๐บ๐ธ
mnsf
2026-06-07 08:07:39
(1 week ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 07:35:37
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.246.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.246.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 03:35:30.513827 2026] [security2:error] [pid 13476:tid 13476] [client 172.70.246.21:13450] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "barnesandbrower.com"] [uri "/.git/config"] [unique_id "ah6HwgfulY0R0m98ka5EOgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-05-20 11:07:58
(4 weeks ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐จ๐ญ
TheCoon
2026-04-04 20:45:02
(2 months ago)
Automated: Credential theft attempt - JSON bomb served
Web App Attack
Hacking
๐ซ๐ท
masterguru
2026-04-04 10:07:09
(2 months ago)
Blocked Cloudflare Worker request. Pattern match "." at REQUEST_HEADERS:cf-worker. (5025-196)
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-03 03:49:51
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.246.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.246.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 23:49:43.696726 2026] [security2:error] [pid 27066:tid 27066] [client 172.70.246.21:13287] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.acupressbooks.com"] [uri "/.git/HEAD"] [unique_id "ac841y-MDxdtzjF-N9ZPAAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-04-02 21:43:04
(2 months ago)
Try to access /brandpreventie//.git/config
Web App Attack
๐ซ๐ท
masterguru
2026-04-02 10:19:11
(2 months ago)
Blocked Cloudflare Worker request. Pattern match "." at REQUEST_HEADERS:cf-worker. (5025-193)
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-02 10:03:07
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.246.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.246.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 06:03:00.794527 2026] [security2:error] [pid 19718:tid 19718] [client 172.70.246.21:12807] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.quantumacceleration.org"] [uri "/.git/index"] [unique_id "ac4-1GI4VJ10xLc60mBJVwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-01 11:05:25
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.246.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.246.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 01 07:05:17.996959 2026] [security2:error] [pid 4912:tid 4916] [client 172.70.246.21:11142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.cynosureinternetservices.com"] [uri "/.env.production.local"] [unique_id "acz77ZOAfj0_5Cu7I0bZMgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-03-30 22:00:27
(2 months ago)
Auto-ban: >3000 req/min op 2026-03-30
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-03-30 08:26:11
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.246.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.246.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 04:26:04.296130 2026] [security2:error] [pid 8552:tid 8552] [client 172.70.246.21:13728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.insect-politics.com"] [uri "/.git/HEAD"] [unique_id "acoznILrvOY555nRuIAdGAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-03-21 04:17:09
(2 months ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hary74656
2026-03-21 03:15:19
(2 months ago)
[Sat Mar 21 04:15:11.101622 2026] [security2:error] [pid 17224:tid 17343] [client 172.70.246.21:1026 ...
show more
[Sat Mar 21 04:15:11.101622 2026] [security2:error] [pid 17224:tid 17343] [client 172.70.246.21:10262] [client 172.70.246.21] ModSecurity: Access denied with code 403 (phase 2). Pattern match "Search Engine" at TX:httpbl_msg. [file "/usr/share/modsecurity-crs/rules/REQUEST-910-IP-REPUTATION.conf"] [line "199"] [id "910150"] [msg "HTTP Blacklist match for search engine IP"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-ip"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [hostname "26th.eu"] [uri "/.git/config"] [unique_id "ab4NPp1BWHrP7gysFd3ZkQAABCU"]
[Sat Mar 21 04:15:11.115389 2026] [security2:error] [pid 17224:tid 17348] [client 172.70.246.21:10262] [client 172.70.246.21] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted F
...
show less
Web App Attack
๐บ๐ธ
mnsf
2026-03-21 01:07:52
(2 months ago)
Scanning/Probing (21)
Brute-Force
Web App Attack