๐ซ๐ฎ
nNordic
2026-06-09 09:12:18
(5 days ago)
Connection attempt blocked by IDS/IPS from 172.70.240.21/32
Hacking
Anonymous
2026-06-08 02:26:11
(6 days ago)
[Mon Jun 08 04:26:07.797345 2026] [authz_core:error] [pid 16584] [client 172.70.240.21:9710] AH01630 ...
show more
[Mon Jun 08 04:26:07.797345 2026] [authz_core:error] [pid 16584] [client 172.70.240.21:9710] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon Jun 08 04:26:07.986339 2026] [authz_core:error] [pid 16584] [client 172.70.240.21:9710] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon Jun 08 04:26:08.011576 2026] [authz_core:error] [pid 16584] [client 172.70.240.21:9710] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 23:03:07
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 19:03:03.841528 2026] [security2:error] [pid 11465:tid 11465] [client 172.70.240.21:13217] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "touchmypython.bwill.dev"] [uri "/.git/config"] [unique_id "aiX4p0nvzAG3bGt5GL267wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 02:05:17
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 22:05:11.100801 2026] [security2:error] [pid 19349:tid 19349] [client 172.70.240.21:13550] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drgtek.com.smogsandiego.com"] [uri "/.git/config"] [unique_id "aiTR1yyuMlpqE1RHzgXwwgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-06-04 09:10:52
(1 week ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 16:36:20
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 12:36:13.230149 2026] [security2:error] [pid 13291:tid 13291] [client 172.70.240.21:13698] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "professorjunk.com"] [uri "/.git/config"] [unique_id "ah8GfVLwKajohjj7DJmrOgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 14:37:22
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 10:37:14.888760 2026] [security2:error] [pid 32624:tid 32633] [client 172.70.240.21:11938] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tkfay.com"] [uri "/.git/config"] [unique_id "ah7qmj_aWheH2VVxHOo7NgAAAMQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 09:59:09
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 05:59:06.126713 2026] [security2:error] [pid 1640:tid 1640] [client 172.70.240.21:11079] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "briannalls.com"] [uri "/.git/config"] [unique_id "ah6paj7OP37ySh-7rhTejgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 09:33:12
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 05:33:07.085295 2026] [security2:error] [pid 27628:tid 27648] [client 172.70.240.21:14010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "baronlongford.com"] [uri "/.git/config"] [unique_id "ah6jUwalG9o7yNkQimX1fAAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-28 06:13:15
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 28 02:13:09.085762 2026] [security2:error] [pid 23246:tid 23246] [client 172.70.240.21:13997] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trclegacyholdings.org.ryanc.net"] [uri "/.git/config"] [unique_id "ahfc9VNouUePu7C6qXcA8AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
abdubhai
2026-05-27 16:20:13
(2 weeks ago)
172.70.240.21 - - [27/May/2026:2
...
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-16 06:58:47
(4 weeks ago)
(mod_security) mod_security (id:210730) triggered by 172.70.240.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.240.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 02:58:42.863061 2026] [security2:error] [pid 8692:tid 8692] [client 172.70.240.21:13167] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||anrfilters.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "anrfilters.com"] [uri "/backup.sql"] [unique_id "aggVop6hcFOQiQhrQGrzagAAABo"], referer: https://www.google.com/search?q=anrfilters.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
dispensight
2026-05-15 23:57:31
(4 weeks ago)
Automated WordPress exploit probe via honeydomain. UA: dispensight.cyou. Cloudflare Germany proxy.
Bad Web Bot
๐ฌ๐ง
openstrike.co.uk
2026-05-13 05:13:29
(1 month ago)
2 attacks on env grabbing URLs:
GET /.env.local HTTP/1.1
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-05 17:56:49
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 05 13:56:42.802331 2026] [security2:error] [pid 4750:tid 4750] [client 172.70.240.21:10930] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wheelworks.my"] [uri "/.env.save"] [unique_id "afovWoUCnHab7G5wm4ybEAAAAAQ"], referer: https://www.google.com/search?q=wheelworks.my
show less
Brute-Force
Bad Web Bot
Web App Attack