Anonymous
2026-06-15 22:59:07
(20 hours ago)
[Tue Jun 16 00:59:05.508313 2026] [authz_core:error] [pid 3151] [client 172.70.35.67:11419] AH01630: ...
show more
[Tue Jun 16 00:59:05.508313 2026] [authz_core:error] [pid 3151] [client 172.70.35.67:11419] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Jun 16 00:59:05.829876 2026] [authz_core:error] [pid 3151] [client 172.70.35.67:11419] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Jun 16 00:59:06.047997 2026] [authz_core:error] [pid 3151] [client 172.70.35.67:11419] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐บ๐ธ
mawan
2026-06-15 09:48:34
(1 day ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
mawan
2026-06-13 15:24:12
(3 days ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
Anonymous
2026-06-08 08:00:53
(1 week ago)
[Mon Jun 08 10:00:51.977529 2026] [authz_core:error] [pid 19669] [client 172.70.35.67:12665] AH01630 ...
show more
[Mon Jun 08 10:00:51.977529 2026] [authz_core:error] [pid 19669] [client 172.70.35.67:12665] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon Jun 08 10:00:52.437051 2026] [authz_core:error] [pid 19669] [client 172.70.35.67:12665] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon Jun 08 10:00:52.651833 2026] [authz_core:error] [pid 19669] [client 172.70.35.67:12665] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐บ๐ธ
mawan
2026-05-26 13:47:59
(3 weeks ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 08:12:55
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 172.70.35.67 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.35.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:11:08.654626 2026] [security2:error] [pid 4392:tid 4392] [client 172.70.35.67:11626] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.aurumcraft.com.38floorsupply.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.aurumcraft.com.38floorsupply.com"] [uri "/db_backup.sql"] [unique_id "agbVHOlaDhSrCUF5v-85fAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
masterguru
2026-05-14 18:43:20
(1 month ago)
BAD BOT - Detected and Blocked.. Matched phrase "baidu" at REQUEST_HEADERS:User-Agent. (1100000-166)
Bad Web Bot
Anonymous
2026-05-14 07:52:43
(1 month ago)
(caddyscan) Scanner path probe from 172.70.35.67 (US/United States/-): 5 in the last 3600 secs; Port ...
show more
(caddyscan) Scanner path probe from 172.70.35.67 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 172.70.35.67 - - [14/May/2026:07:19:13 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.70.35.67 - - [14/May/2026:07:19:19 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.70.35.67 - - [14/May/2026:07:41:21 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.70.35.67 - - [14/May/2026:07:46:02 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.70.35.67 - - [14/May/2026:07:52:42 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
๐ฎ๐ฉ
RasyiidWho
2026-04-30 20:20:29
(1 month ago)
ip112.20 . 172.70.35.67 - - [01/May/2026:03:20:28 +0700] "GET /wp-login.php HTTP/2.0" 404 146 "-" "B ...
show more
ip112.20 . 172.70.35.67 - - [01/May/2026:03:20:28 +0700] "GET /wp-login.php HTTP/2.0" 404 146 "-" "BlackVeil-Security-Scanner/5.1.0 (https://blackveilsecurity.com; [email protected] )"
...
show less
DDoS Attack
Brute-Force
Port Scan
Bad Web Bot
Web App Attack
SSH
๐บ๐ธ
mnsf
2026-04-05 19:05:17
(2 months ago)
Scanning/Probing (14)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 02:07:34
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.35.67 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.35.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 22:07:29.099495 2026] [security2:error] [pid 6451:tid 6451] [client 172.70.35.67:12183] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.beetreelabs.com"] [uri "/.env.production.bak"] [unique_id "ac8g4W_JJNwSlVXn9orD6wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 07:44:45
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.35.67 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.35.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 03:44:41.260925 2026] [security2:error] [pid 2615:tid 2615] [client 172.70.35.67:12300] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "museum.henning.org"] [uri "/.env.development.local"] [unique_id "act7aVLsvTXW56MjQHLFUQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 04:50:27
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.35.67 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.35.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 00:50:20.431923 2026] [security2:error] [pid 32007:tid 32007] [client 172.70.35.67:12512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.thesilverlegion.org"] [uri "/.env.development.local"] [unique_id "actSjKaN7ZLYG7YB2fMYJAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 03:00:30
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.35.67 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.35.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 23:00:23.666989 2026] [security2:error] [pid 1781:tid 1781] [client 172.70.35.67:11444] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.fetchamreadingroom.org"] [uri "/api/.env"] [unique_id "acs4xxQSLu6U5hKD5OeQZgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-30 18:31:51
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.35.67 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.35.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 14:31:45.933644 2026] [security2:error] [pid 15697:tid 15697] [client 172.70.35.67:13234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.everpickon.com"] [uri "/.env.save"] [unique_id "acrBkfmDPshyky2nmaGBRQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack