π©πͺ
XICTRON
2026-09-10 05:45:15
(1 hour ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
Anonymous
2026-09-02 16:31:31
(1 week ago)
[Wed Sep 02 18:31:28.263458 2026] [authz_core:error] [pid 20346] [client 172.70.243.124:9240] AH0163 ...
show more
[Wed Sep 02 18:31:28.263458 2026] [authz_core:error] [pid 20346] [client 172.70.243.124:9240] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: https://antler-snacks.com/wordpress/wp-admin/
[Wed Sep 02 18:31:29.940169 2026] [authz_core:error] [pid 20346] [client 172.70.243.124:9240] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: https://antler-snacks.com/wordpress/wp-admin/
[Wed Sep 02 18:31:29.968741 2026] [authz_core:error] [pid 20346] [client 172.70.243.124:9240] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: https://antler-snacks.com/wordpress/wp-admin/
...
show less
Web App Attack
Anonymous
2026-09-01 16:41:15
(1 week ago)
[Tue Sep 01 18:41:13.931134 2026] [authz_core:error] [pid 26531] [client 172.70.243.124:13154] AH016 ...
show more
[Tue Sep 01 18:41:13.931134 2026] [authz_core:error] [pid 26531] [client 172.70.243.124:13154] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Sep 01 18:41:14.261548 2026] [authz_core:error] [pid 26531] [client 172.70.243.124:13154] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Sep 01 18:41:14.364122 2026] [authz_core:error] [pid 26531] [client 172.70.243.124:13154] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
π·πΊ
DZBOT
2026-08-16 23:37:06
(3 weeks ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
Anonymous
2026-08-13 22:14:20
(3 weeks ago)
[Fri Aug 14 00:13:39.786811 2026] [authz_core:error] [pid 2875] [client 172.70.243.124:13106] AH0163 ...
show more
[Fri Aug 14 00:13:39.786811 2026] [authz_core:error] [pid 2875] [client 172.70.243.124:13106] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri Aug 14 00:14:19.935756 2026] [authz_core:error] [pid 3159] [client 172.70.243.124:11649] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri Aug 14 00:14:19.958598 2026] [authz_core:error] [pid 3159] [client 172.70.243.124:11649] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
Anonymous
2026-04-30 14:11:19
(4 months ago)
Web app attack and vulnerability scan detected from IIS logs
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-07 00:42:11
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.243.124 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.243.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 20:42:07.721962 2026] [security2:error] [pid 1113769:tid 1113769] [client 172.70.243.124:13284] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.warshaw1.com"] [uri "/.git/logs/HEAD"] [unique_id "adRS37E0uhYHNAdsWX-I7wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-05 19:46:59
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.243.124 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.243.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 15:46:54.565174 2026] [security2:error] [pid 12027:tid 12027] [client 172.70.243.124:10605] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.waleed-alshalan.com"] [uri "/.git/config"] [unique_id "adK8LnNipx2h8kGjQUUPCgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-05 06:29:07
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.243.124 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.243.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 02:29:00.761985 2026] [security2:error] [pid 24478:tid 24478] [client 172.70.243.124:10055] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.player-care.us"] [uri "/.env"] [unique_id "adIBLLWJnzkOC6eekrVEHAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-04 18:12:51
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.243.124 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.243.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 14:12:47.584392 2026] [security2:error] [pid 24951:tid 24951] [client 172.70.243.124:9315] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.elegantweddingnapkins.com"] [uri "/.git/refs/heads/master"] [unique_id "adFUn7dqKSeVFqJ3O8EcQQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-04-04 13:06:13
(5 months ago)
Scanning/Probing (45)
Brute-Force
Web App Attack
πΊπΈ
myagent.site
2026-04-04 06:25:20
(5 months ago)
Blocking for trying to access an exploit file: /admin/.env
Hacking
π³π±
jjnxpct
2026-04-04 03:53:45
(5 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /docker/.env.local (Rule ID: 930130) - Restricted File Access Attempt
show less
Web App Attack
Hacking
π©πͺ
Vegascosmetics
2026-04-03 21:50:50
(5 months ago)
Kingcopy(AI-IDS):IP does Multiple AWS Environment Abuse
Hacking
Web App Attack
π¦πΊ
aranguren.org
2026-04-02 20:56:21
(5 months ago)
172.70.243.124 - - [03/Apr/2026:07:56:21 +1100] "GET /.git/index HTTP/2.0" 404 999 "-" "-"
172.70.24 ...
show more
172.70.243.124 - - [03/Apr/2026:07:56:21 +1100] "GET /.git/index HTTP/2.0" 404 999 "-" "-"
172.70.243.124 - - [03/Apr/2026:07:56:21 +1100] "GET /.git/refs/heads/main HTTP/2.0" 404 999 "-" "-"
172.70.243.124 - - [03/Apr/2026:07:56:21 +1100] "GET /.git/config HTTP/2.0" 404 999 "-" "-"
172.70.243.124 - - [03/Apr/2026:07:56:21 +1100] "GET /.env.production HTTP/2.0" 404 999 "-" "-"
172.70.243.124 - - [03/Apr/2026:07:56:21 +1100] "GET /.env.development HTTP/2.0" 404 999 "-" "-"
172.70.243.124 - - [03/Apr/2026:07:56:21 +1100] "GET /.env.dev HTTP/2.0" 404 999 "-" "-"
...
show less
Bad Web Bot