๐บ๐ฆ
URAN Publishing Service
2026-07-26 05:56:05
(2 days ago)
172.69.130.104 - - [26/Jul/2026:08:56:04 +0300] "GET /wp-includes/theme-compat/wp-login.php HTTP/1.1 ...
show more
172.69.130.104 - - [26/Jul/2026:08:56:04 +0300] "GET /wp-includes/theme-compat/wp-login.php HTTP/1.1" 404 789 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.69.130.104 - - [26/Jul/2026:08:56:05 +0300] "GET /wp-content/plugins/module.php HTTP/1.1" 404 789 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-07-08 22:52:05
(2 weeks ago)
172.69.130.104 - - [09/Jul/2026:01:52:05 +0300] "GET /cgi-bin/ HTTP/1.1" 404 561 "-" "Mozilla/5.0 (W ...
show more
172.69.130.104 - - [09/Jul/2026:01:52:05 +0300] "GET /cgi-bin/ HTTP/1.1" 404 561 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.69.130.104 - - [09/Jul/2026:01:52:05 +0300] "GET /wp-content/themes/ HTTP/1.1" 404 789 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-06-26 09:07:35
(1 month ago)
172.69.130.104 - - [26/Jun/2026:12:07:33 +0300] "GET /wp-content/uploads/index.php HTTP/1.1" 404 789 ...
show more
172.69.130.104 - - [26/Jun/2026:12:07:33 +0300] "GET /wp-content/uploads/index.php HTTP/1.1" 404 789 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.69.130.104 - - [26/Jun/2026:12:07:35 +0300] "GET /wp-admin/user.php HTTP/1.1" 404 789 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-10 22:02:02
(1 month ago)
Auto-ban: >3000 req/min op 2026-06-10
Web App Attack
SSH
Hacking
๐บ๐ฆ
URAN Publishing Service
2026-05-12 20:01:33
(2 months ago)
172.69.130.104 - - [12/May/2026:23:01:32 +0300] "GET /wp-content/plugins/dummyyummy/wp-signup.php HT ...
show more
172.69.130.104 - - [12/May/2026:23:01:32 +0300] "GET /wp-content/plugins/dummyyummy/wp-signup.php HTTP/1.1" 404 3342 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.69.130.104 - - [12/May/2026:23:01:33 +0300] "GET /wp-content/themes/twentytwenty/404.php HTTP/1.1" 404 783 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-05-04 00:36:48
(2 months ago)
172.69.130.104 - - [04/May/2026:03:36:47 +0300] "GET /wp-admin/maint/about.php HTTP/1.1" 404 789 "-" ...
show more
172.69.130.104 - - [04/May/2026:03:36:47 +0300] "GET /wp-admin/maint/about.php HTTP/1.1" 404 789 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.69.130.104 - - [04/May/2026:03:36:48 +0300] "GET /wp-admin/network/wp-conflg.php?p= HTTP/1.1" 404 789 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 06:14:46
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 02:14:41.335983 2026] [security2:error] [pid 2585739:tid 2585739] [client 172.69.130.104:10494] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.scaleiq.group"] [uri "/.env.backup"] [unique_id "adXyUUi1NjQZVFiwul7QkwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 10:44:40
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 06:44:27.446881 2026] [security2:error] [pid 1198796:tid 1198796] [client 172.69.130.104:10348] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.jspd.com"] [uri "/.env"] [unique_id "adTgC4LGOBa3xYTjnmkziAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 21:42:52
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 17:42:45.913154 2026] [security2:error] [pid 403826:tid 403826] [client 172.69.130.104:12631] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.punctuminteractive.com"] [uri "/.env.dist"] [unique_id "adQo1QVUGEFFGHiWjhDFogAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 18:48:11
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 14:48:08.165289 2026] [security2:error] [pid 722187:tid 722187] [client 172.69.130.104:12899] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.somewierdness.com"] [uri "/.env.old"] [unique_id "adP_6CSol0RVazFaWVByRQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 15:17:49
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 11:17:45.966056 2026] [security2:error] [pid 266761:tid 266761] [client 172.69.130.104:11799] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.davisound.com"] [uri "/.env.dev"] [unique_id "adPOmX2o2VfKGl9qeJZvBwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 20:29:07
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 16:28:59.488269 2026] [security2:error] [pid 17200:tid 17200] [client 172.69.130.104:12181] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.markrudin.com"] [uri "/.env.bak"] [unique_id "adLGC20zSGkCtlXzq96c4QAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 20:07:59
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 16:07:52.467365 2026] [security2:error] [pid 24791:tid 24791] [client 172.69.130.104:14266] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.redcranemgt.com"] [uri "/.env.local"] [unique_id "adLBGFISQkbH8HPX5fmg4AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 15:25:34
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 11:25:25.622300 2026] [security2:error] [pid 3954:tid 3954] [client 172.69.130.104:12630] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kvaziri.com"] [uri "/.env.bak"] [unique_id "adJ-5VOBV9hyX0cm8M4oUwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 23:37:49
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 19:37:39.723929 2026] [security2:error] [pid 18177:tid 18177] [client 172.69.130.104:10058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mycouchwriting.com"] [uri "/.env"] [unique_id "adGgw2-TvFeGkh526e2kDgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack