๐บ๐ธ
TPI-Abuse
2026-05-03 04:48:48
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.251.162 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.251.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 03 00:48:41.225273 2026] [security2:error] [pid 5390:tid 5394] [client 172.70.251.162:14075] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "8mm-stockfootage.com"] [uri "/.git/config"] [unique_id "afbTqSiORLGMg7XYZiln9gAAAQI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Thaliruth
2026-04-07 13:15:33
(3 months ago)
[Tue Apr 07 15:15:31.999688 2026] [authz_core:error] [pid 3633158:tid 137548793894592] [client 172.7 ...
show more
[Tue Apr 07 15:15:31.999688 2026] [authz_core:error] [pid 3633158:tid 137548793894592] [client 172.70.251.162:0] AH01630: client denied by server configuration: /var/www/vhosts/reiter-von-rohan.com/httpdocs/docker-compose.env
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-04-07 11:15:42
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.251.162 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.251.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 07:15:37.537709 2026] [security2:error] [pid 1025467:tid 1025467] [client 172.70.251.162:11156] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.haroparke.com"] [uri "/.git/refs/heads/main"] [unique_id "adTnWTruxIlXo2X6e2wa_QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 01:21:56
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.251.162 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.251.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 21:21:49.256394 2026] [security2:error] [pid 24368:tid 24368] [client 172.70.251.162:10118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.agreyhawkcampaign.net"] [uri "/.git/logs/HEAD"] [unique_id "adMKrcgJTxyLQNjAN-DXrgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-05 10:09:48
(3 months ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 05:27:01
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.251.162 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.251.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 01:26:53.247211 2026] [security2:error] [pid 20991:tid 20991] [client 172.70.251.162:12217] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.cubicearth.com"] [uri "/.env.dev"] [unique_id "adChHf1lwj0BqFS9Yms8SwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Petros Stefanakis
2026-04-03 15:14:47
(3 months ago)
(mod_security) mod_security triggered on hostname [redacted] 172.70.251.162 (DE/Germany/-)
SQL Injection
๐บ๐ธ
mnsf
2026-04-02 21:05:41
(3 months ago)
Scanning/Probing (29)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-02 16:47:07
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.251.162 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.251.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 12:47:03.078550 2026] [security2:error] [pid 21166:tid 21166] [client 172.70.251.162:11912] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "myatherapy.abecasis.com"] [uri "/.git/HEAD"] [unique_id "ac6dh79m_x0mb3Oe0HzobQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Tripwire
2026-04-02 12:44:36
(3 months ago)
Scanning for exploits - /.env.test
Web App Attack
๐บ๐ธ
mnsf
2026-04-01 09:05:51
(3 months ago)
Scanning/Probing (14)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 13:13:05
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.251.162 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.251.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 09:12:58.651809 2026] [security2:error] [pid 1921:tid 1921] [client 172.70.251.162:13047] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.captpalpreschool.com"] [uri "/.env.production"] [unique_id "acvIWu7xvJjg1xfXoe-8TgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 06:34:31
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.251.162 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.251.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 02:34:19.845793 2026] [security2:error] [pid 14940:tid 14940] [client 172.70.251.162:12546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.jordanware.com"] [uri "/.git/logs/HEAD"] [unique_id "actq6xCPQB_RMvIvJ0fUUQAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-30 15:10:47
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.251.162 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.251.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 11:10:42.419569 2026] [security2:error] [pid 30767:tid 30767] [client 172.70.251.162:11392] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.kochcreative.com"] [uri "/.git/config"] [unique_id "acqScjLchdoECIDdXuuh8wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
Jordy
2026-03-30 15:09:34
(3 months ago)
30/Mar/2026:17:04:14.194417 +0200Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
30/Mar/2026:17:04:14.194417 +0200Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 172.70.251.162] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "jordymarije.nl"] [uri "/api/.env"] [unique_id "acqQ7kz8K2a21Pj-aGt9qgAAAAY"]
30/Mar/2026:17:04:14.194417 +0200Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 172.70.251.162] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.
...
show less
Web App Attack