πΊπΈ
TPI-Abuse
2026-06-11 05:53:34
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.70.250.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.250.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 01:53:28.173649 2026] [security2:error] [pid 19601:tid 19846] [client 172.70.250.10:13359] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "heatlhydatasystems.com"] [uri "/.git/config"] [unique_id "aipNWOe8hyVVIYp0dcH3qAAAAUU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-06-06 07:58:13
(5 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-29 12:37:17
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.250.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.250.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 29 08:37:11.491858 2026] [security2:error] [pid 25837:tid 25837] [client 172.70.250.10:11987] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.amgtr.com"] [uri "/.git/config"] [unique_id "afH7d6_C2NPW4Tj7stqLVQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
e.fierstra
2026-04-07 00:28:04
(2 months ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-04-05 18:12:32
(2 months ago)
[Sun Apr 05 20:12:16.594806 2026] [authz_core:error] [pid 29333] [client 172.70.250.10:12943] AH0163 ...
show more
[Sun Apr 05 20:12:16.594806 2026] [authz_core:error] [pid 29333] [client 172.70.250.10:12943] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sun Apr 05 20:12:32.186053 2026] [authz_core:error] [pid 28868] [client 172.70.250.10:13441] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sun Apr 05 20:12:32.412184 2026] [authz_core:error] [pid 28868] [client 172.70.250.10:13441] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
π©πͺ
XICTRON
2026-04-04 15:30:05
(2 months ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
π©πͺ
Hazzard
2026-04-04 08:11:13
(2 months ago)
(apache-empty-ua) Failed empty apache-ua trigger with match [redacted]): (CF_ENABLE)
Hacking
πΊπΈ
TPI-Abuse
2026-04-03 22:09:59
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.250.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.250.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 18:09:31.329289 2026] [security2:error] [pid 15397:tid 15397] [client 172.70.250.10:13951] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.oceandrivebeach.net"] [uri "/.env.tmp"] [unique_id "adA6m1_SNrDnW_k6QdNigAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-03 21:12:55
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.250.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.250.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 17:12:47.659751 2026] [security2:error] [pid 20526:tid 20563] [client 172.70.250.10:10307] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.atlasrecordssearch.com"] [uri "/.git/index"] [unique_id "adAtTy10lg6kvBdO7OxNpAAAAMc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
updown.io
2026-04-02 20:30:22
(2 months ago)
{"level":"info","ts":1775161820.707534,"logger":"http.log.access.log1","msg":"handled request","requ ...
show more
{"level":"info","ts":1775161820.707534,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"172.70.250.10","remote_port":"10134","client_ip":"172.70.250.10","proto":"HTTP/1.1","method":"GET","host":"status.dreamsis.com","uri":"/wp-includes/Text/Diff/Renderer/","headers":{"Cdn-Loop":["cloudflare; loops=1"],"Sec-Fetch-Dest":["document"],"Sec-Fetch-Site":["none"],"Cf-Ray":["9e6297428d75d4f3-FRA"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"],"Cf-Visitor":["{\"scheme\":\"https\"}"],"Connection":["Keep-Alive"],"Sec-Ch-Ua-Platform":["\"Windows\""],"Cf-Ipcountry":["JP"],"Accept-Language":["en-US, en; q=0.9"],"Dnt":["1"],"Cf-Connecting-Ip":["52.243.57.116"],"Sec-Fetch-Mode":["navigate"],"Accept-Encoding":["gzip, br"],"Sec-Ch-Ua":["\"Not_A Brand\";v=\"8\", \"Chromium\";v=\"120\", \"Google Chrome\";v=\"120\""],"Sec-Fetch-User":["?1"],"X-Forwarded-For":["52.243.57.116"],"Upgrade-Insecure-
...
show less
DDoS Attack
Web App Attack
π«π·
masterguru
2026-04-01 20:10:44
(2 months ago)
Blocked Cloudflare Worker request. Pattern match "." at REQUEST_HEADERS:cf-worker. (5025-195)
Hacking
πΊπΈ
mnsf
2026-04-01 18:06:30
(2 months ago)
Scanning/Probing (21)
Brute-Force
Web App Attack
πΊπΈ
mnsf
2026-03-31 08:06:39
(2 months ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
π³π±
debestelapp
2026-03-31 05:25:05
(2 months ago)
Web App Attack
π¬π§
openstrike.co.uk
2026-03-31 05:14:27
(2 months ago)
18 attacks on env grabbing URLs, PHP URLs:
GET /.env.local.backup HTTP/1.1
GET /.env.php HTTP/1.1
Hacking
Web App Attack