π·πΊ
DZBOT
2026-06-20 11:15:54
(1 day ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-18 15:44:09
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.147 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 11:44:02.535400 2026] [security2:error] [pid 13329:tid 13379] [client 172.70.240.147:14162] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.bakmail.net"] [uri "/.git/config"] [unique_id "ajQSQvx7s1iLp3jJTXbXiwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-14 02:18:33
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 172.70.240.147 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.240.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 22:18:26.861612 2026] [security2:error] [pid 23327:tid 23327] [client 172.70.240.147:12544] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.garyandthegroove.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.garyandthegroove.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "ai4PcqsE4Jq-ap6woYkFQgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-06-07 05:05:12
(2 weeks ago)
Abuse Detected (1)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-02 15:47:15
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.147 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 11:47:10.619461 2026] [security2:error] [pid 4409:tid 4409] [client 172.70.240.147:11129] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hollorancompanies.com"] [uri "/.git/config"] [unique_id "ah76_lHp1zmItlLU5scIsgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-02 10:07:56
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.147 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 06:07:49.634484 2026] [security2:error] [pid 8328:tid 8328] [client 172.70.240.147:10769] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "californiacbcdelegation.com"] [uri "/.git/config"] [unique_id "ah6rdZmAchc0cPPygc788AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-13 09:24:22
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.147 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 05:24:07.644220 2026] [security2:error] [pid 9269:tid 9269] [client 172.70.240.147:9690] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "onevoicefoundationlb.org"] [uri "/.env.production"] [unique_id "agRDN6ahQG9-xKQwUBPS6wAAAA0"], referer: https://www.google.com/search?q=onevoicefoundationlb.org
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-12 13:21:41
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.147 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 09:21:33.367617 2026] [security2:error] [pid 32640:tid 32640] [client 172.70.240.147:9508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "globalodit.com"] [uri "/.env"] [unique_id "agMpXX94d7R_eVhmccbMUgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-08 13:44:08
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.147 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 09:44:00.801415 2026] [security2:error] [pid 7489:tid 7489] [client 172.70.240.147:10319] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "unitedwestandent.org"] [uri "/sftp-config.json"] [unique_id "af3ooB3W_U_7hMlgBvpwuwAAAAk"], referer: https://www.google.com/search?q=unitedwestandent.org
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-07 17:55:19
(1 month ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
πΊπΈ
TPI-Abuse
2026-05-05 00:24:24
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.147 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 04 20:24:19.646089 2026] [security2:error] [pid 10883:tid 10883] [client 172.70.240.147:12135] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "joshuashands.org"] [uri "/.git/config"] [unique_id "afk4syYVDyFLayTRLr_YVAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π―π΅
S.O.B.A. Dev.
2026-04-30 09:30:04
(1 month ago)
Persistent port scanning or vulnerability scanning
Port Scan
π±πΉ
NotACaptcha
2026-04-30 01:00:46
(1 month ago)
webserver:443 [30/Apr/2026] "GET /.env.backup HTTP/1.1" 404 4309 "https://www.google.com/search?q=a ...
show more
webserver:443 [30/Apr/2026] "GET /.env.backup HTTP/1.1" 404 4309 "https://www.google.com/search?q=asunledevles.duckdns.org" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-22 17:01:48
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.147 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 22 13:01:41.797002 2026] [security2:error] [pid 10551:tid 10551] [client 172.70.240.147:13630] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "more-grace.com"] [uri "/.env.bak"] [unique_id "aej-9TeWPP8Zh9-ObqYZtgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-20 23:37:54
(2 months ago)
172.70.240.147 - - [21/Apr/2026:07:37:44 +0800] "GET /.git/config HTTP/1.1" 404 196 "-" "Mozilla/5.0 ...
show more
172.70.240.147 - - [21/Apr/2026:07:37:44 +0800] "GET /.git/config HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:137.0) Gecko/20100101 Firefox/137.0"
...
show less
Bad Web Bot
Web App Attack