๐บ๐ธ
Rip
2026-06-14 10:27:55
(23 hours ago)
Restricted File Access Attempts
Port Scan
Web App Attack
๐ฉ๐ช
updown.io
2026-06-07 06:53:49
(1 week ago)
{"level":"info","ts":1780814599.2115297,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1780814599.2115297,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"172.70.248.207","remote_port":"21233","client_ip":"172.70.248.207","proto":"HTTP/1.1","method":"GET","host":"status.clay.earth","uri":"/assets/nuclei.svg?ZZEC6=x","headers":{"Cf-Ray":["a07dae8b29d70f9d-FRA"],"Cdn-Loop":["cloudflare; loops=1"],"Cf-Ipcountry":["US"],"Accept-Encoding":["gzip"],"Connection":["Keep-Alive"],"X-Forwarded-For":["68.183.28.23"],"Cf-Connecting-Ip":["68.183.28.23"],"X-Forwarded-Proto":["http"],"Cf-Visitor":["{\"scheme\":\"http\"}"]}},"bytes_read":0,"user_id":"","duration":0.000039295,"size":0,"status":308,"resp_headers":{"Server":["Caddy"],"Connection":["close"],"Location":["https://status.clay.earth/assets/nuclei.svg?ZZEC6=x"],"Content-Type":[]}}
{"level":"info","ts":1780814607.923862,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"172.70.248.207","remote_port":"16319","client_ip":"172.70.248.207","proto":"HTTP/1
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 22:25:06
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.207 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 18:24:59.867950 2026] [security2:error] [pid 15328:tid 15342] [client 172.70.248.207:9575] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davidchapa.com"] [uri "/.git/config"] [unique_id "ah9YO_4CjKzREAGvLKicHgAAAQw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-06-02 21:45:13
(1 week ago)
172.70.248.207 - - [03/Jun/2026:00:45:12 +0300] "GET /.aws/credentials HTTP/1.1" 301 162 "http://bit ...
show more
172.70.248.207 - - [03/Jun/2026:00:45:12 +0300] "GET /.aws/credentials HTTP/1.1" 301 162 "http://bitwarden.it-systems.org/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 18:10:15
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.207 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 14:10:11.945629 2026] [security2:error] [pid 24473:tid 24473] [client 172.70.248.207:13001] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "washburn-books.com"] [uri "/.git/config"] [unique_id "ah8cg1rX6fhkffkyeisXOwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 14:37:53
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.207 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 10:37:47.099692 2026] [security2:error] [pid 16626:tid 16626] [client 172.70.248.207:9704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marklex.com"] [uri "/.git/config"] [unique_id "ah7qu1BrclaGfgt7HymMqAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 13:39:55
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.207 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 09:39:48.607446 2026] [security2:error] [pid 24022:tid 24038] [client 172.70.248.207:12438] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "landmarkocchealth.com"] [uri "/.git/config"] [unique_id "ah7dJNW_2x1uQ7CKycb5hQAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 08:55:17
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.207 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 04:55:10.364944 2026] [security2:error] [pid 28269:tid 28269] [client 172.70.248.207:10447] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "123clearmyticket.com"] [uri "/.git/config"] [unique_id "ah6abr_aEkkrL_CA_GI1VAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 08:08:30
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.207 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 04:08:25.568977 2026] [security2:error] [pid 18521:tid 18521] [client 172.70.248.207:10936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "carpascarpe.com"] [uri "/.git/config"] [unique_id "ah6PeQenFr9Y8ta6tOgZlgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 06:21:31
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.207 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 02:21:25.374563 2026] [security2:error] [pid 14513:tid 14513] [client 172.70.248.207:11946] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whitmarshinc.com"] [uri "/.git/config"] [unique_id "ah52ZZKtRgZfIFD6Jogf6AAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-25 04:40:25
(3 weeks ago)
[Mon May 25 06:40:24.182838 2026] [authz_core:error] [pid 7818] [client 172.70.248.207:9416] AH01630 ...
show more
[Mon May 25 06:40:24.182838 2026] [authz_core:error] [pid 7818] [client 172.70.248.207:9416] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon May 25 06:40:24.245081 2026] [authz_core:error] [pid 7818] [client 172.70.248.207:9416] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon May 25 06:40:24.362008 2026] [authz_core:error] [pid 7818] [client 172.70.248.207:9416] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐ท๐บ
DZBOT
2026-05-19 22:10:52
(3 weeks ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฆ๐บ
trentwiles.com
2026-05-18 15:07:32
(3 weeks ago)
Unauthorized connection attempt detected from IP address 172.70.248.207 to port 443 [SYD]
Port Scan
๐ฆ๐บ
trentwiles.com
2026-05-11 06:55:10
(1 month ago)
Unauthorized connection attempt detected from IP address 172.70.248.207 to port 80 [SYD]
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-09 02:27:38
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.207 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 22:27:33.328802 2026] [security2:error] [pid 8157:tid 8157] [client 172.70.248.207:12158] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "uppermotradingco.com"] [uri "/.git/config"] [unique_id "af6blQBSjFk49KfTMpx2SgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack