๐ณ๐ฑ
BlueWire Hosting
2026-09-29 08:53:19
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ง๐ช
madeit
2026-09-25 22:55:06
(4 days ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-09 10:22:09
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.69.166.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.166.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 06:22:02.541039 2026] [security2:error] [pid 20432:tid 20432] [client 172.69.166.29:10298] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "smokeyspb.photos.pages4you.com"] [uri "/.env.dist"] [unique_id "aqEzSkJBG7WtBgaOy2kzSgAAAAI"], referer: https://www.google.com/search?q=smokeyspb.photos.pages4you.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-09 06:09:25
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.69.166.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.166.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 02:09:14.885433 2026] [security2:error] [pid 20271:tid 20271] [client 172.69.166.29:10547] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jefflowenstein.com"] [uri "/.env.dist"] [unique_id "aqD4CiGMqBB2Vl_7CM0xowAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-09-07 18:13:42
(3 weeks ago)
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-04 22:00:27
(3 weeks ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-17 23:28:42
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.69.166.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.166.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 19:28:35.823390 2026] [security2:error] [pid 19099:tid 19099] [client 172.69.166.29:10100] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.paulsingdahlsen.com"] [uri "/.git/HEAD"] [unique_id "aoOZI_jnuw_p3ypYuipH2wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 23:11:11
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.69.166.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.166.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 19:11:06.309099 2026] [security2:error] [pid 23463:tid 23463] [client 172.69.166.29:13247] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wp.fritsknuf.com"] [uri "/.git/config"] [unique_id "aoOVCkBTBykJZbzX_tTn3wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-17 08:41:06
(1 month ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 02:43:13
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.69.166.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.166.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 22:43:08.623392 2026] [security2:error] [pid 9475:tid 9475] [client 172.69.166.29:13441] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.capefearastro.org"] [uri "/.git/HEAD"] [unique_id "aoJ1PAMFe-sLiw7r2-PJPAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
abdubhai
2026-07-09 04:15:59
(2 months ago)
172.69.166.29 - - [09/Jul/2026:0
...
Brute-Force
๐ฉ๐ช
Blexyel
2026-07-04 16:20:07
(2 months ago)
172.69.166.29 - - [04/Jul/2026:18:20:06 +0200] "GET /wp-login.php HTTP/1.1" 404 153 "-" "-" "pingusm ...
show more
172.69.166.29 - - [04/Jul/2026:18:20:06 +0200] "GET /wp-login.php HTTP/1.1" 404 153 "-" "-" "pingusmc.org"
...
show less
Brute-Force
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-05-11 13:33:56
(4 months ago)
172.69.166.29 - - [11/May/2026:16:33:55 +0300] "GET /wp-content/languages/wp-blog-header.php HTTP/1. ...
show more
172.69.166.29 - - [11/May/2026:16:33:55 +0300] "GET /wp-content/languages/wp-blog-header.php HTTP/1.1" 404 791 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.69.166.29 - - [11/May/2026:16:33:55 +0300] "GET /wp-content/themes/panel.php HTTP/1.1" 404 791 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ฉ๐ช
acadeova
2026-04-27 17:22:38
(5 months ago)
๐จ Recon detected (nft drop)
SRC=172.69.166.29
Observed=TCP dpt=80 in=enp0s6 ttl=56
Time=recent(journ ...
show more
๐จ Recon detected (nft drop)
SRC=172.69.166.29
Observed=TCP dpt=80 in=enp0s6 ttl=56
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐บ๐ธ
mawan
2026-04-21 22:47:35
(5 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack