๐บ๐ธ
WellSpring
2026-05-23 19:21:31
(2 months ago)
wordpress scan on 229.today/wp-admin/install.php โ WellSpr.ing/NetSentinel civic-AI security layer
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-05-15 06:48:02
(2 months ago)
block ruleset bad bot: misc bad content F608233CC4C86EE814CE8DDDA9C4A0D3C79882F6
Bad Web Bot
๐ฉ๐ช
acadeova
2026-05-06 18:35:39
(2 months ago)
๐จ Recon detected (nft drop)
SRC=172.70.251.159
Observed=TCP dpt=2087 in=enp0s6 ttl=59
Time=recent(jo ...
show more
๐จ Recon detected (nft drop)
SRC=172.70.251.159
Observed=TCP dpt=2087 in=enp0s6 ttl=59
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐ฉ๐ช
Zydzy
2026-05-02 11:59:44
(2 months ago)
Automated attack detected. Server: 95.140.154.181. Jail: nginx-exploit.
Web App Attack
Anonymous
2026-04-08 16:15:10
(3 months ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 12:14:15
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.251.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.251.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 08:14:10.933610 2026] [security2:error] [pid 1456401:tid 1456401] [client 172.70.251.159:9952] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.dawnmazur.com"] [uri "/.git/index"] [unique_id "adT1EgoD_ZtaS7CjhBjt4AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 07:39:41
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.251.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.251.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 03:39:34.300967 2026] [security2:error] [pid 854004:tid 854004] [client 172.70.251.159:13227] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.dreamingofatlantis.com"] [uri "/.git/config"] [unique_id "adS0tkC4T9POkHvIH-RM1AAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-04-05 03:05:43
(3 months ago)
Scanning/Probing (44)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 17:28:12
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.251.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.251.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 13:28:06.720623 2026] [security2:error] [pid 7493:tid 7493] [client 172.70.251.159:14162] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.bridalshowerinvitationsonline.com"] [uri "/.git/HEAD"] [unique_id "adFKJj7BNcLQE1UKoeqakAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 07:14:35
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.251.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.251.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 03:14:21.156942 2026] [security2:error] [pid 22968:tid 22968] [client 172.70.251.159:10608] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.tigerpathteam.org"] [uri "/.git/refs/heads/master"] [unique_id "adC6TTDraJz-uChuV3inOgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-04-01 10:05:31
(3 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-03-31 09:06:37
(3 months ago)
Scanning/Probing (17)
Brute-Force
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-03-31 00:39:11
(3 months ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/-
Web App Attack
๐ซ๐ฎ
Jordy
2026-03-30 15:09:28
(3 months ago)
30/Mar/2026:17:04:13.547240 +0200Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
30/Mar/2026:17:04:13.547240 +0200Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 172.70.251.159] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/index"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "jordymarije.nl"] [uri "/.git/index"] [unique_id "acqQ7RZIslh-rXJ_ks3ZzgAAAAk"]
30/Mar/2026:17:04:13.547240 +0200Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 172.70.251.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALU
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-30 07:12:57
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.251.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.251.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 03:12:50.855139 2026] [security2:error] [pid 21773:tid 21773] [client 172.70.251.159:14323] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.emsahara.org"] [uri "/.env.old/"] [unique_id "acoicsyV2Nr3XseTF9XjqAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack