Anonymous
2026-08-26 14:46:53
(1 day ago)
[Wed Aug 26 16:46:52.704740 2026] [authz_core:error] [pid 6477] [client 172.70.80.32:12225] AH01630: ...
show more
[Wed Aug 26 16:46:52.704740 2026] [authz_core:error] [pid 6477] [client 172.70.80.32:12225] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Wed Aug 26 16:46:52.835621 2026] [authz_core:error] [pid 6477] [client 172.70.80.32:12225] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Wed Aug 26 16:46:52.962991 2026] [authz_core:error] [pid 6477] [client 172.70.80.32:12225] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐ง๐ช
madeit
2026-08-18 21:39:05
(1 week ago)
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-08-09 06:35:51
(2 weeks ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐ง๐ช
madeit
2026-08-07 05:43:53
(2 weeks ago)
Web App Attack
Anonymous
2026-07-27 13:10:50
(1 month ago)
[Mon Jul 27 15:10:48.196037 2026] [authz_core:error] [pid 4338] [client 172.70.80.32:10751] AH01630: ...
show more
[Mon Jul 27 15:10:48.196037 2026] [authz_core:error] [pid 4338] [client 172.70.80.32:10751] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon Jul 27 15:10:48.385927 2026] [authz_core:error] [pid 4338] [client 172.70.80.32:10751] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon Jul 27 15:10:49.542714 2026] [authz_core:error] [pid 4338] [client 172.70.80.32:10751] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-02 03:18:43
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 172.70.80.32 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.80.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 23:18:36.763066 2026] [security2:error] [pid 29911:tid 29911] [client 172.70.80.32:14017] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.lusocleaningservice.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.lusocleaningservice.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "akXYjPnZ5kruiTpEdBqRNgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-21 05:11:48
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.32 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 01:11:42.151249 2026] [security2:error] [pid 23661:tid 23661] [client 172.70.80.32:9870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.edupal.angeltarrac.com"] [uri "/.env.old"] [unique_id "ajdyjqLfazEDbIVmdGUM1QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-18 06:52:11
(2 months ago)
Web App Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 06:27:02
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 172.70.80.32 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.80.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 02:26:57.891866 2026] [security2:error] [pid 18489:tid 18489] [client 172.70.80.32:13621] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.dalessalesandservice.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.dalessalesandservice.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "aipVMXF8nUWA4pVpyy6GGwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-10 09:35:13
(2 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฌ๐ง
sandra361
2026-06-01 02:45:01
(2 months ago)
Port scan detected: 6 attempts across 1 ports (443). | Evidence: REAPER_TARPIT:IN=enp1s0f0 OUT= SRC= ...
show more
Port scan detected: 6 attempts across 1 ports (443). | Evidence: REAPER_TARPIT:IN=enp1s0f0 OUT= SRC=172.70.80.32 LEN=60 TOS=0x00 PREC=0x00 TTL=55 ID=31634 DF PROTO=TCP SPT=10710 DPT=443 WINDOW=65535 RES=0x00 SYN URGP=0
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-21 21:17:16
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 172.70.80.32 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.80.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 17:17:09.383052 2026] [security2:error] [pid 11075:tid 11075] [client 172.70.80.32:11142] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.greensealusa.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.greensealusa.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "ag92VXPEEUqLb8yIPhdoTQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐ฑ
router.al
2026-05-16 04:16:13
(3 months ago)
05/16/2026-04:16:13.326252 172.70.80.32 Protocol: 6 ET SCAN LeakIX Inbound User-Agent
Hacking
๐ต๐ฑ
Jacqb
2026-05-13 17:53:16
(3 months ago)
Adres potencjalnie niebezpieczny
Brute-Force
Web App Attack
Bad Web Bot
๐ต๐ฑ
Jacqb
2026-05-12 15:45:23
(3 months ago)
Adres potencjalnie niebezpieczny
Brute-Force
Web App Attack
Bad Web Bot