π§πͺ
madeit
2026-09-08 10:26:20
(3 hours ago)
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 23:11:57
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.143 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 19:11:53.187210 2026] [security2:error] [pid 29106:tid 29106] [client 172.70.38.143:13839] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.cvoguemag.com"] [uri "/.git/config"] [unique_id "aoOVOcJ5d16r1Qq0TELWbwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 08:53:01
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.143 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 04:52:56.884611 2026] [security2:error] [pid 13371:tid 13371] [client 172.70.38.143:12128] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.f4fbbs.com"] [uri "/.git/config"] [unique_id "aoLL6B75qc5EVegvAOtWVwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 06:04:20
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.143 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 02:04:12.888530 2026] [security2:error] [pid 13574:tid 13574] [client 172.70.38.143:12616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.sewacheckbookcover.com"] [uri "/.git/HEAD"] [unique_id "aoKkXKN831CF0Kf9eqLh-gAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 04:50:03
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.143 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 00:49:57.969647 2026] [security2:error] [pid 29235:tid 29240] [client 172.70.38.143:12310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.upperwilds.com"] [uri "/.git/config"] [unique_id "aoKS9cwEy-CzjmaJwfHRtQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
madeit
2026-08-15 18:33:54
(3 weeks ago)
Web App Attack
π§πͺ
madeit
2026-08-08 10:07:43
(1 month ago)
Web App Attack
π²π½
octageeks.com
2026-07-29 04:18:40
(1 month ago)
Wordpress malicious attack:[octawpauthor]
Web App Attack
πΊπΈ
mawan
2026-07-11 12:55:13
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
Anonymous
2026-06-13 07:44:57
(2 months ago)
LH-Watcher: FAKE_ID [Fake facebook.com/externalhit]
Bad Web Bot
π¬π§
sandra361
2026-05-26 17:53:05
(3 months ago)
Port scan detected: 10 attempts across 1 ports (443). | Evidence: REAPER_TARPIT:IN=enp1s0f0 OUT= SRC ...
show more
Port scan detected: 10 attempts across 1 ports (443). | Evidence: REAPER_TARPIT:IN=enp1s0f0 OUT= SRC=172.70.38.143 LEN=60 TOS=0x00 PREC=0x00 TTL=55 ID=6874 DF PROTO=TCP SPT=11935 DPT=443 WINDOW=65535 RES=0x00 SYN URGP=0
show less
Port Scan
π¦πΊ
oncord
2026-04-17 07:12:04
(4 months ago)
Form spam
Web Spam
πΊπΈ
TPI-Abuse
2026-04-07 09:19:39
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.143 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 05:19:34.970818 2026] [security2:error] [pid 924470:tid 924470] [client 172.70.38.143:9494] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.boat-registration-italy.com"] [uri "/.env2"] [unique_id "adTMJh-6qknOq9NuFVuQAgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-07 06:04:26
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.143 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 02:04:21.056328 2026] [security2:error] [pid 738276:tid 738276] [client 172.70.38.143:9350] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "consultnv.com"] [uri "/app/.env"] [unique_id "adSeZdyk7hF2qxYd-a5BDgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-06 17:54:09
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.143 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 13:53:59.578743 2026] [security2:error] [pid 239979:tid 239979] [client 172.70.38.143:12371] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.alarmnummer.com"] [uri "/.env"] [unique_id "adPzN_NuQ3C1oEe0Jj8eOAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack