๐ง๐ช
madeit
2026-09-08 10:26:21
(3 hours ago)
Web App Attack
Anonymous
2026-09-02 17:10:06
(5 days ago)
Failed Wordpress Logins
Web App Attack
๐ง๐ช
madeit
2026-08-18 03:00:12
(3 weeks ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 11:37:47
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 07:37:37.328263 2026] [security2:error] [pid 23514:tid 23514] [client 172.70.38.131:9316] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thepercussionworks.com"] [uri "/.git/config"] [unique_id "aoLygdN-YfHCdKGvkrdfUgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 09:23:50
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 05:23:42.916220 2026] [security2:error] [pid 10536:tid 10536] [client 172.70.38.131:10831] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.girardonline.net"] [uri "/.git/config"] [unique_id "aoLTHvgd2Wr8qF1CpPAM4QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 05:41:40
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 01:41:33.166131 2026] [security2:error] [pid 11787:tid 11787] [client 172.70.38.131:13348] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "refinery.ic1.biz"] [uri "/.git/HEAD"] [unique_id "aoKfDUXaddUYS8lOb-pSzAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 04:45:57
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 00:45:53.051151 2026] [security2:error] [pid 22181:tid 22181] [client 172.70.38.131:10821] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.lo-family.org"] [uri "/.git/config"] [unique_id "aoKSAV9RBk5XS6d8JTK2QAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 01:34:23
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 21:34:17.898092 2026] [security2:error] [pid 7838:tid 7838] [client 172.70.38.131:10577] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.meghanmack.name"] [uri "/.git/HEAD"] [unique_id "aoETmWDCcsYltPFTqSS7cwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-02 14:25:57
(1 month ago)
Failed Wordpress Logins
Web App Attack
Anonymous
2026-07-20 17:14:12
(1 month ago)
Failed Wordpress Logins
Web App Attack
Anonymous
2026-07-19 00:24:37
(1 month ago)
Aggressive web scan
Web App Attack
๐ฌ๐ง
pinguin
2026-06-15 10:59:59
(2 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (POST method) ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (POST method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
acadeova
2026-04-11 18:17:08
(4 months ago)
๐จ Recon detected (nft drop)
SRC=172.70.38.131
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journ ...
show more
๐จ Recon detected (nft drop)
SRC=172.70.38.131
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-04-06 02:25:34
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 22:25:30.540186 2026] [security2:error] [pid 3764:tid 3789] [client 172.70.38.131:13735] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.tmsx2.com"] [uri "/.env.old"] [unique_id "adMZmoEwjmOcESD4DQR89QAAANU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 21:42:24
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 17:42:18.750550 2026] [security2:error] [pid 790:tid 790] [client 172.70.38.131:13595] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sushamalka.royal-barbershop.com"] [uri "/root/.env"] [unique_id "adGFuvfblDM9r5ZHbfevCgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack