๐บ๐ธ
TPI-Abuse
2026-06-07 06:56:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 02:56:44.825527 2026] [security2:error] [pid 16958:tid 16975] [client 172.70.248.20:12013] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "spiritualwealthmanagement.aafm.us"] [uri "/.git/config"] [unique_id "aiUWLPvsRyIwIRZkemNSkwAAAM8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 18:26:06
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 14:26:03.324225 2026] [security2:error] [pid 28764:tid 28764] [client 172.70.248.20:14174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "csm-dtc.com"] [uri "/.git/config"] [unique_id "aiMUu1oFKY95biQgnCdnxAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 11:57:01
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 07:56:53.309601 2026] [security2:error] [pid 14817:tid 14817] [client 172.70.248.20:13423] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fromthecellarnyc.com"] [uri "/.git/config"] [unique_id "ah7FBbsiknq07EbavB-2QAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
ALPHANET
2026-06-02 11:52:57
(5 days ago)
web exploits
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
mnsf
2026-06-02 04:05:52
(6 days ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-30 06:51:48
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 172.70.248.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.248.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 02:51:41.441757 2026] [security2:error] [pid 23384:tid 23384] [client 172.70.248.20:10397] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.lunginjurylaw.com.helpkccare.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.lunginjurylaw.com.helpkccare.org"] [uri "/backup.sql"] [unique_id "ahqI_dJvm2KasgNcT2zA4gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-29 22:06:35
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-28.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
WellSpring
2026-05-26 18:57:00
(1 week ago)
wordpress scan on 863.today/wp-admin/install.php โ WellSpr.ing/NetSentinel civic-AI security layer
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-22 07:04:28
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 03:04:22.924632 2026] [security2:error] [pid 3517:tid 3517] [client 172.70.248.20:10929] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "formationone.com.kooroshvaziri.com"] [uri "/.git/config"] [unique_id "ag__9jmb1CsEWxK_Vuvy5QAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
citylights13
2026-05-12 19:45:37
(3 weeks ago)
Web scanning/vulnerability probing on core: systematic 4xx responses probing for .env, credentials, ...
show more
Web scanning/vulnerability probing on core: systematic 4xx responses probing for .env, credentials, phpinfo etc (automated report via fail2ban)
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 10:20:11
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 06:20:08.308443 2026] [security2:error] [pid 10378:tid 10459] [client 172.70.248.20:14269] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "garyjahrig.com"] [uri "/.git/config"] [unique_id "af242NeP4Ll9afLDgrtBHAAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
ALPHANET
2026-05-03 08:00:48
(1 month ago)
web exploits
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-29 12:55:14
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 29 08:55:07.167957 2026] [security2:error] [pid 14980:tid 14980] [client 172.70.248.20:12643] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.anneoday.com"] [uri "/.git/config"] [unique_id "afH_q2YTZzFnAhyWoaL-DAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-28 11:22:10
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 07:22:05.814486 2026] [security2:error] [pid 13457:tid 13457] [client 172.70.248.20:9874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theastoria.com"] [uri "/.git/config"] [unique_id "afCYXeoQFvS0aepqRxMdfQAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-26 11:11:52
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 07:11:49.573441 2026] [security2:error] [pid 14660:tid 14660] [client 172.70.248.20:13735] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "myriadpubs.com"] [uri "/.git/config"] [unique_id "ae3y9Wlw6k0ayEXrlTC8KQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack