๐ซ๐ท
dynamix
2026-10-11 01:21:44
(11 hours ago)
Multiple WAF Violations
Web App Attack
๐ง๐ช
madeit
2026-09-30 21:06:49
(1 week ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 15:41:14
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.244 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 11:41:09.334396 2026] [security2:error] [pid 30452:tid 30452] [client 172.70.38.244:10983] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.mitchellamazing.com"] [uri "/.git/config"] [unique_id "aoMrlQZqG9tE1muZ03Y0DgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 14:09:13
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.244 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 10:09:09.454802 2026] [security2:error] [pid 26545:tid 26574] [client 172.70.38.244:10729] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.coloradospringsdermatology.com"] [uri "/.git/config"] [unique_id "aoMWBfCjvfsVcQ8RrafTEAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 10:53:51
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.244 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:53:45.214785 2026] [security2:error] [pid 19960:tid 19960] [client 172.70.38.244:10966] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.yosalvationyo.org"] [uri "/.git/config"] [unique_id "aoLoOV6lAHGCGMyKr25z6gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 08:08:14
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.244 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 04:08:08.794946 2026] [security2:error] [pid 17735:tid 17735] [client 172.70.38.244:12523] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.bikinitweets.com"] [uri "/.git/config"] [unique_id "aoLBaE2_rsH1NKX2ofMFtgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-08-14 17:51:36
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ง๐ท
chronos
2026-08-13 06:47:23
(1 month ago)
2026-08-13 03:23:38 UTC-3||Unauthorized connection attempt detected for port scanning
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-12 09:08:19
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.244 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 05:08:10.696625 2026] [security2:error] [pid 2867256:tid 2867256] [client 172.70.38.244:13109] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.kameleonquilt.com"] [uri "/.git/config"] [unique_id "anw3-n5h1j9DC09jonTq7wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-09 08:54:00
(2 months ago)
Web App Attack
๐บ๐ธ
mawan
2026-07-21 22:08:03
(2 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
Anonymous
2026-06-18 14:06:18
(3 months ago)
172.70.38.244 - - [18/Jun/2026:16:05:53 +0200] "GET /?items/U216837668/ HTTP/1.1" 403 12583 "-" "Moz ...
show more
172.70.38.244 - - [18/Jun/2026:16:05:53 +0200] "GET /?items/U216837668/ HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.7827.155 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
172.70.38.244 - - [18/Jun/2026:16:05:54 +0200] "GET /?items/W107554153/ HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.7778.96 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
172.70.38.244 - - [18/Jun/2026:16:05:54 +0200] "GET /?items/U192920628/ HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.7827.155 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
172.70.38.244 - - [18/Jun/2026:16:05:56 +0200] "GET /?items/U226917901/ HTTP/1.1" 403 12583 "-" "Mozilla
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 09:21:12
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 172.70.38.244 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.38.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 05:20:45.913074 2026] [security2:error] [pid 12804:tid 12804] [client 172.70.38.244:13426] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||hills-tax.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hills-tax.com"] [uri "/backup.sql"] [unique_id "agblbZBUBDrF3a7a7qd48wAAAGo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
trentwiles.com
2026-05-10 04:12:49
(5 months ago)
Unauthorized connection attempt detected from IP address 172.70.38.244 to port 443 [SYD]
Port Scan
๐บ๐ธ
TPI-Abuse
2026-04-08 21:08:24
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.244 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 17:08:17.888366 2026] [security2:error] [pid 3319608:tid 3319608] [client 172.70.38.244:10644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yacht-register-san-marino.com"] [uri "/admin/.env"] [unique_id "adbDwcVMsdwmcpY-I7lfbQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack