π²π½
octageeks.com
2026-06-10 04:10:16
(2 weeks ago)
Wordpress malicious attack:[octaflood]
Web App Attack
π©πͺ
FeG Deutschland
2026-06-09 02:24:53
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-06 05:06:45
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 172.70.80.234 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.80.234 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 01:06:40.435558 2026] [security2:error] [pid 16134:tid 16134] [client 172.70.80.234:9395] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.thesweetfam.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.thesweetfam.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "aiOq4HVhG3-HN4NIMXm5NQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-05 13:27:33
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 172.70.80.234 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.80.234 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 09:27:28.839773 2026] [security2:error] [pid 19362:tid 19362] [client 172.70.80.234:13977] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.simonharvey.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.simonharvey.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "aiLOwDFL4xUl0ds4p1NunwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-23 02:53:54
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 172.70.80.234 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.80.234 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 22:53:49.360762 2026] [security2:error] [pid 7719:tid 7730] [client 172.70.80.234:12181] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.americanacademyofprojectmanagement.com|F|2"] [data "[email protected] "] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.americanacademyofprojectmanagement.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "ahEWvU7d-SN0mD1h1X3TiQAAAIg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-17 09:14:47
(1 month ago)
Aggressive web scan
Web App Attack
Anonymous
2026-05-15 08:28:02
(1 month ago)
Web App Attack
Brute-Force
Web App Attack
Anonymous
2026-05-14 04:24:59
(1 month ago)
Aggressive web scan
Web App Attack
Anonymous
2026-05-12 01:25:09
(1 month ago)
Aggressive web scan
Web App Attack
Anonymous
2026-04-13 08:10:50
(2 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
πΊπΈ
TPI-Abuse
2026-04-08 09:20:33
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.234 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.234 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 05:20:27.874889 2026] [security2:error] [pid 466073:tid 466092] [client 172.70.80.234:13851] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "property-management.company"] [uri "/.env.production"] [unique_id "adYd2wX6SWtI3chCCeiIhgAAAU8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-08 06:06:22
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.234 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.234 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 02:06:13.997741 2026] [security2:error] [pid 1949646:tid 1949646] [client 172.70.80.234:11696] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.lonescouting.us"] [uri "/.env.old"] [unique_id "adXwVd1cU_Zjm2qs0JCgOQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-07 08:34:01
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.234 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.234 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 04:33:53.449535 2026] [security2:error] [pid 1232279:tid 1232279] [client 172.70.80.234:12221] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mariarozella.com"] [uri "/.env.old"] [unique_id "adTBcbPu3qRFj9T7xd4EEwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-06 21:31:54
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.234 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.234 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 17:31:51.246861 2026] [security2:error] [pid 387552:tid 387552] [client 172.70.80.234:14137] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sys.integratic.com.co"] [uri "/.env.local"] [unique_id "adQmRxDVhMDkCUmj2yAycgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-06 11:15:30
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.234 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.234 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 07:15:22.817423 2026] [security2:error] [pid 24381:tid 24381] [client 172.70.80.234:12878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.brupharm.net"] [uri "/.env.staging"] [unique_id "adOVymXxowl0TZJ7Qr-xxwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack