๐บ๐ธ
TPI-Abuse
2026-06-09 05:25:05
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.122 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 01:24:57.076441 2026] [security2:error] [pid 10002:tid 10002] [client 172.70.248.122:9360] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "acsellsre.com"] [uri "/.git/config"] [unique_id "aiejqUHJlUQaSXgouEkyzwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
abdubhai
2026-06-04 04:26:01
(1 week ago)
172.70.248.122 - - [04/Jun/2026:
...
Brute-Force
๐ฉ๐ช
itsolon
2026-06-04 04:20:43
(1 week ago)
172.70.248.122 - - [04/Jun/2026:06:20:40 +0200] "POST /wp-login.php HTTP/2.0" 200 21560 "https://www ...
show more
172.70.248.122 - - [04/Jun/2026:06:20:40 +0200] "POST /wp-login.php HTTP/2.0" 200 21560 "https://www.vonkuester.de/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; rv:119.0) Gecko/20100101 Firefox/119.0"
172.70.248.122 - - [04/Jun/2026:06:20:41 +0200] "POST /wp-login.php HTTP/2.0" 200 21562 "https://www.vonkuester.de/wp-login.php" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36"
172.70.248.122 - - [04/Jun/2026:06:20:42 +0200] "POST /wp-login.php HTTP/2.0" 200 21562 "https://www.vonkuester.de/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:118.0) Gecko/20100101 Firefox/118.0"
172.70.248.122 - - [04/Jun/2026:06:20:43 +0200] "POST /wp-login.php HTTP/2.0" 200 21556 "https://www.vonkuester.de/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:118.0) Gecko/20100101 Firefox/118.0"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 17:24:49
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.122 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 13:24:41.912662 2026] [security2:error] [pid 13928:tid 13928] [client 172.70.248.122:12257] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theprairiejewel.com"] [uri "/.git/config"] [unique_id "ah8R2XDqBrtOIHbA4luW_AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
inlink.ltd
2026-05-25 22:52:24
(2 weeks ago)
Known malicious PHP file or CMS probe
Web App Attack
๐ท๐บ
DZBOT
2026-05-22 04:39:38
(2 weeks ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-05-22 04:06:12
(2 weeks ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐จ๐ญ
backslash
2026-05-15 09:12:02
(3 weeks ago)
block ruleset bad bot: misc bad content F608233CC4C86EE814CE8DDDA9C4A0D3C79882F6
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-15 08:47:42
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.122 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:47:34.575667 2026] [security2:error] [pid 13447:tid 13484] [client 172.70.248.122:10068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pluralmatrix.cynosureinternetservices.com"] [uri "/sftp-config.json"] [unique_id "agbdpuKWfeJho_TDubTsfgAAAcQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-14 04:38:28
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.122 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 00:38:21.082152 2026] [security2:error] [pid 32423:tid 32423] [client 172.70.248.122:12549] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.onward.ws"] [uri "/.git/config"] [unique_id "agVRvaSRcr8-pSTfil9_WAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 15:13:09
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.122 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 11:13:04.217350 2026] [security2:error] [pid 25470:tid 25470] [client 172.70.248.122:11565] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "photonmatrix.com"] [uri "/.git/config"] [unique_id "af39gHIDXjZlmZclHjCg4QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 10:47:17
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.122 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 06:47:13.552900 2026] [security2:error] [pid 28750:tid 28750] [client 172.70.248.122:13044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eye7graphics.com"] [uri "/.git/config"] [unique_id "af2_MZTiV5LpYkzSUVaMmwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-07 16:31:57
(1 month ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ฟ๐ฆ
Tokolosh Hunters
2026-05-05 18:16:46
(1 month ago)
AutoBlockWindow-Known bad useragent query-2026-05-05 18:16:45
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-04 16:12:56
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.122 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 04 12:12:53.238289 2026] [security2:error] [pid 10104:tid 10104] [client 172.70.248.122:13628] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "asociacioncopan.org"] [uri "/.git/config"] [unique_id "afjFhQbFRtIQ_5n4NMDDDQAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack