๐ง๐ช
madeit
2026-09-18 06:22:16
(1 day ago)
Web App Attack
Anonymous
2026-09-01 21:11:59
(2 weeks ago)
[Tue Sep 01 23:11:57.666350 2026] [authz_core:error] [pid 29887] [client 172.70.80.118:10690] AH0163 ...
show more
[Tue Sep 01 23:11:57.666350 2026] [authz_core:error] [pid 29887] [client 172.70.80.118:10690] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Sep 01 23:11:58.366341 2026] [authz_core:error] [pid 29887] [client 172.70.80.118:10690] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Sep 01 23:11:58.681952 2026] [authz_core:error] [pid 29887] [client 172.70.80.118:10690] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐ง๐ช
madeit
2026-08-17 14:24:30
(1 month ago)
Web App Attack
๐ซ๐ท
UnixPrime
2026-08-17 00:18:55
(1 month ago)
172.70.80.118 - - [17/Aug/2026:02:18:48 +0200] "GET /info.php HTTP/1.1" 404 118 "-" "-"
172.70.80.11 ...
show more
172.70.80.118 - - [17/Aug/2026:02:18:48 +0200] "GET /info.php HTTP/1.1" 404 118 "-" "-"
172.70.80.118 - - [17/Aug/2026:02:18:54 +0200] "GET /cgi-bin/index.php HTTP/1.1" 404 118 "-" "-"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
ratcarcher-labs
2026-08-05 06:23:03
(1 month ago)
[Ratcarcher Labs/MutantShield honeypot CTI] actor=human vector=brute_force_auth risk=80 attacks=8 de ...
show more
[Ratcarcher Labs/MutantShield honeypot CTI] actor=human vector=brute_force_auth risk=80 attacks=8 depth=4 node=node-ap-south canary=no human_score=65 agentic=15 cc=CA asn=Cloudflare, Inc. | Data provided by Ratcarcher Labs ยท https://ratcarcher-labs.com ยท docs https://api.ratcarcher-labs.com/api/v1/public/docs
show less
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-07-17 09:15:39
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.118 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 05:15:34.510243 2026] [security2:error] [pid 38226:tid 38226] [client 172.70.80.118:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.webuildbeaches.com"] [uri "/.git/config"] [unique_id "alnytnlOIAXtASQU5mZIsQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-09 02:06:32
(3 months ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐ฆ๐บ
oncord
2026-05-19 13:13:21
(3 months ago)
Form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2026-05-03 08:24:53
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 172.70.80.118 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.80.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 03 04:24:49.523176 2026] [security2:error] [pid 27547:tid 27547] [client 172.70.80.118:12950] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.drpeppard.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.drpeppard.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "afcGUQBWE-ubyX_YEn6TrgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-19 21:26:29
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 172.70.80.118 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.80.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 19 17:26:21.259968 2026] [security2:error] [pid 1806126:tid 1806126] [client 172.70.80.118:10386] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.tonytremblayauthor.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.tonytremblayauthor.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "aeVIfXogdy9nrrIoGD4tcgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 09:06:47
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.118 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 05:06:37.247241 2026] [security2:error] [pid 2366564:tid 2366564] [client 172.70.80.118:14005] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sr.handyrehab.com"] [uri "/.env.test"] [unique_id "adYanSYvWJ1Fig_WIUGoFgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 15:55:15
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.118 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 11:54:59.410555 2026] [security2:error] [pid 1215402:tid 1215402] [client 172.70.80.118:10779] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.gevieworld.com"] [uri "/.env.bak"] [unique_id "adUo07P-d96A67Ize--V4gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 06:23:20
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.118 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 02:23:11.882869 2026] [security2:error] [pid 1018209:tid 1018209] [client 172.70.80.118:14112] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.stsis.me"] [uri "/private/.env"] [unique_id "adSiz8a0Q6Arpq1VKR8L6QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 00:21:03
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.118 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 20:20:58.453736 2026] [security2:error] [pid 519264:tid 519264] [client 172.70.80.118:13828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "iammeapparel.liddlesports.com"] [uri "/.env.prod"] [unique_id "adRN6kfhjz51JD7sOJn6cgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 23:27:25
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.118 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 19:26:56.006601 2026] [security2:error] [pid 562623:tid 562623] [client 172.70.80.118:13729] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jennyfiore.com"] [uri "/.env_config"] [unique_id "adRBQKmtMpLsjvC5k0QnQwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack