๐ณ๐ฑ
wolfemium
2026-06-13 21:39:55
(1 day ago)
172.69.130.234 - - [14/Jun/2026:00:39:51 +0300] "GET /geforce.php HTTP/1.1" 502 150 "-" "-"
172.69.1 ...
show more
172.69.130.234 - - [14/Jun/2026:00:39:51 +0300] "GET /geforce.php HTTP/1.1" 502 150 "-" "-"
172.69.130.234 - - [14/Jun/2026:00:39:52 +0300] "GET /info2.php HTTP/1.1" 502 150 "-" "-"
172.69.130.234 - - [14/Jun/2026:00:39:52 +0300] "GET /olik.php HTTP/1.1" 502 150 "-" "-"
172.69.130.234 - - [14/Jun/2026:00:39:53 +0300] "GET /simple.php HTTP/1.1" 502 150 "-" "-"
172.69.130.234 - - [14/Jun/2026:00:39:54 +0300] "GET /img.php HTTP/1.1" 502 150 "-" "-"
172.69.130.234 - - [14/Jun/2026:00:39:54 +0300] "GET /drykl.php HTTP/1.1" 502 150 "-" "-"
...
show less
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 17:18:13
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 172.69.130.234 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.69.130.234 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 13:18:09.099159 2026] [security2:error] [pid 23211:tid 23211] [client 172.69.130.234:11636] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.compmansys.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.compmansys.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "aimcUYk_ObjQ9QV1bLxMTAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
wolfemium
2026-05-31 23:36:23
(2 weeks ago)
172.69.130.234 - - [01/Jun/2026:02:36:05 +0300] "GET /wp-content/plugins/hellopress/wp_filemanager.p ...
show more
172.69.130.234 - - [01/Jun/2026:02:36:05 +0300] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 502 150 "-" "-"
172.69.130.234 - - [01/Jun/2026:02:36:06 +0300] "GET /xmrlpc.php HTTP/1.1" 502 150 "-" "-"
172.69.130.234 - - [01/Jun/2026:02:36:06 +0300] "GET /bb.php HTTP/1.1" 502 150 "-" "-"
172.69.130.234 - - [01/Jun/2026:02:36:21 +0300] "GET /test1.php HTTP/1.1" 502 150 "-" "-"
172.69.130.234 - - [01/Jun/2026:02:36:22 +0300] "GET /wp-mail.php HTTP/1.1" 502 150 "-" "-"
172.69.130.234 - - [01/Jun/2026:02:36:22 +0300] "GET /wp.php HTTP/1.1" 502 150 "-" "-"
...
show less
DDoS Attack
Anonymous
2026-05-27 03:49:44
(2 weeks ago)
Web App Attack
Brute-Force
Web App Attack
๐ณ๐ฑ
wolfemium
2026-05-19 22:22:10
(3 weeks ago)
172.69.130.234 - - [20/May/2026:01:22:09 +0300] "GET /wp-admin/wp.php HTTP/1.1" 502 150 "-" "-"
172. ...
show more
172.69.130.234 - - [20/May/2026:01:22:09 +0300] "GET /wp-admin/wp.php HTTP/1.1" 502 150 "-" "-"
172.69.130.234 - - [20/May/2026:01:22:10 +0300] "GET /aa.php HTTP/1.1" 502 150 "-" "-"
172.69.130.234 - - [20/May/2026:01:22:10 +0300] "GET /bolt.php HTTP/1.1" 502 150 "-" "-"
172.69.130.234 - - [20/May/2026:01:22:10 +0300] "GET /bthil.php HTTP/1.1" 502 150 "-" "-"
172.69.130.234 - - [20/May/2026:01:22:10 +0300] "GET /x.php HTTP/1.1" 502 150 "-" "-"
172.69.130.234 - - [20/May/2026:01:22:10 +0300] "GET /index/function.php HTTP/1.1" 502 150 "-" "-"
...
show less
DDoS Attack
Anonymous
2026-05-12 14:28:21
(1 month ago)
Web App Attack
Brute-Force
Web App Attack
๐ณ๐ฑ
wolfemium
2026-05-06 14:59:29
(1 month ago)
172.69.130.234 - - [06/May/2026:17:59:28 +0300] "GET /atx.php HTTP/1.1" 502 150 "-" "-"
172.69.130.2 ...
show more
172.69.130.234 - - [06/May/2026:17:59:28 +0300] "GET /atx.php HTTP/1.1" 502 150 "-" "-"
172.69.130.234 - - [06/May/2026:17:59:28 +0300] "GET /z60.php HTTP/1.1" 502 150 "-" "-"
172.69.130.234 - - [06/May/2026:17:59:28 +0300] "GET /403.php HTTP/1.1" 502 150 "-" "-"
172.69.130.234 - - [06/May/2026:17:59:29 +0300] "GET /m.php HTTP/1.1" 502 150 "-" "-"
172.69.130.234 - - [06/May/2026:17:59:29 +0300] "GET /themes.php HTTP/1.1" 502 150 "-" "-"
172.69.130.234 - - [06/May/2026:17:59:29 +0300] "GET /wp-admin/maint/about.php HTTP/1.1" 502 150 "-" "-"
...
show less
DDoS Attack
๐ฉ๐ช
msdong
2026-05-02 17:11:21
(1 month ago)
Automated report from NPM Security UI. Total attacks: 3. Attack types: Env Access: 3. First seen: 02 ...
show more
Automated report from NPM Security UI. Total attacks: 3. Attack types: Env Access: 3. First seen: 02/May/2026:06:27:50. Last seen: 02/May/2026:06:27:48.
show less
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-04-25 16:18:32
(1 month ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐บ๐ธ
TPI-Abuse
2026-04-07 01:29:30
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.234 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.234 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 21:29:24.856480 2026] [security2:error] [pid 570689:tid 570689] [client 172.69.130.234:12909] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amgsurfaces.com.38floorsupply.com"] [uri "/private/.env"] [unique_id "adRd9PMLvZmTAZl8JRyp_AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-04-06 21:29:01
(2 months ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐บ๐ธ
TPI-Abuse
2026-04-06 00:18:37
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.234 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.234 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 20:18:29.910789 2026] [security2:error] [pid 17318:tid 17318] [client 172.69.130.234:11504] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.nomanszone.com.nomanszone.org"] [uri "/.env.local"] [unique_id "adL71dVuGKYpPVG1pWSwtQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 19:12:20
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.234 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.234 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 15:12:16.581296 2026] [security2:error] [pid 9708:tid 9708] [client 172.69.130.234:10795] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "equipoperu.org"] [uri "/.env2"] [unique_id "adK0EEs8IdU-3DYuOX4KaAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 17:01:04
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.234 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.234 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 13:00:57.005709 2026] [security2:error] [pid 5611:tid 5611] [client 172.69.130.234:10770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.seiganji.ichi51e.net"] [uri "/.env.production"] [unique_id "adKVSYRP6g9josDTAmDIbQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 06:58:51
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.234 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.234 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 02:58:42.343749 2026] [security2:error] [pid 16382:tid 16382] [client 172.69.130.234:11098] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.artspacecleveland.org"] [uri "/.env.bak"] [unique_id "adIIIjxYLkxv5zxW9rfsYwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack