Anonymous
2026-06-25 12:12:42
(15 hours ago)
[Thu Jun 25 14:12:41.598686 2026] [authz_core:error] [pid 20640] [client 172.70.240.107:12208] AH016 ...
show more
[Thu Jun 25 14:12:41.598686 2026] [authz_core:error] [pid 20640] [client 172.70.240.107:12208] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu Jun 25 14:12:41.671538 2026] [authz_core:error] [pid 20640] [client 172.70.240.107:12208] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu Jun 25 14:12:42.006654 2026] [authz_core:error] [pid 20640] [client 172.70.240.107:12208] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐ฉ๐ช
strxmpp
2026-06-24 17:47:23
(1 day ago)
172.70.240.107 - - [24/Jun/2026:19:47:23 +0200] "GET /.env.old HTTP/2.0" 404 412 "https://www.google ...
show more
172.70.240.107 - - [24/Jun/2026:19:47:23 +0200] "GET /.env.old HTTP/2.0" 404 412 "https://www.google.com/search?q=proxy.chat.rxmpp.de" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-21 05:17:22
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.107 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 01:17:16.624012 2026] [security2:error] [pid 13747:tid 13747] [client 172.70.240.107:10665] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.elearning.nextngnr.com"] [uri "/.env.production"] [unique_id "ajdz3CGArG7vF2ET--xJKAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-06-18 03:32:54
(1 week ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 19:45:34
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.107 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 15:45:28.328771 2026] [security2:error] [pid 422:tid 422] [client 172.70.240.107:12027] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mordesign1.com"] [uri "/.git/config"] [unique_id "ai2zWGvX5N86eveGEufnNQAAAJE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-06-10 00:29:00
(2 weeks ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐บ๐ธ
mnsf
2026-06-06 01:05:08
(2 weeks ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 23:45:35
(3 weeks ago)
(mod_security) mod_security (id:949110) triggered by 172.70.240.107 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 172.70.240.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 19:45:31.483738 2026] [security2:error] [pid 7266:tid 7266] [client 172.70.240.107:12014] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "789-bid.net"] [uri "/.git/config"] [unique_id "aiC8m6i7Ap8X3Mryp1maugAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 17:12:16
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.107 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 13:12:12.185469 2026] [security2:error] [pid 3364:tid 3364] [client 172.70.240.107:13262] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "roigcorporativo.com"] [uri "/.git/config"] [unique_id "ah8O7P3_Ne60_bwucZJRCgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 16:54:33
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.107 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 12:54:28.418598 2026] [security2:error] [pid 18346:tid 18346] [client 172.70.240.107:11632] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rbmediaworks.com"] [uri "/.git/config"] [unique_id "ah8KxNWkxXIlNHk3PffJdQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 07:29:16
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.107 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 03:29:13.130951 2026] [security2:error] [pid 20521:tid 20521] [client 172.70.240.107:13446] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dryprodrain.com"] [uri "/.git/config"] [unique_id "ah6GSSU1K19seLtQSEKFiwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 06:38:48
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.107 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 02:38:42.296338 2026] [security2:error] [pid 16303:tid 16303] [client 172.70.240.107:14042] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jimvassilakos.com"] [uri "/.git/config"] [unique_id "ah56crsA_j0t3-FUbwWkAgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 03:50:58
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.107 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 23:50:52.997555 2026] [security2:error] [pid 18191:tid 18191] [client 172.70.240.107:14050] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vpatech.com"] [uri "/.git/config"] [unique_id "ah5THHmXss3t_XNThUipcQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
acadeova
2026-06-01 06:15:00
(3 weeks ago)
๐จ Recon detected (nft drop)
SRC=172.70.240.107
Observed=TCP dpt=80 in=enp0s6 ttl=59
Time=recent(jour ...
show more
๐จ Recon detected (nft drop)
SRC=172.70.240.107
Observed=TCP dpt=80 in=enp0s6 ttl=59
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐ฉ๐ช
FeG Deutschland
2026-05-23 22:48:11
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack