๐ง๐ช
madeit
2026-09-30 16:54:50
(4 days ago)
Web App Attack
๐ง๐ช
madeit
2026-09-17 07:30:40
(2 weeks ago)
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-09-10 23:52:53
(3 weeks ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐ฏ๐ต
S.O.B.A. Dev.
2026-09-03 08:39:00
(1 month ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐ง๐ช
madeit
2026-08-22 12:21:32
(1 month ago)
Web App Attack
๐ฎ๐ฉ
securejdprop
2026-08-21 05:43:39
(1 month ago)
This IP was detected by CrowdSec triggering custom/vpatch-bad-cloudflare.
Hacking
๐ง๐ช
madeit
2026-08-13 14:50:03
(1 month ago)
Web App Attack
Anonymous
2026-06-21 12:30:19
(3 months ago)
172.70.111.67 - - [21/Jun/2026:07:30:19 -0500] "GET /wp-content/admin.php HTTP/2.0" 404 78 "-" "Mozi ...
show more
172.70.111.67 - - [21/Jun/2026:07:30:19 -0500] "GET /wp-content/admin.php HTTP/2.0" 404 78 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.70.111.67 - - [21/Jun/2026:07:30:19 -0500] "GET /wp-admin/images/admin.php HTTP/2.0" 404 78 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.70.111.67 - - [21/Jun/2026:07:30:19 -0500] "GET /wp-admin/css/ HTTP/2.0" 404 78 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-17 18:58:42
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 17 14:58:36.933762 2026] [security2:error] [pid 2110608:tid 2110728] [client 172.70.111.67:9379] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "inongap.com"] [uri "/.env.test"] [unique_id "aeKC3NaKCWrwkd23XwVtewAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 07:22:22
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 03:22:14.516374 2026] [security2:error] [pid 18882:tid 18882] [client 172.70.111.67:10457] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.schoolsliaisoncommunity.net"] [uri "/.env.production.local"] [unique_id "act2JmDN6VtPOAOCKK9s8AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-03-30 22:57:03
(6 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 04:32:34
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 00:32:29.526336 2026] [security2:error] [pid 2179:tid 2179] [client 172.70.111.67:11151] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crystalshealinglights.com.my-spec.com"] [uri "/.env.tmp"] [unique_id "ab4fXdiPvsGFaeXI76VeVwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 03:16:15
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 23:16:10.332244 2026] [security2:error] [pid 3853:tid 3853] [client 172.70.111.67:12545] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "intercotrading.com"] [uri "/.env.production.local"] [unique_id "ab4NeiuGrTFWAd_SGp96QwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 01:10:35
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 21:10:31.790404 2026] [security2:error] [pid 29509:tid 29509] [client 172.70.111.67:12298] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.dawnmazur.com"] [uri "/.env.old"] [unique_id "ab3wB58QHkpWMPBAgDXebQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 00:03:55
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 20:03:47.778557 2026] [security2:error] [pid 5335:tid 5335] [client 172.70.111.67:9230] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.theuf.org"] [uri "/app/.env"] [unique_id "ab3gYxhh5JUMqTxKgcAl3AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack