๐บ๐ธ
TPI-Abuse
2026-08-22 13:41:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.119 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 09:41:43.881640 2026] [security2:error] [pid 8745:tid 8802] [client 172.70.38.119:25501] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.siriuspharmaceuticals.com"] [uri "/.env.local"] [unique_id "aomnFyGF7SNsqhrz_M9m1AAAAYc"], referer: https://www.google.com/search?q=siriuspharma.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 13:20:29
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.119 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 09:20:25.728371 2026] [security2:error] [pid 8105:tid 8105] [client 172.70.38.119:9440] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.vittaria.com"] [uri "/.git/config"] [unique_id "aoMKmZKjDTVlXVJuDs2UUAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 09:34:36
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.119 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 05:34:29.559399 2026] [security2:error] [pid 2726:tid 2726] [client 172.70.38.119:9570] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.lyldevelopers.com"] [uri "/.git/HEAD"] [unique_id "aoLVpUj7AHlLIcq42HgaHAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Sรฉfora Srl
2026-08-17 08:00:10
(6 days ago)
Bad user agents ignoring web crawling rules. Draing bandwidth - detected by Fail2Ban in plesk-apache ...
show more
Bad user agents ignoring web crawling rules. Draing bandwidth - detected by Fail2Ban in plesk-apache-badbot jail
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-16 07:20:55
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.119 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 03:20:50.296137 2026] [security2:error] [pid 24059:tid 24059] [client 172.70.38.119:9449] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "spirits66.com"] [uri "/.git/HEAD"] [unique_id "aoFk0q1Qk_mASkkAzAPo6AAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-12 01:29:10
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.119 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 21:29:03.472567 2026] [security2:error] [pid 3252375:tid 3252395] [client 172.70.38.119:10576] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.dontbeajerklikeyourwork.com"] [uri "/.git/config"] [unique_id "anvMXz5JlWU48Ux3RWaeCwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 02:43:39
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.119 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 22:43:35.919014 2026] [security2:error] [pid 731703:tid 731703] [client 172.70.38.119:9562] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.imerse.com"] [uri "/.git/HEAD"] [unique_id "anqMV7LhO-wV9ukPd0LyHwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-08 19:47:29
(2 weeks ago)
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-06-10 04:24:19
(2 months ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-14 22:06:43
(3 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-13.
show less
Web App Attack
SSH
Hacking
๐ฎ๐ฉ
sockominfo
2026-04-06 21:28:46
(4 months ago)
[WAZUH] Access to sensitive configuration files detected.
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 02:38:20
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.119 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 22:38:10.740263 2026] [security2:error] [pid 6865:tid 6865] [client 172.70.38.119:10323] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.solaire-chauffe-eau.info"] [uri "/.env.test"] [unique_id "adMckno9RTmdmXQ4dvRELQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 22:31:00
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.119 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 18:30:52.284221 2026] [security2:error] [pid 22398:tid 22398] [client 172.70.38.119:13915] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.destintoday.com.danged.com"] [uri "/.env.bak"] [unique_id "adGRHNaCldmJ-smOQyZEhAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 17:50:08
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.119 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 13:50:00.933807 2026] [security2:error] [pid 9674:tid 9674] [client 172.70.38.119:13333] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "britanniapilates.com.systemcapacityoptimization.com"] [uri "/.env.production"] [unique_id "adFPSG2GJsi3EbYdSRDqJAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 17:16:44
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.119 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 13:16:38.728248 2026] [security2:error] [pid 451:tid 451] [client 172.70.38.119:11230] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.b9k9.com"] [uri "/.env.backup"] [unique_id "adFHdnRmhqrtWV4AICEHNwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack