๐ง๐ช
madeit
2026-08-29 08:01:55
(3 days ago)
Web App Attack
Anonymous
2026-08-28 13:24:58
(4 days ago)
Aggressive web scan
Web App Attack
๐ง๐ช
madeit
2026-08-21 22:38:41
(1 week ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 08:48:40
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.35.211 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.35.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 04:48:35.671585 2026] [security2:error] [pid 3567:tid 3567] [client 172.70.35.211:9772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.lcssouth.com"] [uri "/.git/HEAD"] [unique_id "aoLK4yqFYBCRR360dbarVgAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 08:31:07
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.35.211 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.35.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 04:31:02.784647 2026] [security2:error] [pid 30929:tid 30929] [client 172.70.35.211:12604] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.genesis-castle.com"] [uri "/.git/HEAD"] [unique_id "aoLGxqVJQbnhBHlYz2tj2wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 02:01:02
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.35.211 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.35.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 22:00:58.726994 2026] [security2:error] [pid 8996:tid 8996] [client 172.70.35.211:14244] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.hyps.com"] [uri "/.git/config"] [unique_id "aoJrWnDFHkllnuLasYeWsgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
chronos
2026-08-13 07:57:42
(2 weeks ago)
2026-08-13 03:26:05 UTC-3||Unauthorized connection attempt detected for port scanning
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-12 04:07:24
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.35.211 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.35.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 00:07:18.187057 2026] [security2:error] [pid 3537265:tid 3537273] [client 172.70.35.211:11534] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.belfastpropertyagency.com"] [uri "/.git/HEAD"] [unique_id "anvxdqv83Ljkdmonw52SAwAAAQQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-10 17:23:14
(3 weeks ago)
Web App Attack
๐บ๐ธ
wimaxnz
2026-06-16 04:39:48
(2 months ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
๐ณ๐ฑ
COMPLEX
2026-05-27 01:00:20
(3 months ago)
Unsolicited TCP traffic | Action: DROP | Port 443
Phishing
๐บ๐ธ
TPI-Abuse
2026-05-15 08:22:04
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.35.211 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.35.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:21:58.815408 2026] [security2:error] [pid 24819:tid 24819] [client 172.70.35.211:11467] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sandboxspeech.org"] [uri "/.env.dev"] [unique_id "agbXprDCanHUJrUcrsUdngAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ณ
ThreatBook.io
2026-04-24 00:36:09
(4 months ago)
2026-04-23 13:28:54 /
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-04-21 22:03:47
(4 months ago)
Auto-ban: >3000 req/min op 2026-04-21
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-04 06:55:09
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.35.211 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.35.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 02:55:03.338474 2026] [security2:error] [pid 20828:tid 20828] [client 172.70.35.211:11944] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.marilynmonroebooks.com"] [uri "/.env.bak"] [unique_id "adC1x-Rt_6a9Pc36aGstVgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack