π―π΅
S.O.B.A. Dev.
2026-06-13 09:25:56
(1 week ago)
Persistent port scanning or vulnerability scanning
Port Scan
π©πͺ
F242
2026-05-19 21:06:46
(1 month ago)
Wordpress Login or XMLRPC abuse
Web App Attack
π©πͺ
F242
2026-04-17 04:41:37
(2 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack
π©πͺ
big-cloud.nl
2026-04-07 00:49:12
(2 months ago)
Try to access /.git/logs/HEAD
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-06 00:21:00
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.247.56 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.247.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 20:20:52.770153 2026] [security2:error] [pid 24070:tid 24089] [client 172.70.247.56:13088] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.plasticsurgeonbrazil.aafm.us"] [uri "/.git/HEAD"] [unique_id "adL8ZLrJ9gukVdJPB9ghVQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Mangelot Hosting
2026-04-03 18:47:14
(2 months ago)
(modsecurity) srv103 ModSecurity 172.70.247.56 (DE/Germany/-): 10 in the last 3600 secs; Ports: *; D ...
show more
(modsecurity) srv103 ModSecurity 172.70.247.56 (DE/Germany/-): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-03 13:28:08
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.247.56 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.247.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 09:28:01.252275 2026] [security2:error] [pid 2892:tid 2892] [client 172.70.247.56:12460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.eran.construction"] [uri "/.git/config"] [unique_id "ac_AYRnM8000-2dOirKGlAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
big-cloud.nl
2026-04-03 09:36:48
(2 months ago)
Try to access /.git/config
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-31 10:24:08
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.247.56 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.247.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 06:24:03.875292 2026] [security2:error] [pid 30729:tid 30729] [client 172.70.247.56:12729] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.ouguergouz.com"] [uri "/.git/config"] [unique_id "acugw3m9RflXudUItqmtjAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-31 07:07:03
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.247.56 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.247.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 03:06:55.147370 2026] [security2:error] [pid 17528:tid 17528] [client 172.70.247.56:13466] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ukrainianspy.banis-associates.com"] [uri "/private/.env"] [unique_id "actyj5CsargldFOouPpMegAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
www.mammazone.it
2026-03-31 05:44:41
(2 months ago)
[Tue Mar 31 07:44:41.225393 2026] [proxy_fcgi:error] [pid 3742190] [client 172.70.247.56:14310] AH01 ...
show more
[Tue Mar 31 07:44:41.225393 2026] [proxy_fcgi:error] [pid 3742190] [client 172.70.247.56:14310] AH01071: Got error 'Primary script unknown'
...
show less
Hacking
Web App Attack
πΊπΈ
mnsf
2026-03-30 18:06:43
(2 months ago)
Scanning/Probing (18)
Brute-Force
Web App Attack
π³π±
Site.eu
2026-03-30 15:51:19
(2 months ago)
Excessive 404/403 errors
Brute-Force
π©πͺ
mygcode.de
2026-03-30 15:13:55
(2 months ago)
Scanning for Exploits
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-03-30 08:21:42
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.247.56 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.247.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 04:21:35.942468 2026] [security2:error] [pid 20684:tid 20684] [client 172.70.247.56:10118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.mrbss.com"] [uri "/.git/refs/heads/main"] [unique_id "acoyjw9-dPVYo2pRHF4O5wAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack