๐ง๐ช
madeit
2026-08-21 20:56:09
(5 days ago)
Web App Attack
๐ง๐ช
madeit
2026-08-08 01:03:33
(2 weeks ago)
Web App Attack
๐ฉ๐ช
updown.io
2026-07-19 19:28:11
(1 month ago)
{"level":"info","ts":1784486247.3770673,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1784486247.3770673,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"172.70.243.183","remote_port":"13911","client_ip":"172.70.243.183","proto":"HTTP/1.1","method":"GET","host":"thestatus.nimizz.com","uri":"/wp-includes/style-engine/about.php","headers":{"X-Forwarded-For":["20.9.15.100"],"Accept-Encoding":["gzip"],"Cf-Connecting-Ip":["20.9.15.100"],"Cf-Visitor":["{\"scheme\":\"http\"}"],"Cf-Ray":["a1dbd665bf52acff-FRA"],"Cdn-Loop":["cloudflare; loops=1"],"Connection":["Keep-Alive"],"Cf-Ipcountry":["US"],"X-Forwarded-Proto":["http"]}},"bytes_read":0,"user_id":"","duration":0.00006798,"size":0,"status":308,"resp_headers":{"Server":["Caddy"],"Connection":["close"],"Location":["https://thestatus.nimizz.com/wp-includes/style-engine/about.php"],"Content-Type":[]}}
{"level":"info","ts":1784486279.5315087,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"172.70.243.183","remote_port":"9247","client_ip":"172.70.243
...
show less
DDoS Attack
Web App Attack
๐ณ๐ฑ
COMPLEX
2026-06-23 00:05:48
(2 months ago)
Unsolicited TCP traffic | Action: DROP | Port 8443
Brute-Force
๐บ๐ธ
wimaxnz
2026-05-21 06:30:27
(3 months ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-08 01:12:47
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.243.183 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.243.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 21:12:40.057862 2026] [security2:error] [pid 22746:tid 22746] [client 172.70.243.183:13010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tylerdroneservices.com"] [uri "/.git/config"] [unique_id "af04iObhkF80e2D3kUvJdgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-05-02 12:01:58
(3 months ago)
Try to access /.git/config
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-30 12:04:14
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.243.183 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.243.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 08:04:08.016684 2026] [security2:error] [pid 24326:tid 24326] [client 172.70.243.183:10911] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.timezonespro.com"] [uri "/.git/config"] [unique_id "afNFODZyuX-U_TiCOv8OcQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-17 14:03:42
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 172.70.243.183 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.243.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 17 10:03:36.392085 2026] [security2:error] [pid 2034614:tid 2034640] [client 172.70.243.183:11189] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.btrofficial.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.btrofficial.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "aeI9uHXubYVr2-x_IsvLTwAAARE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 03:03:07
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.243.183 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.243.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 23:02:59.659452 2026] [security2:error] [pid 1955908:tid 1955908] [client 172.70.243.183:10937] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.livresanciens.fritsknuf.com"] [uri "/.git/config"] [unique_id "adXFY4qdVAKyDJLSFlZVCwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 14:07:43
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.243.183 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.243.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 10:07:31.192595 2026] [security2:error] [pid 31657:tid 31657] [client 172.70.243.183:10732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tvsolar.aguasolar.com"] [uri "/.env.dev"] [unique_id "adEbI1I6Dyxk40DupLb2IgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 04:41:42
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.243.183 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.243.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 00:41:33.084306 2026] [security2:error] [pid 5730:tid 5736] [client 172.70.243.183:9749] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "icbc-canada.com"] [uri "/.git/HEAD"] [unique_id "adCWfbRTCr3Tv3qQVpMwegAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-04-03 10:05:28
(4 months ago)
Scanning/Probing (14)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 03:49:40
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.243.183 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.243.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 23:49:35.217754 2026] [security2:error] [pid 25969:tid 25969] [client 172.70.243.183:12360] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.tell-me-first.com"] [uri "/.git/config"] [unique_id "ac84z1HmbRSYf8YBRK1O7AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-04-01 05:38:20
(4 months ago)
(apache-empty-ua) Failed empty apache-ua trigger with match [redacted]): (CF_ENABLE)
Hacking