๐บ๐ธ
mawan
2026-06-20 19:48:57
(3 days ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 13:36:33
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 09:36:27.428928 2026] [security2:error] [pid 7392:tid 7392] [client 172.70.248.154:13499] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eclipsesoftware.andrew.weigel.name"] [uri "/.git/config"] [unique_id "ajKi2y76UBoBbkC3hjsyRQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-06-07 23:01:55
(2 weeks ago)
172.70.248.154 - - [08/Jun/2026:02:01:55 +0300] "GET /wp-json/psd/v1/get-details HTTP/2.0" 404 1853 ...
show more
172.70.248.154 - - [08/Jun/2026:02:01:55 +0300] "GET /wp-json/psd/v1/get-details HTTP/2.0" 404 1853 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 19:12:04
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 15:11:56.599150 2026] [security2:error] [pid 18603:tid 18603] [client 172.70.248.154:9740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nancybcatering.com"] [uri "/.git/config"] [unique_id "ah8q_OYb3PieLj4Pd9_CAAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-01 23:05:13
(3 weeks ago)
Too many Status 40X (12)
Brute-Force
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-05-26 06:34:01
(4 weeks ago)
172.70.248.154 - - [26/May/2026:09:34:01 +0300] "GET //blog/wp-includes/wlwmanifest.xml HTTP/2.0" 40 ...
show more
172.70.248.154 - - [26/May/2026:09:34:01 +0300] "GET //blog/wp-includes/wlwmanifest.xml HTTP/2.0" 404 1792 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-17 04:32:54
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 00:32:48.743180 2026] [security2:error] [pid 27632:tid 27632] [client 172.70.248.154:9449] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kingdomway.church.internet-brochures.com"] [uri "/sftp-config.json"] [unique_id "aglE8NS7f25FbAdRHRshagAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-05-12 08:19:37
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 04:23:11
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 00:23:02.851652 2026] [security2:error] [pid 15424:tid 15424] [client 172.70.248.154:13949] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "high5-vr.com"] [uri "/.env.dev"] [unique_id "agFZppJdL9eBLTszr5U7MwAAAAw"], referer: https://www.google.com/search?q=high5-vr.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-05-03 09:04:28
(1 month ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 172.70.248.154 (DE/Germany/-): 1 in ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 172.70.248.154 (DE/Germany/-): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-29 13:22:12
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 29 09:22:06.016526 2026] [security2:error] [pid 13700:tid 13700] [client 172.70.248.154:12203] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.armadillosigns.com"] [uri "/.git/config"] [unique_id "afIF_k0dJurhlTsh-zV0vQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-28 11:25:11
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 07:25:03.572589 2026] [security2:error] [pid 8870:tid 8870] [client 172.70.248.154:9314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "warpedweed.com"] [uri "/.git/config"] [unique_id "afCZD50GUzVp0ADSEJ-YOQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-26 17:14:05
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 13:13:57.379917 2026] [security2:error] [pid 32686:tid 32686] [client 172.70.248.154:10314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "primestatepainting.com"] [uri "/.git/config"] [unique_id "ae5H1W6yUloo3GcXFPc1fAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-11 08:29:28
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 11 04:29:23.822345 2026] [security2:error] [pid 121378:tid 121378] [client 172.70.248.154:11728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.kenirving.com"] [uri "/.git/config"] [unique_id "adoGY8L1tIsgQ73VAIbapQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-08 13:53:13
(2 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH