๐ง๐ฌ
Stoyko Stoykov
2026-08-16 21:56:06
(1 month ago)
172.70.42.91 - - [17/Aug/2026:00:56:06 +0300] "GET /goods.php HTTP/1.1" 301 162 "-" "-"
...
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 09:59:16
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.42.91 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.42.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 05:59:12.617287 2026] [security2:error] [pid 11142:tid 11256] [client 172.70.42.91:10154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.gamecrazy.us"] [uri "/.git/HEAD"] [unique_id "aoGJ8P6xqNltni7ioC9pBgAAAMA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 06:44:15
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.42.91 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.42.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 02:44:10.109541 2026] [security2:error] [pid 1183:tid 1183] [client 172.70.42.91:12584] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.lightbender.net"] [uri "/.git/HEAD"] [unique_id "aoFcOgMqrr55U68IIL0MHAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2026-08-15 21:54:28
(1 month ago)
15/Aug/2026:23:54:28.614163 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
15/Aug/2026:23:54:28.614163 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 172.70.42.91] ModSecurity: Warning. Pattern match "(?:^|=)\\\\\\\\s*(?:{|\\\\\\\\s*\\\\\\\\(\\\\\\\\s*|\\\\\\\\w+=(?:[^\\\\\\\\s]*|\\\\\\\\$.*|\\\\\\\\$.*|<.*|>.*|\\\\\\\\'.*\\\\\\\\'|\\\\".*\\\\")\\\\\\\\s+|!\\\\\\\\s*|\\\\\\\\$)*\\\\\\\\s*(?:'|\\\\")*(?:[\\\\\\\\?\\\\\\\\*\\\\\\\\[\\\\\\\\]\\\\\\\\(\\\\\\\\)\\\\\\\\-\\\\\\\\|+\\\\\\\\w'\\\\"\\\\\\\\./\\\\\\\\\\\\\\\\]+/)?[\\\\\\\\\\\\\\\\'\\\\"]*(?:l[\\\\\\\\\\\\\\\\'\\\\"]*(?:s(?:[\\\\\\\\\\\\\\\\'\\\\"]*(?:b[\\\\\\\\\\\\\\\\'\\\\"]*_[\\\\\\\\\\\\\\\\'\\\\"]*r[\\\\\\\\\\\\\\\\'\\\\"]*e[\\\\\\\\\\\\\\\\'\\\\"]*l[\\\\\\\\\\\\\\\\' ..." at ARGS_NAMES:php the_permalink( $recent_post->ID ); ?>. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "464"] [id "932150"] [msg "Remote Command Execution: Direct Unix Command Execution"] [data "Matched Data: php found within ARGS_NAMES:php the_permalink(
...
show less
Hacking
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-08-15 19:08:41
(1 month ago)
172.70.42.91 - - [15/Aug/2026:22:08:40 +0300] "GET /wp-admin/css/ HTTP/1.1" 301 162 "-" "-"
...
Hacking
Web App Attack
๐ง๐ช
madeit
2026-08-13 22:06:45
(1 month ago)
Web App Attack
Anonymous
2026-07-25 10:40:43
(2 months ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
Anonymous
2026-07-17 13:22:10
(2 months ago)
[Fri Jul 17 15:22:08.750320 2026] [authz_core:error] [pid 13756] [client 172.70.42.91:10130] AH01630 ...
show more
[Fri Jul 17 15:22:08.750320 2026] [authz_core:error] [pid 13756] [client 172.70.42.91:10130] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri Jul 17 15:22:08.876410 2026] [authz_core:error] [pid 13756] [client 172.70.42.91:10130] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri Jul 17 15:22:09.387939 2026] [authz_core:error] [pid 13756] [client 172.70.42.91:10130] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-02 16:02:31
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.42.91 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.42.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 12:02:23.260067 2026] [security2:error] [pid 22283:tid 22283] [client 172.70.42.91:11221] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "secretsoftheuniverse.bluegrassexpressband.com"] [uri "/admin/.env"] [unique_id "ac6TDxUoZlHXt3rfGiR3EwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-02 04:35:39
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.42.91 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.42.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 00:35:35.236367 2026] [security2:error] [pid 13884:tid 13884] [client 172.70.42.91:11649] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.campos.tv"] [uri "/.env.development.local"] [unique_id "ac3yF5LOllz6PdrjGctq8wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-02 00:06:04
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.42.91 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.42.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 01 20:05:55.965794 2026] [security2:error] [pid 3613:tid 3613] [client 172.70.42.91:13975] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "danafrostick.com"] [uri "/server/.env"] [unique_id "ac2y4y0Kzk9SMS-Ib_PGxQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-01 20:25:25
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.42.91 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.42.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 01 16:25:22.130483 2026] [security2:error] [pid 31908:tid 31914] [client 172.70.42.91:10782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "proracersecrets.com"] [uri "/.env.production"] [unique_id "ac1_Mia41XlbloOsEMRAzwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-01 06:02:46
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.42.91 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.42.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 01 02:02:37.976552 2026] [security2:error] [pid 21873:tid 21873] [client 172.70.42.91:9766] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.filardi.org"] [uri "/.env.production"] [unique_id "acy0_bOfk22cELwGNIlw5gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 13:26:06
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.42.91 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.42.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 09:25:59.916982 2026] [security2:error] [pid 14976:tid 14976] [client 172.70.42.91:11977] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.johnmorogiello.com"] [uri "/.env.production.local"] [unique_id "acvLZ_HDnOzqjhibXI2EBwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 09:44:40
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.42.91 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.42.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 05:44:32.548050 2026] [security2:error] [pid 31052:tid 31052] [client 172.70.42.91:12390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.franchiseconsultants.biz"] [uri "/.env.json"] [unique_id "acuXgMPdy_x2bUSCI-ZQVwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack