๐บ๐ธ
MPL
2026-09-04 20:26:49
(2 weeks ago)
tcp/443 (10 or more attempts)
Port Scan
๐ง๐ช
madeit
2026-08-13 12:40:03
(1 month ago)
Web App Attack
Anonymous
2026-06-14 04:41:57
(3 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ณ๐ฑ
homeshowdomain.nl
2026-06-11 21:59:44
(3 months ago)
Auto-ban: >3000 req/min op 2026-06-11
Web App Attack
SSH
Hacking
๐ฒ๐ฝ
octageeks.com
2026-06-10 04:36:56
(3 months ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐บ๐ธ
mnsf
2026-06-09 10:08:09
(3 months ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 22:38:20
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 172.70.80.106 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.80.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 18:38:16.308703 2026] [security2:error] [pid 18468:tid 18468] [client 172.70.80.106:12686] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.stevedegroodt.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.stevedegroodt.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "aidEWPQjWX9pKpywQyDAPwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-23 08:14:28
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 172.70.80.106 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.80.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 04:14:23.061645 2026] [security2:error] [pid 7236:tid 7236] [client 172.70.80.106:11317] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.acraloc.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.acraloc.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "ahFh33OA5puZJ1Tv4MFoDwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-19 18:12:25
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 172.70.80.106 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.80.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 19 14:12:22.185186 2026] [security2:error] [pid 17688:tid 17688] [client 172.70.80.106:9417] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.stevedegroodt.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.stevedegroodt.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "agyoBjOLBWOBZbbnjQzPZAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐ฑ
router.al
2026-05-12 09:12:47
(4 months ago)
05/12/2026-09:12:47.233468 172.70.80.106 Protocol: 6 ET HUNTING Request for Webshell in .well-known ...
show more
05/12/2026-09:12:47.233468 172.70.80.106 Protocol: 6 ET HUNTING Request for Webshell in .well-known directory
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-08 15:50:45
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.106 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 11:50:38.018877 2026] [security2:error] [pid 2330824:tid 2330824] [client 172.70.80.106:10718] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grupo-visalud.com"] [uri "/private/.env"] [unique_id "adZ5TofVZl4aZ8cwfS_UggAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 02:29:03
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.106 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 22:28:58.582955 2026] [security2:error] [pid 1799279:tid 1799279] [client 172.70.80.106:14329] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.7bsuperfruit.com"] [uri "/.env.bak"] [unique_id "adW9ajJ_Oqik-4R4Pgh9tAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 11:51:28
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.106 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 07:51:21.227160 2026] [security2:error] [pid 33654:tid 33654] [client 172.70.80.106:9965] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.takeapawsboston.com"] [uri "/.env.dev"] [unique_id "adOeOSxaFEEkBoRXOEcftgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 09:25:09
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.106 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 05:25:03.357578 2026] [security2:error] [pid 22582:tid 22582] [client 172.70.80.106:13603] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.surviquo.com"] [uri "/.git/refs/heads/main"] [unique_id "adN77x_GonyfUwLATLLwUwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 06:29:53
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.106 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 02:29:48.660474 2026] [security2:error] [pid 12718:tid 12718] [client 172.70.80.106:11964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.chateau-saleza-bruges.com"] [uri "/.env.staging"] [unique_id "adNS3PWtD37r47czLM5_qwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack