๐ต๐ฐ
sbk97 (https://sayor.net)
2026-10-04 07:42:32
(1 week ago)
SAYOR honeypot: observed attack /components/ovaxqhsbg.php
Brute-Force
๐ฒ๐ฝ
octageeks.com
2026-10-03 04:17:00
(1 week ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐ง๐ช
madeit
2026-09-20 12:42:52
(2 weeks ago)
Web App Attack
๐ง๐ช
madeit
2026-08-18 22:05:46
(1 month ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 03:43:16
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.157 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 23:43:06.605107 2026] [security2:error] [pid 24584:tid 24669] [client 172.70.38.157:9594] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.peimbert.com"] [uri "/.git/HEAD"] [unique_id "aoPUymnNd59vlRxgQTuTGwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 12:08:37
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.157 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 08:08:31.390626 2026] [security2:error] [pid 31994:tid 31994] [client 172.70.38.157:10372] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.golflavahotsprings.com"] [uri "/.git/config"] [unique_id "aoL5v0fu2jcr1N6MA4xzdwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 08:04:15
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.157 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 04:04:11.873720 2026] [security2:error] [pid 17642:tid 17642] [client 172.70.38.157:11154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tiln.org"] [uri "/.git/HEAD"] [unique_id "aoFu-3q_b2jFQgpBhf7o-QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 17:13:22
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.157 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 13:13:15.143895 2026] [security2:error] [pid 1297583:tid 1297583] [client 172.70.38.157:11676] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.adrienberthaud.com"] [uri "/.git/config"] [unique_id "antYKwaHx_j65DP6cje4ZQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-11 11:01:56
(2 months ago)
Web App Attack
๐ฉ๐ช
Sรฉfora Srl
2026-07-03 05:02:18
(3 months ago)
Bad user agents ignoring web crawling rules. Draing bandwidth - detected by Fail2Ban in plesk-apache ...
show more
Bad user agents ignoring web crawling rules. Draing bandwidth - detected by Fail2Ban in plesk-apache-badbot jail
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-06 02:04:45
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.157 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 22:04:37.761063 2026] [security2:error] [pid 7086:tid 7086] [client 172.70.38.157:12742] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.kraftre.com"] [uri "/.env.staging"] [unique_id "adMUtU8PNfH0wHmp8pzyJgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 07:16:49
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.157 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 03:16:44.441798 2026] [security2:error] [pid 3272:tid 3272] [client 172.70.38.157:13592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.fashionisland.ca"] [uri "/config/.env.local"] [unique_id "adIMXKT-K-B6LwvKHO8LzAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 03:47:42
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.157 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 23:47:39.261207 2026] [security2:error] [pid 22277:tid 22277] [client 172.70.38.157:10288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.secureinitiatives.com"] [uri "/.git/refs/heads/master"] [unique_id "adHbW3Okb1eZ-aPHntQqSwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 23:58:45
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.157 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 19:58:22.607207 2026] [security2:error] [pid 5673:tid 5673] [client 172.70.38.157:13516] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.achari.com"] [uri "/.env.orig"] [unique_id "adGlnrBZDoaBCOcXcOYrYgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 22:31:40
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.157 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 18:31:32.733198 2026] [security2:error] [pid 22441:tid 22441] [client 172.70.38.157:12917] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.destintoday.com.danged.com"] [uri "/backend/.env"] [unique_id "adGRREdRZuf352aI5J4S3wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack