πΊπΈ
mccsoft.io
2026-06-11 06:40:45
(1 day ago)
Web application attack / vulnerability scanning against our public nginx web server (TCP 80/443). So ...
show more
Web application attack / vulnerability scanning against our public nginx web server (TCP 80/443). Source matched a blocked-path security rule (jail nginx-444); server returned HTTP 444 (connection closed without response). TCP three-way handshake completed (full HTTP request received).
show less
Bad Web Bot
Web App Attack
πΊπΈ
WellSpring
2026-06-07 06:02:59
(5 days ago)
wordpress scan on 806.today/wp-admin/install.php β WellSpr.ing/NetSentinel civic-AI security layer
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-06 00:29:01
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 20:28:55.029628 2026] [security2:error] [pid 27694:tid 27694] [client 172.70.248.173:11039] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "julecarey.com"] [uri "/.git/config"] [unique_id "aiNpx7Nkj_Zh7MR1prnOBwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-04 21:24:56
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 17:24:50.839543 2026] [security2:error] [pid 9856:tid 9856] [client 172.70.248.173:11600] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cornerstonecharitablescholarshiptrust.org"] [uri "/.git/config"] [unique_id "aiHtIl8F3PiiEv_HKKyCxwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
ALPHANET
2026-05-31 21:46:07
(1 week ago)
web exploits
Hacking
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-31 13:17:19
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 09:17:12.128461 2026] [security2:error] [pid 13387:tid 13387] [client 172.70.248.173:10625] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.merrickarts.azbrooks.com"] [uri "/.env.development.local"] [unique_id "ahw02LdJD5p8YMUFMEDHegAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-05-27 19:47:25
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
Anonymous
2026-05-12 21:38:28
(4 weeks ago)
"GET /sftp-config.json HTTP/1.1"
Hacking
Web App Attack
π©πͺ
acadeova
2026-05-06 18:34:39
(1 month ago)
π¨ Recon detected (nft drop)
SRC=172.70.248.173
Observed=TCP dpt=2087 in=enp0s6 ttl=59
Time=recent(jo ...
show more
π¨ Recon detected (nft drop)
SRC=172.70.248.173
Observed=TCP dpt=2087 in=enp0s6 ttl=59
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
π©πͺ
FeG Deutschland
2026-04-14 07:10:23
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-04 22:42:44
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 18:42:36.600536 2026] [security2:error] [pid 7929:tid 7955] [client 172.70.248.173:10810] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.neotienda.com"] [uri "/docker/.env.local"] [unique_id "adGT3HvmuAqw8aTQgBAEKQAAANc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-04 20:17:04
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 16:16:54.166120 2026] [security2:error] [pid 1578:tid 1578] [client 172.70.248.173:13705] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kirbysheetmetalworks.kirbysmw.com"] [uri "/.env.development"] [unique_id "adFxtlpp82VCM73FA3zqYAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-04 13:55:58
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 09:55:52.100428 2026] [security2:error] [pid 9288:tid 9288] [client 172.70.248.173:10609] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "art.drjaymissdiana.com"] [uri "/config/.env.local"] [unique_id "adEYaClVwbG12KnPOuHoXgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Bedios GmbH
2026-04-04 13:49:07
(2 months ago)
Login credentials theft attempt
Hacking
πΊπΈ
TPI-Abuse
2026-04-04 06:50:59
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 02:50:54.374687 2026] [security2:error] [pid 12113:tid 12113] [client 172.70.248.173:13928] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.carterindustries.net"] [uri "/.env.production"] [unique_id "adC0zmd4n1Z2tRVXF23EQwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack