πͺπΈ
el-brujo
2026-08-28 17:42:30
(1 week ago)
28/Aug/2026:19:42:28.742213 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
28/Aug/2026:19:42:28.742213 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 172.70.38.176] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "warzone.elhacker.net"] [uri "/.env.production"] [unique_id "apHIhEPc-X9QNg3LF2In1gAAdQI"]
...
show less
Hacking
Web App Attack
πͺπΈ
el-brujo
2026-08-17 16:24:28
(2 weeks ago)
17/Aug/2026:18:24:27.952419 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
17/Aug/2026:18:24:27.952419 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 172.70.38.176] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "warzone.elhacker.net"] [uri "/.env.production.local"] [unique_id "aoM1u64fbs4x1hRg3MFldwAC4GY"]
...
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 11:31:02
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.176 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 07:30:59.104153 2026] [security2:error] [pid 9280:tid 9280] [client 172.70.38.176:12639] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.whaleyhouse.net"] [uri "/.git/HEAD"] [unique_id "aoLw8w8Vg6vh6XmFh-e41AAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 10:10:50
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.176 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:10:45.377462 2026] [security2:error] [pid 24701:tid 24701] [client 172.70.38.176:9302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.jazziientertainment.com"] [uri "/.git/config"] [unique_id "aoLeJacEqbx7664cEA9VGAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 02:07:45
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.176 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 22:07:36.891434 2026] [security2:error] [pid 12356:tid 12356] [client 172.70.38.176:13559] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.dutchlake.com"] [uri "/.git/HEAD"] [unique_id "aoEbaKORgwasJjXB5U-uEQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-15 17:45:37
(3 weeks ago)
172.70.38.176 - - [15/Aug/2026:19:45:33 +0200] "GET /@fs/home/node/.aws/config?raw?? HTTP/1.1" 403 1 ...
show more
172.70.38.176 - - [15/Aug/2026:19:45:33 +0200] "GET /@fs/home/node/.aws/config?raw?? HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot)"
172.70.38.176 - - [15/Aug/2026:19:45:33 +0200] "GET /@fs/etc/nginx/nginx.conf?raw?? HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; Google-Extended/1.0; +http://www.google.com/bot.html)"
172.70.38.176 - - [15/Aug/2026:19:45:33 +0200] "GET /@fs/home/ubuntu/.config/gcloud/application_default_credentials.json?raw?? HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot)"
172.70.38.176 - - [15/Aug/2026:19:45:33 +0200] "GET /@fs/root/.claude/settings.json?raw?? HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; Google-Extended/1.0; +http://www.google.com/bot.html)"
172.70.38.176 - - [15/Aug/2026:19:45:33 +0200] "GET /.git/HEAD HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/ama
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-11 11:11:16
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.176 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 07:11:09.926760 2026] [security2:error] [pid 2890966:tid 2890966] [client 172.70.38.176:10812] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fasllc.rooksfamily.com"] [uri "/.git/config"] [unique_id "ansDTd9nSsnsNG_GPBOXIwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
interbiznw.com
2026-08-02 23:15:58
(1 month ago)
fail2ban-ban
Hacking
Brute-Force
Exploited Host
Web App Attack
πΊπΈ
mawan
2026-07-16 16:16:08
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
π²π½
octageeks.com
2026-05-17 04:11:27
(3 months ago)
Wordpress malicious attack:[octaflood]
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-15 08:12:22
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.176 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:10:57.567008 2026] [security2:error] [pid 3287:tid 3287] [client 172.70.38.176:9699] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.galaxymarble.quest.38floorsupply.com"] [uri "/sftp-config.json"] [unique_id "agbVERES5OYC9yCQeqhInQAAACo"], referer: https://www.google.com/search?q=www.galaxymarble.quest.38floorsupply.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-06 21:08:35
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.176 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 17:08:27.257461 2026] [security2:error] [pid 650913:tid 650913] [client 172.70.38.176:10552] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.jeremyurbanski.com"] [uri "/.env.dev"] [unique_id "adQgy8APMCiCnS9DBmJClAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-06 18:18:38
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.176 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 14:18:33.159842 2026] [security2:error] [pid 358431:tid 358431] [client 172.70.38.176:11894] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.sanjuangrange.org"] [uri "/.env.php"] [unique_id "adP4-Wv_TieYkcDDClwQ_gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-06 15:04:40
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.176 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 11:04:34.455715 2026] [security2:error] [pid 337067:tid 337067] [client 172.70.38.176:14093] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.mdivietnam.com"] [uri "/.env.test"] [unique_id "adPLghjERa9OtZpEk-Qz9QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-05 11:24:16
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.176 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 07:24:11.163235 2026] [security2:error] [pid 21503:tid 21503] [client 172.70.38.176:9341] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "royal-barbershop.com"] [uri "/.env.test"] [unique_id "adJGW-T4sPkVXPw2QWCOIQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack