🇳🇿
Tripwire
2026-09-10 17:35:37
(1 day ago)
Scanning for exploits - /wp-json/batch/v1
Web App Attack
🇳🇿
Tripwire
2026-09-09 17:15:26
(2 days ago)
Scanning for exploits - /wp-json/batch/v1
Web App Attack
🇺🇸
juguemosalacarioca.com
2026-03-30 06:21:53
(5 months ago)
Multiple HTTP calls attempting to GET resources using common API calls or formats on port 8080
Web App Attack
🇨🇳
ThreatBook.io
2026-01-22 23:29:29
(7 months ago)
ThreatBook Intelligence: cdn more details on http://threatbook.io/ip/139.59.13.117
2026-01-22 18:25: ...
show more
ThreatBook Intelligence: cdn more details on http://threatbook.io/ip/139.59.13.117
2026-01-22 18:25:38 /
show less
Web App Attack
🇺🇸
MPL
2026-01-22 09:44:39
(7 months ago)
tcp/1000 (2 or more attempts)
Port Scan
🇸🇪
Abu Bakr
2026-01-22 09:41:37
(7 months ago)
endlessh-go tarpit accepted connection
Brute-Force
SSH
🇳🇱
CryptoYakari
2025-08-03 16:35:06
(1 year ago)
139.59.13.117 - - [03/Aug/2025:19:34:59 +0300] "GET /admin HTTP/1.0" 404 6995 "-" "Mozilla/5.0 (Wind ...
show more
139.59.13.117 - - [03/Aug/2025:19:34:59 +0300] "GET /admin HTTP/1.0" 404 6995 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:129.0) Gecko/20100101 Firefox/129.0"
139.59.13.117 - - [03/Aug/2025:19:34:59 +0300] "GET /administrator HTTP/1.0" 404 3514 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:129.0) Gecko/20100101 Firefox/129.0"
139.59.13.117 - - [03/Aug/2025:19:35:00 +0300] "GET /admincp HTTP/1.0" 404 3514 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:129.0) Gecko/20100101 Firefox/129.0"
139.59.13.117 - - [03/Aug/2025:19:35:00 +0300] "GET /admin-panel HTTP/1.0" 404 3514 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:129.0) Gecko/20100101 Firefox/129.0"
139.59.13.117 - - [03/Aug/2025:19:35:01 +0300] "GET /controlpanel HTTP/1.0" 404 3514 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:129.0) Gecko/20100101 Firefox/129.0"
...
show less
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
Anonymous
2025-08-01 17:20:54
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
🇺🇸
TPI-Abuse
2025-07-30 14:00:35
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 139.59.13.117 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 139.59.13.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 30 10:00:27.530600 2025] [security2:error] [pid 6281:tid 6281] [client 139.59.13.117:58823] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "williamcline.com"] [uri "/.env"] [unique_id "aIole11cQTDJnx4WQs6GFgAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
backslash
2025-07-29 05:40:16
(1 year ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
🇺🇸
TPI-Abuse
2025-07-29 05:32:08
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 139.59.13.117 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 139.59.13.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 29 01:32:05.147433 2025] [security2:error] [pid 21222:tid 21222] [client 139.59.13.117:51259] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dc406.org"] [uri "/.env"] [unique_id "aIhc1QsOZC9KfEYCMIMhywAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-07-29 05:16:34
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 139.59.13.117 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 139.59.13.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 29 01:16:28.196228 2025] [security2:error] [pid 5317:tid 5317] [client 139.59.13.117:61861] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "metrotcs.com"] [uri "/.env"] [unique_id "aIhZLMjLh3PvhigJO2j20gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-07-29 04:21:35
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 139.59.13.117 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 139.59.13.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 29 00:21:31.685374 2025] [security2:error] [pid 14257:tid 14257] [client 139.59.13.117:57153] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kimbrothersusa.com"] [uri "/.env"] [unique_id "aIhMS1r_CkwxBgmdSMZxZQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2025-07-28 09:51:35
(1 year ago)
Multiple WAF Violations
Web App Attack
🇫🇷
dynamix
2025-07-27 08:11:39
(1 year ago)
Multiple WAF Violations
Web App Attack