute-Force
๐ฎ๐ฉ
gonet.home
2026-07-19 03:30:32
(2 months ago)
Security Event Detected by SOC Gonet: event=alert, hits=1
Brute-Force
๐ฎ๐ฉ
gonet.home
2026-07-18 03:30:08
(2 months ago)
Security Event Detected by SOC Gonet: event=alert, hits=1
Brute-Force
๐ณ๐ฑ
COMPLEX
2026-07-17 01:08:15
(2 months ago)
Unsolicited TCP traffic | Action: DROP | Port 8443
Brute-Force
๐ฎ๐ฉ
gonet.home
2026-07-16 12:40:08
(2 months ago)
Security Event Detected by SOC Gonet: event=alert, hits=1
Brute-Force
๐ณ๐ฑ
COMPLEX
2026-07-03 02:34:50
(3 months ago)
Unsolicited TCP traffic | Action: DROP | Port 8443
Brute-Force
Anonymous
2026-05-07 16:53:06
(4 months ago)
Web Probe / Attack
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-04-21 23:33:44
(5 months ago)
172.70.231.69 - - [22/Apr/2026:02:32:55 +0300] "GET /wp-includes/widgets/ HTTP/1.1" 404 770 "-" "Moz ...
show more
172.70.231.69 - - [22/Apr/2026:02:32:55 +0300] "GET /wp-includes/widgets/ HTTP/1.1" 404 770 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
172.70.231.69 - - [22/Apr/2026:02:33:43 +0300] "GET /wp-content/plugins/ubh/ HTTP/1.1" 404 770 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 00:29:34
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.231.69 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.231.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 20:29:24.751611 2026] [security2:error] [pid 1300251:tid 1300251] [client 172.70.231.69:9683] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.bikiniwatersports.com"] [uri "/.env.dev"] [unique_id "adWhZDdprUDiW0ySC_W7XQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-01 13:44:12
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.231.69 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.231.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 01 09:44:07.523322 2026] [security2:error] [pid 21974:tid 21974] [client 172.70.231.69:13687] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bespoke-ss.c-w-a-m.com"] [uri "/backend/.env"] [unique_id "ac0hJ8Bk6owMQitfGypBBAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mw
2026-03-30 00:35:54
(6 months ago)
GET /.env.development.local HTTP/1.1
Web App Attack