πΊπ¦
URAN Publishing Service
2026-07-06 16:01:30
(1 week ago)
172.68.164.12 - - [06/Jul/2026:19:01:30 +0300] "POST /wp-admin/admin-ajax.php HTTP/1.1" 404 3351 "-" ...
show more
172.68.164.12 - - [06/Jul/2026:19:01:30 +0300] "POST /wp-admin/admin-ajax.php HTTP/1.1" 404 3351 "-" "Mozilla/5.0"
...
show less
Web App Attack
πΊπ¦
URAN Publishing Service
2026-07-05 19:32:14
(2 weeks ago)
172.68.164.12 - - [05/Jul/2026:22:32:13 +0300] "GET /wp-includes/js/ HTTP/1.1" 404 3351 "-" "Mozilla ...
show more
172.68.164.12 - - [05/Jul/2026:22:32:13 +0300] "GET /wp-includes/js/ HTTP/1.1" 404 3351 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.68.164.12 - - [05/Jul/2026:22:32:13 +0300] "GET /wp-admin/css/colors/ HTTP/1.1" 404 791 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
π¬π§
openstrike.co.uk
2026-06-30 05:14:08
(2 weeks ago)
37 attacks on PHP URLs, env grabbing URLs, password grabbing URLs, VC URLs:
GET /apis/server/phpinfo ...
show more
37 attacks on PHP URLs, env grabbing URLs, password grabbing URLs, VC URLs:
GET /apis/server/phpinfo.php HTTP/1.1
GET /app/.env HTTP/1.1
GET /.aws/credentials HTTP/1.1
GET /.git/config HTTP/1.1
show less
Web App Attack
Hacking
π¬π§
Axel
2026-06-22 22:38:13
(3 weeks ago)
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.env Server: ...
show more
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.env Server: UK-01
show less
Web App Attack
Hacking
SQL Injection
π¬π§
Axel
2026-06-19 16:19:34
(1 month ago)
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.git/config ...
show more
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.git/config Server: UK-01
show less
Web App Attack
Hacking
SQL Injection
π¬π§
Axel
2026-06-03 11:08:03
(1 month ago)
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /new/.env Ser ...
show more
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /new/.env Server: UK-01
show less
Web App Attack
Hacking
SQL Injection
πΊπ¦
URAN Publishing Service
2026-05-21 17:51:51
(1 month ago)
172.68.164.12 - - [21/May/2026:20:51:50 +0300] "GET /wp-content/plugins/ HTTP/1.1" 404 769 "-" "Go-h ...
show more
172.68.164.12 - - [21/May/2026:20:51:50 +0300] "GET /wp-content/plugins/ HTTP/1.1" 404 769 "-" "Go-http-client/1.1"
172.68.164.12 - - [21/May/2026:20:51:50 +0300] "GET /wp-admin/js/widgets/maint/ HTTP/1.1" 404 769 "-" "Go-http-client/1.1"
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-15 11:19:02
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.164.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.164.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 07:18:56.514098 2026] [security2:error] [pid 2019:tid 2019] [client 172.68.164.12:12849] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "myclassicvw.com"] [uri "/.env.backup"] [unique_id "agcBIEYdOcqvoq1mBkEuxQAAAAQ"], referer: https://www.google.com/search?q=myclassicvw.com
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
acadeova
2026-05-14 16:02:02
(2 months ago)
π¨ Recon detected (nft drop)
SRC=172.68.164.12
Observed=TCP dpt=80 in=enp0s6 ttl=55
Time=recent(journ ...
show more
π¨ Recon detected (nft drop)
SRC=172.68.164.12
Observed=TCP dpt=80 in=enp0s6 ttl=55
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
πΊπΈ
octageeks.com
2026-05-13 04:06:27
(2 months ago)
Wordpress malicious attack:[octawpauthor]
Web App Attack
Anonymous
2026-05-12 11:36:17
(2 months ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
πΊπ¦
URAN Publishing Service
2026-05-10 23:19:15
(2 months ago)
172.68.164.12 - - [11/May/2026:02:19:15 +0300] "GET /wp-content/admin.php HTTP/1.1" 404 791 "-" "Moz ...
show more
172.68.164.12 - - [11/May/2026:02:19:15 +0300] "GET /wp-content/admin.php HTTP/1.1" 404 791 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
πΊπ¦
URAN Publishing Service
2026-05-10 08:33:04
(2 months ago)
172.68.164.12 - - [10/May/2026:11:33:02 +0300] "GET /wp-content/index.php HTTP/1.1" 404 791 "-" "Moz ...
show more
172.68.164.12 - - [10/May/2026:11:33:02 +0300] "GET /wp-content/index.php HTTP/1.1" 404 791 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.68.164.12 - - [10/May/2026:11:33:03 +0300] "GET /wp-content/plugins/beteng88/ws83.php HTTP/1.1" 404 791 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
πΊπ¦
URAN Publishing Service
2026-05-08 19:32:09
(2 months ago)
172.68.164.12 - - [08/May/2026:22:31:56 +0300] "GET /xmlrpc.php HTTP/1.1" 404 791 "-" "Mozilla/5.0 ( ...
show more
172.68.164.12 - - [08/May/2026:22:31:56 +0300] "GET /xmlrpc.php HTTP/1.1" 404 791 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.68.164.12 - - [08/May/2026:22:32:08 +0300] "GET /wp-includes/html-api/ HTTP/1.1" 404 3352 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-08 14:24:57
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.164.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.164.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 10:24:52.297648 2026] [security2:error] [pid 13246:tid 13246] [client 172.68.164.12:13900] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.jamelrobinson.com"] [uri "/.git/config"] [unique_id "af3yNC4PWQSyAP-DlDVkSgAAACI"], referer: https://www.google.com/search?q=mail.jamelrobinson.com
show less
Brute-Force
Bad Web Bot
Web App Attack