๐ท๐บ
DZBOT
2026-05-22 12:59:20
(3 months ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-05-13 21:04:58
(4 months ago)
Try to access /.git/config
Web App Attack
๐ฉ๐ช
acadeova
2026-05-08 07:47:40
(4 months ago)
๐จ Recon detected (nft drop)
SRC=172.70.251.202
Observed=TCP dpt=80 in=enp0s6 ttl=59
Time=recent(jour ...
show more
๐จ Recon detected (nft drop)
SRC=172.70.251.202
Observed=TCP dpt=80 in=enp0s6 ttl=59
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-03 20:41:47
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.251.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.251.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 03 16:41:40.505327 2026] [security2:error] [pid 1171:tid 1171] [client 172.70.251.202:10450] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "butterflymornings.com"] [uri "/.git/config"] [unique_id "afezBMF68RfQMnCqW_8PJgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-09 03:57:51
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.251.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.251.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 23:57:47.869722 2026] [security2:error] [pid 3267338:tid 3267338] [client 172.70.251.202:11558] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.itimetable21.com"] [uri "/.git/HEAD"] [unique_id "adcjuwA2t8X2mwhTRclyAgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 11:42:40
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.251.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.251.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 07:42:36.277722 2026] [security2:error] [pid 2099030:tid 2099030] [client 172.70.251.202:10626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.kenirving.com"] [uri "/.git/refs/heads/main"] [unique_id "adTtrAlbAOMnuZPlQX9i7QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-04-07 10:30:20
(5 months ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 15:01:35
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.251.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.251.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 11:01:28.709864 2026] [security2:error] [pid 242317:tid 242317] [client 172.70.251.202:12652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.arts4health.org"] [uri "/.git/config"] [unique_id "adPKyFNutWDpWqZdZdXxawAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-04-05 01:51:58
(5 months ago)
Blocking for trying to access an exploit file: /admin/.env
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-04 23:05:34
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.251.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.251.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 19:05:28.547359 2026] [security2:error] [pid 29620:tid 29620] [client 172.70.251.202:12395] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.godcanuseyou.com"] [uri "/.git/config"] [unique_id "adGZOIZ9Jpx_46QOfC9TIAAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 19:01:24
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.251.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.251.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 15:01:18.146096 2026] [security2:error] [pid 7675:tid 7675] [client 172.70.251.202:12492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sunapeeautomation.com"] [uri "/.git/logs/HEAD"] [unique_id "adFf_gjugbGIOgHTKPU1pwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 16:09:33
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.251.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.251.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 12:09:19.581813 2026] [security2:error] [pid 25354:tid 25354] [client 172.70.251.202:11460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.wilhelminas.biz"] [uri "/.env"] [unique_id "adE3r-3TWt3ppYUuYp4c8gAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
paulo.apoloni
2026-04-04 11:10:50
(5 months ago)
172.70.251.202 - - [04/Apr/2026:08:10:49 -0300] "GET /.git/config HTTP/1.1" 404 118 "-" "-"
172.70.2 ...
show more
172.70.251.202 - - [04/Apr/2026:08:10:49 -0300] "GET /.git/config HTTP/1.1" 404 118 "-" "-"
172.70.251.202 - - [04/Apr/2026:08:10:49 -0300] "GET /.git/index HTTP/1.1" 404 118 "-" "-"
172.70.251.202 - - [04/Apr/2026:08:10:50 -0300] "GET /.env.local HTTP/1.1" 404 118 "-" "-"
172.70.251.202 - - [04/Apr/2026:08:10:50 -0300] "GET /.env.production HTTP/1.1" 404 118 "-" "-"
172.70.251.202 - - [04/Apr/2026:08:10:50 -0300] "GET /.env.backup HTTP/1.1" 404 118 "-" "-"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 20:22:10
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.251.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.251.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 16:22:02.212291 2026] [security2:error] [pid 30861:tid 30861] [client 172.70.251.202:10135] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.menafert.menagri.com"] [uri "/.env"] [unique_id "adAhaowHHYBJ7O8qdgakogAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 06:36:00
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.251.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.251.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 02:35:53.832861 2026] [security2:error] [pid 32610:tid 32610] [client 172.70.251.202:14208] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shhcenter.com"] [uri "/.env~"] [unique_id "ac9fyVQUQqUma3CXH4lbuQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack