๐บ๐ธ
TPI-Abuse
2026-06-12 18:07:07
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 172.70.248.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.248.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 14:07:01.970819 2026] [security2:error] [pid 20122:tid 20122] [client 172.70.248.198:11470] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.cbcfargo.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.cbcfargo.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "aixKxXc-U-GkJ6t7xO9U8gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xxkodedxx
2026-06-09 22:53:01
(4 days ago)
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 1ร edge-block in 10 ...
show more
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 1ร edge-block in 10m window.
Origin: DE / AS13335 Cloudflare, Inc.
Active: 22:52:17 UTC
Volume: 1 HTTP req
Probed: /.git/config
Status mix: 444ร1
UA: "Mozilla/5.0 (X11; Linux x86_64; rv:127.0) Gecko/20100101 Firefox/127.0"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
Smish
2026-06-07 08:54:44
(6 days ago)
HONEYPOT HIT --> Fail2ban time=1780822482 log=2026-06-07T09:54:42+01:00 ip=172.70.248.198 host=vmhos ...
show more
HONEYPOT HIT --> Fail2ban time=1780822482 log=2026-06-07T09:54:42+01:00 ip=172.70.248.198 host=vmhost01.mci.as210667.net method=GET uri="/.env.development.local" status=404 ua="Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:137.0) Gecko/20100101 Firefox/137.0" ref="-" rid=af637ee459bc3241a6083aad2fcab483
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 16:33:25
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 12:33:19.696192 2026] [security2:error] [pid 19371:tid 19371] [client 172.70.248.198:10677] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "braintechsoftwaresolutions.com"] [uri "/.git/config"] [unique_id "aiL6T7NGVIdRHLLwVzFCogAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-05 14:06:03
(1 week ago)
Trying to access config files
Web App Attack
Anonymous
2026-06-04 13:06:02
(1 week ago)
Trying to access config files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 07:51:44
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 03:51:37.654366 2026] [security2:error] [pid 17787:tid 17787] [client 172.70.248.198:11880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bccnews.us"] [uri "/.git/config"] [unique_id "aiEuiTBjsi6HJjXtCxhotQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-03 12:06:09
(1 week ago)
Trying to access config files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 19:17:43
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 15:17:36.683020 2026] [security2:error] [pid 32038:tid 32038] [client 172.70.248.198:12815] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "swiss-pac.com"] [uri "/.git/config"] [unique_id "ah8sUOHu_VZ7nyZiNvAUIAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 16:37:30
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 12:37:22.514033 2026] [security2:error] [pid 9503:tid 9503] [client 172.70.248.198:10226] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sketchnotebook.com"] [uri "/.git/config"] [unique_id "ah8GwrqiALLKwvA6td4CqwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 14:26:29
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 10:26:23.344951 2026] [security2:error] [pid 18270:tid 18408] [client 172.70.248.198:10120] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lasertagandgames.com"] [uri "/.git/config"] [unique_id "ah7oD_bbZROOXDwJsq_lIgAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-02 10:06:04
(1 week ago)
Trying to access config files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 09:11:17
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 05:11:14.173737 2026] [security2:error] [pid 25919:tid 25919] [client 172.70.248.198:10921] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elenacampo.com"] [uri "/.git/config"] [unique_id "ah6eMg-FYMqcWAWP7TaYUAAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 08:44:35
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 04:44:31.340177 2026] [security2:error] [pid 17846:tid 17921] [client 172.70.248.198:13453] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abundancebible.com"] [uri "/.git/config"] [unique_id "ah6X79bOtqpFbAw9nRBZbgAAAgw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-05-31 22:16:44
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack