๐บ๐ธ
WellSpring
2026-05-15 22:01:32
(2 months ago)
wordpress scan on 229.today/wp-admin/install.php โ WellSpr.ing/NetSentinel civic-AI security layer
Bad Web Bot
Web App Attack
๐ฉ๐ช
acadeova
2026-05-06 18:35:25
(2 months ago)
๐จ Recon detected (nft drop)
SRC=172.70.251.160
Observed=TCP dpt=2087 in=enp0s6 ttl=59
Time=recent(jo ...
show more
๐จ Recon detected (nft drop)
SRC=172.70.251.160
Observed=TCP dpt=2087 in=enp0s6 ttl=59
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐ฉ๐ช
Zydzy
2026-05-02 18:03:33
(2 months ago)
Automated attack detected. Server: 95.140.154.181. Jail: nginx-exploit.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-30 09:14:33
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.251.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.251.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 05:14:08.826218 2026] [security2:error] [pid 5409:tid 5409] [client 172.70.251.160:12291] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.title50.com"] [uri "/.git/config"] [unique_id "afMdYCamLSrd8r7prM2B5AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-29 17:13:34
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.251.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.251.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 29 13:13:27.411580 2026] [security2:error] [pid 21405:tid 21405] [client 172.70.251.160:12437] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.celiaconaway.com"] [uri "/.git/config"] [unique_id "afI8Nwc4PW2_YzFmLt6CsgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-08 04:14:50
(3 months ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 12:14:15
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.251.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.251.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 08:14:10.933690 2026] [security2:error] [pid 1454762:tid 1454762] [client 172.70.251.160:11080] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.dawnmazur.com"] [uri "/.git/refs/heads/master"] [unique_id "adT1Ehl8sLg_XQlUxM40GAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 07:39:40
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.251.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.251.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 03:39:34.301403 2026] [security2:error] [pid 852382:tid 852382] [client 172.70.251.160:10188] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.dreamingofatlantis.com"] [uri "/.git/logs/HEAD"] [unique_id "adS0tmsUD8yVIvdjD9klngAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-04-05 03:05:43
(3 months ago)
Scanning/Probing (17)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 17:28:13
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.251.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.251.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 13:28:06.903119 2026] [security2:error] [pid 6325:tid 6325] [client 172.70.251.160:10393] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.bridalshowerinvitationsonline.com"] [uri "/.git/logs/HEAD"] [unique_id "adFKJsR3jXkBmmJu_cj_eAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 07:14:34
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.251.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.251.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 03:14:21.158762 2026] [security2:error] [pid 16342:tid 16342] [client 172.70.251.160:11122] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.tigerpathteam.org"] [uri "/.git/logs/HEAD"] [unique_id "adC6TTsKGg9MlzA5Az6GHgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-04-01 10:05:31
(3 months ago)
Scanning/Probing (26)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-03-31 09:06:37
(3 months ago)
Scanning/Probing (56)
Brute-Force
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-03-31 00:40:00
(3 months ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/-
Web App Attack
๐ซ๐ฎ
Jordy
2026-03-30 15:09:28
(3 months ago)
30/Mar/2026:17:04:13.544700 +0200Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
30/Mar/2026:17:04:13.544700 +0200Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 172.70.251.160] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/refs/heads/main"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "jordymarije.nl"] [uri "/.git/refs/heads/main"] [unique_id "acqQ7SI8lQqkKqmn654NMQAAAA0"]
30/Mar/2026:17:04:13.544700 +0200Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 172.70.251.160] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUES
...
show less
Web App Attack