๐ง๐ช
madeit
2026-08-22 22:28:45
(2 days ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 00:52:53
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.35.121 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.35.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 20:52:45.784289 2026] [security2:error] [pid 23829:tid 23829] [client 172.70.35.121:13213] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.castlewelding.net"] [uri "/.git/HEAD"] [unique_id "aoOs3dW1Ao3g9nt6dLcixgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 03:14:56
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.35.121 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.35.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 23:14:48.046586 2026] [security2:error] [pid 11126:tid 11126] [client 172.70.35.121:10377] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.cgiaquaticcare.com"] [uri "/.git/config"] [unique_id "aoErKKqE8kOqWtaRcGjnZQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
acadeova
2026-08-16 03:12:18
(1 week ago)
๐จ Recon detected (nft drop)
SRC=172.70.35.121
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journ ...
show more
๐จ Recon detected (nft drop)
SRC=172.70.35.121
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐บ๐ธ
mcarthey
2026-08-16 01:59:21
(1 week ago)
Automated honeypot report from mcarthey.com. 2 hits across 2 bait families (git-config, git-head) in ...
show more
Automated honeypot report from mcarthey.com. 2 hits across 2 bait families (git-config, git-head) in the last 24h. Full log: https://mcarthey.com/Shame
show less
Bad Web Bot
Web App Attack
Anonymous
2026-08-16 00:48:07
(1 week ago)
invalid request
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 20:36:52
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.35.121 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.35.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 16:36:48.195274 2026] [security2:error] [pid 1819994:tid 1819994] [client 172.70.35.121:9252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.belgiophar.net"] [uri "/.git/config"] [unique_id "anuH4Ke2ygGBD2FrT16OEQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-05 14:01:31
(2 weeks ago)
Web App Attack
๐ฆ๐ฑ
router.al
2026-08-04 08:03:49
(3 weeks ago)
08/04/2026-08:03:49.010756 172.70.35.121 Protocol: 6 ET SCAN WordPress Scanner Performing Multiple R ...
show more
08/04/2026-08:03:49.010756 172.70.35.121 Protocol: 6 ET SCAN WordPress Scanner Performing Multiple Requests to Windows Live Writer XML
show less
Hacking
๐ซ๐ท
dynamix
2026-06-15 06:11:40
(2 months ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
COMPLEX
2026-05-27 01:00:30
(2 months ago)
Unsolicited TCP traffic | Action: DROP | Port 443
Phishing
๐บ๐ธ
TPI-Abuse
2026-05-15 12:13:01
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.35.121 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.35.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 08:12:51.883908 2026] [security2:error] [pid 30632:tid 30632] [client 172.70.35.121:10864] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/config/parameters.yml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.virtualmediamasters.wholesalelivelobsters.com"] [uri "/app/config/parameters.yml"] [unique_id "agcNw6Jg-4_cMx-iSEROQwAAABU"], referer: https://www.google.com/search?q=www.virtualmediamasters.wholesalelivelobsters.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-14 08:04:05
(3 months ago)
(caddyscan) Scanner path probe from 172.70.35.121 (US/United States/-): 5 in the last 3600 secs; Por ...
show more
(caddyscan) Scanner path probe from 172.70.35.121 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 172.70.35.121 - - [14/May/2026:07:11:12 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.70.35.121 - - [14/May/2026:07:30:18 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.70.35.121 - - [14/May/2026:07:42:43 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.70.35.121 - - [14/May/2026:07:53:17 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.70.35.121 - - [14/May/2026:08:04:00 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
Anonymous
2026-05-09 23:59:37
(3 months ago)
Web Probe / Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-09 16:51:13
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.35.121 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.35.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 12:51:06.755295 2026] [security2:error] [pid 28616:tid 28616] [client 172.70.35.121:14101] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "americaskitchencoach.com"] [uri "/.git/config"] [unique_id "af9l-tfY97JYg5ih_bcgawAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack