π³π±
e.fierstra
2026-04-02 12:19:53
(5 months ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-04-02 11:51:37
(5 months ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-01 22:20:32
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 01 18:20:25.423647 2026] [security2:error] [pid 32467:tid 32467] [client 172.70.240.167:9551] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.calvet1937.marcelacalvet.com"] [uri "/.env"] [unique_id "ac2aKarQWyo66bQHzO9XAwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-01 00:18:35
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 20:18:27.225954 2026] [security2:error] [pid 23563:tid 23576] [client 172.70.240.167:11948] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.strengthsmatter.com"] [uri "/.git/HEAD"] [unique_id "acxkU6RMJDP6ryGrkR-jtgAAAMo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-03-31 19:05:46
(5 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
π©πͺ
Ba-Yu
2026-03-31 14:16:39
(5 months ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-31 13:06:55
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 09:06:49.291508 2026] [security2:error] [pid 28266:tid 28266] [client 172.70.240.167:11596] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.starthreadingsalon.com"] [uri "/.git/HEAD"] [unique_id "acvG6Q3B7a8hEadpgj1BlAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-03-31 05:20:16
(5 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2026-03-31 03:24:26
(5 months ago)
172.70.240.167 - - [31/Mar/2026:05:24:25 +0200] "GET /.env.staging HTTP/1.1" 403 440 "-" "-"
...
Web App Attack
π¬π§
poundawebsiteltd
2026-03-31 03:21:49
(5 months ago)
Web App Attack (ModSecurity Block). Evidence: [REDACTED_DOMAIN]:80 172.70.240.167 - - [31/Mar/2026:0 ...
show more
Web App Attack (ModSecurity Block). Evidence: [REDACTED_DOMAIN]:80 172.70.240.167 - - [31/Mar/2026:04:21:45 +0100] GET /home/.env HTTP/1.1 403 213 - -
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-31 01:40:35
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 21:40:28.443473 2026] [security2:error] [pid 3926:tid 3926] [client 172.70.240.167:13371] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.digdesign.com"] [uri "/.git/refs/heads/main"] [unique_id "acsmDJfJal9A5xhEx9sZOgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
LRob
2026-03-30 19:45:04
(5 months ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
πΊπΈ
mnsf
2026-03-30 18:05:48
(5 months ago)
Scanning/Probing (17)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-30 16:02:18
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 12:02:12.080403 2026] [security2:error] [pid 16224:tid 16224] [client 172.70.240.167:12088] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.humaclub.com"] [uri "/.git/config"] [unique_id "acqehM-EsT10H4B0p3sOdwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-30 13:39:37
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.167 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 09:39:30.642857 2026] [security2:error] [pid 25163:tid 25163] [client 172.70.240.167:14104] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "renperfco.com"] [uri "/.env.local"] [unique_id "acp9EoDIWEfD-Dv30jKHTwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack