๐ต๐ฑ
srebrakowski.com
2026-06-26 17:37:01
(1 day ago)
crowdsec/waf-detected-exploits
Brute-Force
๐บ๐ธ
mawan
2026-06-26 15:25:19
(1 day ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
mawan
2026-06-24 08:02:11
(3 days ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-06-16 03:33:53
(1 week ago)
[Tue Jun 16 13:33:52.435397 2026] [security2:error] [pid 197518] [client 172.70.246.64:14034] [clien ...
show more
[Tue Jun 16 13:33:52.435397 2026] [security2:error] [pid 197518] [client 172.70.246.64:14034] [client 172.70.246.64] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mareeshefford.com"] [uri "/.git/config"] [unique_id "ajDEIE4gZo1tyQa91ZJAbAAAAAs"]
...
show less
Web App Attack
๐บ๐ธ
mnsf
2026-06-07 05:05:13
(2 weeks ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 02:15:40
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.246.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.246.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 22:15:34.046823 2026] [security2:error] [pid 23261:tid 23261] [client 172.70.246.64:12510] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tijuana-bibles.com"] [uri "/.git/config"] [unique_id "ah48xtLkCCM9J4D6M01gEwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 22:13:46
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.246.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.246.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 18:13:41.627715 2026] [security2:error] [pid 28686:tid 28686] [client 172.70.246.64:13699] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.eliteelectricalservices.us"] [uri "/.git/HEAD"] [unique_id "adGNFXDiwChDeOzVgrUaLwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Roderic
2026-04-04 21:33:48
(2 months ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐บ๐ธ
mnsf
2026-04-02 20:05:33
(2 months ago)
Scanning/Probing (27)
Brute-Force
Web App Attack
๐จ๐ญ
zynex
2026-04-02 12:55:51
(2 months ago)
URL Probing: /var/www/.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-01 20:40:42
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.246.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.246.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 01 16:40:33.563262 2026] [security2:error] [pid 30046:tid 30046] [client 172.70.246.64:11359] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.jasonpolland.com"] [uri "/.env.local"] [unique_id "ac2CwffWdmK9ok7-2HO6GgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-30 18:20:18
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.246.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.246.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 14:19:58.969024 2026] [security2:error] [pid 22621:tid 22621] [client 172.70.246.64:9230] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cycontechnology.com"] [uri "/config/.env"] [unique_id "acq-zuOwNVVFYXtTmSeZfgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-30 16:18:52
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.246.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.246.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 12:18:43.217008 2026] [security2:error] [pid 8929:tid 8929] [client 172.70.246.64:12559] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.setx-law.com"] [uri "/.env"] [unique_id "acqiY8fQyAbUE4U_ANX3RwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-30 14:13:27
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.246.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.246.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 10:13:16.681708 2026] [security2:error] [pid 32297:tid 32297] [client 172.70.246.64:10816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.amazingmachining.amazinghydraulics.com"] [uri "/.env.staging"] [unique_id "acqE_KAx1cs9OVSKpUxktwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-30 12:37:39
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 172.70.246.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.246.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 08:37:30.791967 2026] [security2:error] [pid 23290:tid 23290] [client 172.70.246.64:12487] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.bot.rustyog.net|F|2"] [data ".env.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.bot.rustyog.net"] [uri "/.env.backup"] [unique_id "acpuikLs00Dm_dtGGNKNjAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack