π§πͺ
madeit
2026-09-29 03:06:23
(23 hours ago)
Web App Attack
π§πͺ
madeit
2026-09-08 10:27:10
(3 weeks ago)
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 11:21:58
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.122 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 07:21:53.389650 2026] [security2:error] [pid 13183:tid 13183] [client 172.70.38.122:9325] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.geauxcowboys.com"] [uri "/.git/config"] [unique_id "aoLu0aPthjioKgCXnajCHQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-14 21:45:09
(1 month ago)
172.70.38.122 - - [14/Aug/2026:21:45:07 +0000] "GET /yj09.php HTTP/2.0" 404 3581 "-" "-" "52.247.110 ...
show more
172.70.38.122 - - [14/Aug/2026:21:45:07 +0000] "GET /yj09.php HTTP/2.0" 404 3581 "-" "-" "52.247.110.175"
172.70.38.122 - - [14/Aug/2026:21:45:07 +0000] "GET /scxy.php HTTP/2.0" 404 3580 "-" "-" "52.247.110.175"
172.70.38.122 - - [14/Aug/2026:21:45:08 +0000] "GET /3PJcpMFsD8B.php HTTP/2.0" 404 3589 "-" "-" "52.247.110.175"
172.70.38.122 - - [14/Aug/2026:21:45:08 +0000] "GET /BDKR28WP.php HTTP/2.0" 404 3587 "-" "-" "52.247.110.175"
172.70.38.122 - - [14/Aug/2026:21:45:08 +0000] "GET /4PJcpMFsD8B.php HTTP/2.0" 404 3589 "-" "-" "52.247.110.175"
172.70.38.122 - - [14/Aug/2026:21:45:08 +0000] "GET /1xmomo.php HTTP/2.0" 404 3581 "-" "-" "52.247.110.175"
172.70.38.122 - - [14/Aug/2026:21:45:08 +0000] "GET /blurbs.php HTTP/2.0" 404 3580 "-" "-" "52.247.110.175"
172.70.38.122 - - [14/Aug/2026:21:45:08 +0000] "GET /bajah.php HTTP/2.0" 404 3580 "-" "-" "52.247.110.175"
172.70.38.122 - - [14/Aug/2026:21:45:08 +0000] "GET /domvf.php HTTP/2.0" 404 3580 "-" "-" "52.247.110.175"
172.70.38.122 - - [14/
...
show less
Port Scan
Brute-Force
πΊπΈ
TPI-Abuse
2026-08-12 02:08:12
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.122 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 22:08:07.696575 2026] [security2:error] [pid 3236196:tid 3236196] [client 172.70.38.122:14115] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.mmipro.com"] [uri "/.git/config"] [unique_id "anvVh19UFG23gP8hjqvVrwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
madeit
2026-08-11 07:44:29
(1 month ago)
Web App Attack
πΊπΈ
wimaxnz
2026-05-16 07:15:37
(4 months ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
πΊπΈ
TPI-Abuse
2026-04-07 08:52:46
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.122 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 04:52:41.506301 2026] [security2:error] [pid 948839:tid 948839] [client 172.70.38.122:11170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.flyinganorak.com"] [uri "/.env.dev"] [unique_id "adTF2Qk56ilAw8gZPjwVUAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-07 00:13:11
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.122 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 20:13:06.109821 2026] [security2:error] [pid 925389:tid 925389] [client 172.70.38.122:10060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hienle.com"] [uri "/.env.development"] [unique_id "adRMErPsrmTHb22uAFjsLAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-04 06:41:32
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.122 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 02:41:26.699161 2026] [security2:error] [pid 27403:tid 27403] [client 172.70.38.122:11107] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.thestillwatergroup.com"] [uri "/srv/.env"] [unique_id "adCylqbJsh8QgbEFO-AV7QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-04 02:49:52
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.122 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 22:49:48.683459 2026] [security2:error] [pid 20924:tid 20924] [client 172.70.38.122:14122] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.clustershow.com"] [uri "/public/.env"] [unique_id "adB8TMftV0HltzRDFMdtXwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-04 02:20:06
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.122 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 22:20:01.083869 2026] [security2:error] [pid 10222:tid 10222] [client 172.70.38.122:12899] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.register-boat-germany.com"] [uri "/var/www/html/.env"] [unique_id "adB1USXQcQZZlrFx6E3HTwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-03 18:36:47
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.122 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 14:36:42.594093 2026] [security2:error] [pid 28818:tid 28818] [client 172.70.38.122:13112] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.intrinsicreef.com"] [uri "/.env.tmp"] [unique_id "adAIutR4D2R2-vVhfl3XTgAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-03 17:19:00
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.122 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 13:18:54.926581 2026] [security2:error] [pid 10877:tid 10877] [client 172.70.38.122:12480] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "daikin.cloudex.link"] [uri "/.env.dev"] [unique_id "ac_2fkKSOVghs-pF44dRSQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-03 16:10:05
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.122 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 12:09:57.034159 2026] [security2:error] [pid 20526:tid 20571] [client 172.70.38.122:9826] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.djkirby.com"] [uri "/.env.save"] [unique_id "ac_mVS10lg6kvBdO7Ow6uwAAAM8"]
show less
Brute-Force
Bad Web Bot
Web App Attack