๐บ๐ธ
TPI-Abuse
2026-07-28 23:16:38
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.69.70.92 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.70.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 19:16:23.500713 2026] [security2:error] [pid 2834651:tid 2834651] [client 172.69.70.92:14226] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "internationalavionics.com"] [uri "/.git/config"] [unique_id "amk4R10B-i5mCXOfqY9nMgAAABY"], referer: https://www.google.com/search?q=internationalavionics.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-28 22:01:18
(13 hours ago)
Auto-ban: >3000 req/min op 2026-07-28
Web App Attack
SSH
Hacking
๐ฉ๐ช
NihiliousMonk
2026-07-28 21:16:07
(14 hours ago)
Fail2Ban report from jail npm-scanners
Bad Web Bot
Web App Attack
Anonymous
2026-07-23 17:51:10
(5 days ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-09 16:06:10
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.70.92 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.70.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 12:06:03.526939 2026] [security2:error] [pid 32655:tid 32655] [client 172.69.70.92:10941] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "paleopathologist.com"] [uri "/.git/config"] [unique_id "af9ba34SVQnJtUcFmCpPggAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-03-29 20:51:22
(3 months ago)
172.69.70.92 - - [29/Mar/2026:23:51:21 +0300] "GET /backend/.env HTTP/1.1" 404 299 "-" "-"
...
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-03-29 15:53:26
(3 months ago)
172.69.70.92 - - [29/Mar/2026:18:53:20 +0300] "GET /wp-content/themes/about.php HTTP/1.1" 404 196 "- ...
show more
172.69.70.92 - - [29/Mar/2026:18:53:20 +0300] "GET /wp-content/themes/about.php HTTP/1.1" 404 196 "-" "-"
172.69.70.92 - - [29/Mar/2026:18:53:24 +0300] "GET /wp-includes/Requests/Text/admin.php HTTP/1.1" 404 196 "-" "-"
...
show less
Web App Attack
๐บ๐ธ
myagent.site
2026-03-19 23:10:02
(4 months ago)
Blocking for trying to access an exploit file: /.env.container
Hacking
Anonymous
2025-12-10 21:04:47
(7 months ago)
[Wed Dec 10 22:04:45.253720 2025] [authz_core:error] [pid 19475] [client 172.69.70.92:10772] AH01630 ...
show more
[Wed Dec 10 22:04:45.253720 2025] [authz_core:error] [pid 19475] [client 172.69.70.92:10772] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: https://www.google.fr/
[Wed Dec 10 22:04:45.540613 2025] [authz_core:error] [pid 19475] [client 172.69.70.92:10772] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: https://www.google.com/
[Wed Dec 10 22:04:46.362731 2025] [authz_core:error] [pid 19475] [client 172.69.70.92:10772] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: https://www.google.de/
...
show less
Web App Attack
๐ฌ๐ง
pinguin
2025-12-09 16:52:59
(7 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 (compatible; CMS-Checker/1.0; +https://example.com)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฌ๐ง
no1knows.com
2025-09-10 09:42:40
(10 months ago)
2025/09/10 10:42:38 [error] 1618050#1618050: *723462 FastCGI sent in stderr: "Primary script unknown ...
show more
2025/09/10 10:42:38 [error] 1618050#1618050: *723462 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 172.69.70.92, server: _, request: "GET /.well-known/acme-challenge/install.php HTTP/1.1", upstream: "fastcgi://unix:/run/php-fpm/www.sock:", host: "no1knows.com"
2025/09/10 10:42:38 [error] 1618050#1618050: *723462 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 172.69.70.92, server: _, request: "GET /.well-known/acme-challenge/plugins.php HTTP/1.1", upstream: "fastcgi://unix:/run/php-fpm/www.sock:", host: "no1knows.com"
2025/09/10 10:42:38 [error] 1618050#1618050: *723462 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 172.69.70.92, server: _, request: "GET /.well-known/acme-challenge/license.php HTTP/1.1", upstream: "fastcgi://unix:/run/php-fpm/www.sock:", host: "no1knows.com"
...
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
thefoofighter
2025-07-20 06:42:48
(1 year ago)
[Sun Jul 20 06:42:47.836132 2025] [:error] [pid 562124] [client 172.69.70.92:62256] [client 172.69.7 ...
show more
[Sun Jul 20 06:42:47.836132 2025] [:error] [pid 562124] [client 172.69.70.92:62256] [client 172.69.70.92] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "93"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.cathalmcnally.com"] [uri "/core/.env"] [unique_id "aHyP58OtVa4QcpVKA9EbSQAAAAY"]
[Sun Jul 20 06:42:48.089196 2025] [:error] [pid 562124] [client 172.69.70.92:62256] [client 172.69.70.92] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "93"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3
...
show less
Bad Web Bot
Web App Attack
Anonymous
2025-05-16 06:50:52
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-01-24 06:02:33
(1 year ago)
Port probe to tcp/443 (https)
[srv130]
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-19 00:42:15
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.69.70.92 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.70.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 18 20:42:12.408456 2024] [security2:error] [pid 32141:tid 32141] [client 172.69.70.92:38106] [client 172.69.70.92] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ndanetworks.com"] [uri "/.env"] [unique_id "ZsKU5MAxRib6iUjmxCRqygAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack