Anonymous
2026-06-09 12:37:43
(3 days ago)
172.70.100.236 - - [09/Jun/2026:14:37:32 +0200] "GET /wp-content/plugins/hellopress/wp_filemanager.p ...
show more
172.70.100.236 - - [09/Jun/2026:14:37:32 +0200] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 404 440 "-" "-"
172.70.100.236 - - [09/Jun/2026:14:37:32 +0200] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 404 247 "-" "-"
172.70.100.236 - - [09/Jun/2026:14:37:34 +0200] "GET /this_is_a_new_hello_world.php HTTP/1.1" 404 440 "-" "-"
172.70.100.236 - - [09/Jun/2026:14:37:34 +0200] "GET /this_is_a_new_hello_world.php HTTP/1.1" 404 247 "-" "-"
172.70.100.236 - - [09/Jun/2026:14:37:34 +0200] "GET /ff.php HTTP/1.1" 404 440 "-" "-"
172.70.100.236 - - [09/Jun/2026:14:37:34 +0200] "GET /ff.php HTTP/1.1" 404 247 "-" "-"
172.70.100.236 - - [09/Jun/2026:14:37:34 +0200] "GET /tires.php HTTP/1.1" 404 440 "-" "-"
172.70.100.236 - - [09/Jun/2026:14:37:34 +0200] "GET /tires.php HTTP/1.1" 404 247 "-" "-"
172.70.100.236 - - [09/Jun/2026:14:37:34 +0200] "GET /wp-block.php HTTP/1.1" 404 440 "-" "-"
172.70.100.236 - - [09/Jun/2026:14:37:34 +0200] "GET /wp-block.php HTTP/1.1
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-05-11 09:07:25
(1 month ago)
172.70.100.236 - - [11/May/2026:02:07:24 -0700] "GET /template/css/style.css HTTP/1.1" 200 50771 "ht ...
show more
172.70.100.236 - - [11/May/2026:02:07:24 -0700] "GET /template/css/style.css HTTP/1.1" 200 50771 "https://northcoastagency.ltcglobal.com/login" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Googlebot/2.1; +http://www.google.com/bot.html) Chrome/147.0.7727.116 Safari/537.36"
...
show less
Brute-Force
SSH
Anonymous
2026-03-29 16:09:49
(2 months ago)
invalid request
Bad Web Bot
Web App Attack
๐บ๐ธ
threatintelligence_bvc
2026-03-01 12:05:04
(3 months ago)
Brute-Force
๐ง๐ท
leolemos
2026-01-02 22:11:43
(5 months ago)
[Fri Jan 02 19:11:41.050142 2026] [proxy_fcgi:error] [pid 2373495] [client 172.70.100.236:12689] AH0 ...
show more
[Fri Jan 02 19:11:41.050142 2026] [proxy_fcgi:error] [pid 2373495] [client 172.70.100.236:12689] AH01071: Got error 'Primary script unknown', referer: http://web[redacted].[redacted]/cord.php
[Fri Jan 02 19:11:42.169903 2026] [proxy_fcgi:error] [pid 2373495] [client 172.70.100.236:12689] AH01071: Got error 'Primary script unknown', referer: http://web[redacted].[redacted]/dex.php
[Fri Jan 02 19:11:42.356027 2026] [proxy_fcgi:error] [pid 2373495] [client 172.70.100.236:12689] AH01071: Got error 'Primary script unknown', referer: http://web[redacted].[redacted]/file2.php#tabFM
show less
Brute-Force
Web App Attack
๐ซ๐ท
Kurom
2025-12-19 15:23:00
(5 months ago)
Port scanning detected on company server. Targeted ports: [8080]
Port Scan
Hacking
Anonymous
2025-12-10 03:55:02
(6 months ago)
[Wed Dec 10 04:54:49.724333 2025] [authz_core:error] [pid 26947] [client 172.70.100.236:10906] AH016 ...
show more
[Wed Dec 10 04:54:49.724333 2025] [authz_core:error] [pid 26947] [client 172.70.100.236:10906] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Wed Dec 10 04:54:54.577352 2025] [authz_core:error] [pid 26947] [client 172.70.100.236:10906] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Wed Dec 10 04:55:01.704743 2025] [authz_core:error] [pid 14267] [client 172.70.100.236:10393] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-01 11:01:53
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.70.100.236 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.100.236 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 01 07:01:46.804605 2025] [security2:error] [pid 2128038:tid 2128038] [client 172.70.100.236:41326] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.therapistworkshops.com"] [uri "/.git/config"] [unique_id "aDwzGtpds6JG9P4qxTpEAwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2025-05-22 00:53:30
(1 year ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-05-05 17:00:41
(1 year ago)
Port probe to tcp/443 (https)
[srv125]
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-19 00:16:49
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.70.100.236 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.100.236 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 18 20:16:40.952351 2025] [security2:error] [pid 1256903:tid 1256903] [client 172.70.100.236:48556] [client 172.70.100.236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.harry18.cc"] [uri "/.git/"] [unique_id "aALraHX95WwUkAzoZmwzRgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-04-15 15:22:44
(1 year ago)
Port probe to tcp/443 (https)
[srv125]
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-04-05 08:54:37
(1 year ago)
Port probe to tcp/80 (http)
[srv125]
Port Scan
Bad Web Bot
Web App Attack
๐ฆ๐บ
oncord
2025-03-07 18:56:37
(1 year ago)
Form spam
Web Spam
๐ฆ๐บ
oncord
2025-01-12 16:11:41
(1 year ago)
Form spam
Web Spam