๐ท๐บ
DZBOT
2026-07-20 21:40:41
(1 day ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-02 19:00:17
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.32 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 15:00:12.736336 2026] [security2:error] [pid 27020:tid 27020] [client 172.70.240.32:12919] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "asurprisinglittletown.com"] [uri "/.git/config"] [unique_id "aka1PCIL5UE3f_5rl16RVQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-02 12:40:19
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.32 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 08:40:15.100815 2026] [security2:error] [pid 26478:tid 26478] [client 172.70.240.32:9449] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sharkfamily.com"] [uri "/.git/config"] [unique_id "akZcLxQ7wqk_D-BdHBlbGAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-21 05:06:38
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.32 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 01:06:28.460684 2026] [security2:error] [pid 29513:tid 29513] [client 172.70.240.32:13146] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.eastmansmainecraft.arsenaultartistmanagement.com"] [uri "/.env.dist"] [unique_id "ajdxVMGHE5JyAZmRkwC5XQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-06-20 04:54:34
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฉ๐ช
femboy.cat
2026-06-16 22:57:20
(1 month ago)
Port scan to tcp/8443 from 172.70.240.32
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-11 06:22:51
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.32 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 02:22:47.381969 2026] [security2:error] [pid 19053:tid 19053] [client 172.70.240.32:11054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "snapdragonworkshops.com"] [uri "/.git/config"] [unique_id "aipUN9A7ql2qkYJCDZ-dOwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
sandra361
2026-06-10 11:17:01
(1 month ago)
Port scan detected: 10 attempts across 1 ports (443). | Evidence: REAPER_TARPIT: IN=enp1s0f0 SRC=172 ...
show more
Port scan detected: 10 attempts across 1 ports (443). | Evidence: REAPER_TARPIT: IN=enp1s0f0 SRC=172.70.240.32 LEN=60 TOS=0x00 PREC=0x00 TTL=56 ID=65287 DF PROTO=TCP SPT=13252 DPT=443 WINDOW=65535 RES=0x00 SYN URGP=0
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-02 14:41:52
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.32 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 10:41:44.543307 2026] [security2:error] [pid 19563:tid 19563] [client 172.70.240.32:11694] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trademartghana.com"] [uri "/.git/config"] [unique_id "ah7rqErL-ROZDZSA-WymsQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-05-31 23:32:37
(1 month ago)
[MonJun0101:32:31.7430952026][security2:error][pid1869803:tid1869837][client172.70.240.32:0]ModSecur ...
show more
[MonJun0101:32:31.7430952026][security2:error][pid1869803:tid1869837][client172.70.240.32:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(curl\|wget\|python\|nikto\|sqlmap\|acunetix\|fimap\|dirbuster\|cmsmap\)\"atREQUEST_HEADERS:user-agent.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"217\"][id\"990210\"][msg\"Suspicioususer-agentblocked\"][hostname\"wp.aaaa6877.org\"][uri\"/.git/config\"][unique_id\"ahzFD83Tio1RyFANLrIC3gAAABE\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฌ๐ง
sandra361
2026-05-30 21:37:01
(1 month ago)
Port scan detected: 6 attempts across 1 ports (443). | Evidence: REAPER_TARPIT:IN=enp1s0 OUT= SRC=17 ...
show more
Port scan detected: 6 attempts across 1 ports (443). | Evidence: REAPER_TARPIT:IN=enp1s0 OUT= SRC=172.70.240.32 LEN=60 TOS=0x00 PREC=0x00 TTL=56 ID=18057 DF PROTO=TCP SPT=9521 DPT=443 WINDOW=65535 RES=0x00 SYN URGP=0
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-27 15:51:58
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.32 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 11:51:46.605846 2026] [security2:error] [pid 10598:tid 10598] [client 172.70.240.32:11072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.airwatering.grancanariaholidays.com"] [uri "/.env"] [unique_id "ahcTEjcNtUsLdyY4gDQ9KwAAAAo"], referer: http://www.radio2m.ma/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-05-20 11:15:13
(2 months ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ซ๐ฎ
inlink.ltd
2026-05-14 19:14:11
(2 months ago)
Known malicious PHP file or CMS probe
Web App Attack
๐ฆ๐บ
trentwiles.com
2026-05-14 03:26:08
(2 months ago)
Unauthorized connection attempt detected from IP address 172.70.240.32 to port 443 [SYD]
Port Scan