Anonymous
2026-09-18 20:13:59
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-09-13 19:39:29
(6 days ago)
Multiple WAF Violations
Web App Attack
๐ง๐ช
madeit
2026-09-11 18:25:16
(1 week ago)
Web App Attack
๐ฉ๐ช
acadeova
2026-08-16 08:01:30
(1 month ago)
๐จ Recon detected (nft drop)
SRC=172.68.70.164
Observed=TCP dpt=80 in=enp0s6 ttl=56
Time=recent(journ ...
show more
๐จ Recon detected (nft drop)
SRC=172.68.70.164
Observed=TCP dpt=80 in=enp0s6 ttl=56
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐ง๐ช
madeit
2026-08-11 11:43:23
(1 month ago)
Web App Attack
๐ฉ๐ช
acadeova
2026-08-08 19:18:53
(1 month ago)
๐จ Recon detected (nft drop)
SRC=172.68.70.164
Observed=TCP dpt=80 in=enp0s6 ttl=56
Time=recent(journ ...
show more
๐จ Recon detected (nft drop)
SRC=172.68.70.164
Observed=TCP dpt=80 in=enp0s6 ttl=56
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐ณ๐ฑ
homeshowdomain.nl
2026-07-29 22:05:53
(1 month ago)
Auto-ban: >3000 req/min op 2026-07-29
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-17 00:38:56
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.70.164 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.70.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 20:38:49.542059 2026] [security2:error] [pid 19987:tid 19987] [client 172.68.70.164:13276] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.watsonstentsandevents.com"] [uri "/.env.dist"] [unique_id "ajHsmT8hcYNyrFl5ThAjgwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-09 14:47:24
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.70.164 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.70.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 10:47:19.166514 2026] [security2:error] [pid 900:tid 900] [client 172.68.70.164:11630] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "americanlegion935.com"] [uri "/.git/config"] [unique_id "af9I92Y6uZQVv5PQaAvbQQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-09 11:03:52
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.70.164 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.70.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 07:03:47.279376 2026] [security2:error] [pid 25528:tid 25528] [client 172.68.70.164:13745] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elainebroussard.com"] [uri "/.git/config"] [unique_id "af8Uk-x4XXaLT5xpFeY7gwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-04-01 11:45:00
(5 months ago)
Blocking for trying to access an exploit file: /.env.backup
Hacking
๐ซ๐ท
Yepngo
2025-12-26 01:08:50
(8 months ago)
2025-12-26T02:08:45.901475+01:00 ns3006402 kernel: [UFW BLOCK] IN=eno1 OUT= MAC=f0:79:59:6e:bf:2b:00 ...
show more
2025-12-26T02:08:45.901475+01:00 ns3006402 kernel: [UFW BLOCK] IN=eno1 OUT= MAC=f0:79:59:6e:bf:2b:00:ff:ff:ff:ff:fb:08:00 SRC=172.68.70.164 DST=151.80.47.9 LEN=60 TOS=0x00 PREC=0x00 TTL=52 ID=10527 DF PROTO=TCP SPT=11257 DPT=8443 WINDOW=65535 RES=0x00 SYN URGP=0
2025-12-26T02:08:46.926067+01:00 ns3006402 kernel: [UFW BLOCK] IN=eno1 OUT= MAC=f0:79:59:6e:bf:2b:00:ff:ff:ff:ff:fb:08:00 SRC=172.68.70.164 DST=151.80.47.9 LEN=60 TOS=0x00 PREC=0x00 TTL=52 ID=10528 DF PROTO=TCP SPT=11257 DPT=8443 WINDOW=65535 RES=0x00 SYN URGP=0
2025-12-26T02:08:47.949804+01:00 ns3006402 kernel: [UFW BLOCK] IN=eno1 OUT= MAC=f0:79:59:6e:bf:2b:00:ff:ff:ff:ff:fb:08:00 SRC=172.68.70.164 DST=151.80.47.9 LEN=60 TOS=0x00 PREC=0x00 TTL=52 ID=10529 DF PROTO=TCP SPT=11257 DPT=8443 WINDOW=65535 RES=0x00 SYN URGP=0
2025-12-26T02:08:48.973791+01:00 ns3006402 kernel: [UFW BLOCK] IN=eno1 OUT= MAC=f0:79:59:6e:bf:2b:00:ff:ff:ff:ff:fb:08:00 SRC=172.68.70.164 DST=151.80.47.9 LEN=60 TOS=0x00 PREC=0x00 TTL=52 ID=10530 DF PROTO=T
...
show less
Port Scan
๐ซ๐ท
Campus France
2025-12-16 12:21:05
(9 months ago)
[Tue Dec 16 07:42:53.462684 2025] [php:error] [pid 10910] [client 172.68.70.164:13769] script '/var/ ...
show more
[Tue Dec 16 07:42:53.462684 2025] [php:error] [pid 10910] [client 172.68.70.164:13769] script '/var/www/html/alfa-rex1.php' not found or unable to stat
[Tue Dec 16 07:42:54.677674 2025] [php:error] [pid 10910] [client 172.68.70.164:13769] script '/var/www/html/cron.php' not found or unable to stat
[Tue Dec 16 07:43:05.351663 2025] [php:error] [pid 10910] [client 172.68.70.164:13769] script '/var/www/html/sim.php' not found or unable to stat
[Tue Dec 16 13:21:05.381174 2025] [php:error] [pid 29298] [client 172.68.70.164:10073] script '/var/www/html/goods.php' not found or unable to stat
[Tue Dec 16 13:21:05.660627 2025] [php:error] [pid 29298] [client 172.68.70.164:10073] script '/var/www/html/i.php' not found or unable to stat
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
vdub144
2025-12-15 02:07:05
(9 months ago)
Automated report from Gross Automation security system. | Attack type: attack_path | Path: /searchpr ...
show more
Automated report from Gross Automation security system. | Attack type: attack_path | Path: /searchpro/form.php?mode=js&g=18&s=1&t=1 | UA: Mozilla/5.0 (Linux; Android 8.1.0; Moto G (4)) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Mobile Safari/537.36 PTST/251202.154650 | Blocked by: nginx-bot-hell
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-02 10:45:43
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.68.70.164 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.70.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 02 06:45:34.079270 2024] [security2:error] [pid 19002:tid 19002] [client 172.68.70.164:29754] [client 172.68.70.164] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "globetechsecurities.com"] [uri "/.env"] [unique_id "ZyYCzms75j6wzAdW936OHQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack