Anonymous
2026-06-17 02:27:06
(4 days ago)
(caddyscan) Scanner path probe from 172.70.240.5 (DE/Germany/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 172.70.240.5 (DE/Germany/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 172.70.240.5 - - [17/Jun/2026:02:27:00 +0000] "GET /src/.env HTTP/1.1"
[REDACTED] 200 2627 172.70.240.5 - - [17/Jun/2026:02:27:00 +0000] "GET /core/app/.env HTTP/1.1"
[REDACTED] 200 2627 172.70.240.5 - - [17/Jun/2026:02:27:01 +0000] "GET /private/.env HTTP/1.1"
[REDACTED] 200 2627 172.70.240.5 - - [17/Jun/2026:02:27:01 +0000] "GET /bootstrap/.env HTTP/1.1"
[REDACTED] 200 2627 172.70.240.5 - - [17/Jun/2026:02:27:01 +0000] "GET /database/.env HTTP/1.1"
show less
Port Scan
๐จ๐ญ
4server
2026-06-15 15:47:58
(5 days ago)
[MonJun1517:47:54.3141142026][security2:error][pid3888097:tid3888355][client172.70.240.5:0]ModSecuri ...
show more
[MonJun1517:47:54.3141142026][security2:error][pid3888097:tid3888355][client172.70.240.5:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.executivekotech.com.81-17-25-250.cpanel.site\"][uri\"/.env.local\"][unique_id\"ajAeqrrWXpIDj1Ym_XLdHwAAANE\"]\,referer:https://www.google.com/search\?q=www.executivekotech.com.81-17-25-250.cpanel.site
show less
Hacking
Web App Attack
๐ธ๐ฎ
administrator
2026-06-10 22:19:47
(1 week ago)
2026-06-08 17:42:39,582 fail2ban.actions [1104]: NOTICE [apache-fakegooglebot] Ban 172.70.24 ...
show more
2026-06-08 17:42:39,582 fail2ban.actions [1104]: NOTICE [apache-fakegooglebot] Ban 172.70.240.5
2026-06-10 00:10:56,832 fail2ban.actions [1080]: NOTICE [apache-fakegooglebot] Ban 172.70.240.5
2026-06-08 17:42:39,582 fail2ban.actions [1104]: NOTICE [apache-fakegooglebot] Ban 172.70.240.5
2026-06-10 00:10:56,832 fail2ban.actions [1080]: NOTICE [apache-fakegooglebot] Ban 172.70.240.5
...
show less
Bad Web Bot
Web Spam
Email Spam
Blog Spam
Port Scan
Brute-Force
Web App Attack
๐ฆ๐น
nomzamo
2026-06-08 16:08:26
(1 week ago)
Fail2Ban reported: nginx-noscript
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-04 15:36:22
(2 weeks ago)
(mod_security) mod_security (id:949110) triggered by 172.70.240.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:949110) triggered by 172.70.240.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 11:36:17.463615 2026] [security2:error] [pid 4599:tid 4599] [client 172.70.240.5:9471] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "sunstrongmetal.com"] [uri "/.env"] [unique_id "aiGbcUKmmU3iaHo4IaSFogAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 18:14:14
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 14:14:07.762555 2026] [security2:error] [pid 27324:tid 27324] [client 172.70.240.5:9988] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mapleleaf-marketing.com"] [uri "/.git/config"] [unique_id "ah8db8GTitFA74y_enYkAwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 13:05:04
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 09:04:57.756697 2026] [security2:error] [pid 27501:tid 27501] [client 172.70.240.5:9523] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rallyegroup.com"] [uri "/.git/config"] [unique_id "ah7U-ZEYlwTWdTD0h2-6cgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 10:51:39
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 06:51:31.430128 2026] [security2:error] [pid 6294:tid 6294] [client 172.70.240.5:10554] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eatinnola.com"] [uri "/.git/config"] [unique_id "ah61s1GPGq5DCxQvDR5tNAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-06-01 13:58:38
(2 weeks ago)
SQL backup theft attempt
Hacking
๐บ๐ธ
mnsf
2026-05-30 11:05:04
(3 weeks ago)
Abuse Detected (1)
Brute-Force
Web App Attack
Anonymous
2026-05-24 06:00:00
(4 weeks ago)
"GET /.git/config"
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-04 18:13:11
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 04 14:13:08.476484 2026] [security2:error] [pid 8084:tid 8084] [client 172.70.240.5:14160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "supportourlibrary.org"] [uri "/.git/config"] [unique_id "afjhtGMGAHgGqYbb-vy7tAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-04 15:02:50
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 04 11:02:45.845854 2026] [security2:error] [pid 7376:tid 7376] [client 172.70.240.5:13465] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fluffmoo.org"] [uri "/.git/config"] [unique_id "afi1Fdc-AJycto5eMM6cmAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-30 15:47:04
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 11:46:57.271890 2026] [security2:error] [pid 2047:tid 2047] [client 172.70.240.5:12032] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.perlcreative.com"] [uri "/.git/config"] [unique_id "afN5cS4k4UTvo6GzbQB5fAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-30 08:44:52
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 04:44:45.777548 2026] [security2:error] [pid 15506:tid 15506] [client 172.70.240.5:11016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.limoelpaso.com"] [uri "/.git/config"] [unique_id "afMWfSCb3bz8g1BIUvmBEwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack