๐ง๐ท
willianfronza
2026-05-12 03:13:04
(4 months ago)
Blocked by pfSense - Protocol: tcp Port: 80
Port Scan
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 01:22:49
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.114.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.114.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 21:22:44.174972 2026] [security2:error] [pid 25778:tid 25778] [client 172.70.114.235:11314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.teenybikinigirls.com"] [uri "/backend/.env"] [unique_id "acsh5Euo5XPzw_ii3xPCrAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-29 20:15:01
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.114.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.114.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 29 16:14:55.209275 2026] [security2:error] [pid 1132:tid 1132] [client 172.70.114.235:12315] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.bostonscience.com"] [uri "/.env_settings"] [unique_id "acmIP1hP8WvoQTWj5eKy6QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 09:23:46
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.114.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.114.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 05:23:41.913759 2026] [security2:error] [pid 26821:tid 26821] [client 172.70.114.235:9234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.beirutbazar.com"] [uri "/.env.save"] [unique_id "ab0SHaicJWerkBbrS-5pjQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 07:42:29
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.114.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.114.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 03:42:22.662035 2026] [security2:error] [pid 24752:tid 24752] [client 172.70.114.235:11977] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.goatedlottosecrets.com"] [uri "/www/.env"] [unique_id "abz6Xpf2PPkS8iDzPdiGkwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 04:53:18
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.114.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.114.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 00:53:13.789694 2026] [security2:error] [pid 2973:tid 2973] [client 172.70.114.235:12154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.linguistes.com"] [uri "/private/.env"] [unique_id "abzSuUkNbcmap1RnJQk01QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 04:32:01
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.114.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.114.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 00:31:57.468185 2026] [security2:error] [pid 21246:tid 21246] [client 172.70.114.235:12674] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.printorganic.com"] [uri "/backend/.env"] [unique_id "abzNvYDNPnkYIbBXzJYFewAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 04:01:03
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.114.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.114.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 00:00:57.072996 2026] [security2:error] [pid 23354:tid 23354] [client 172.70.114.235:12640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.brunerdevelopment.littlehorndesign.com"] [uri "/config/.env.local"] [unique_id "abzGeWJz27TzBQRFfP8R7wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 01:17:21
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.114.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.114.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 21:17:12.025158 2026] [security2:error] [pid 32080:tid 32080] [client 172.70.114.235:13217] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.sideralis.mx"] [uri "/.env.production"] [unique_id "abygGG6Xei2njKE8pb7oLQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
acadeova
2026-02-23 12:09:59
(6 months ago)
๐จ Recon detected (nft drop)
SRC=172.70.114.235
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(jour ...
show more
๐จ Recon detected (nft drop)
SRC=172.70.114.235
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐บ๐ฆ
URAN Publishing Service
2026-02-12 17:05:59
(7 months ago)
172.70.114.235 - - [12/Feb/2026:19:05:58 +0200] "GET /wp-content/plugins/ioxi/ioxi/ HTTP/1.1" 404 28 ...
show more
172.70.114.235 - - [12/Feb/2026:19:05:58 +0200] "GET /wp-content/plugins/ioxi/ioxi/ HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0"
172.70.114.235 - - [12/Feb/2026:19:05:58 +0200] "GET /wp-includes/id3/ HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36"
...
show less
Web App Attack
Anonymous
2026-01-16 13:19:59
(8 months ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
Anonymous
2025-10-25 23:06:06
(10 months ago)
[Sun Oct 26 01:06:01.018943 2025] [authz_core:error] [pid 26570] [client 172.70.114.235:9501] AH0163 ...
show more
[Sun Oct 26 01:06:01.018943 2025] [authz_core:error] [pid 26570] [client 172.70.114.235:9501] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: https://www.google.com/
[Sun Oct 26 01:06:03.618462 2025] [authz_core:error] [pid 26570] [client 172.70.114.235:9501] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: https://www.google.com/
[Sun Oct 26 01:06:05.957783 2025] [authz_core:error] [pid 26570] [client 172.70.114.235:9501] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: https://www.google.com/
...
show less
Web App Attack
Anonymous
2025-09-09 04:18:24
(1 year ago)
[Tue Sep 09 06:18:23.502559 2025] [authz_core:error] [pid 3823] [client 172.70.114.235:39148] AH0163 ...
show more
[Tue Sep 09 06:18:23.502559 2025] [authz_core:error] [pid 3823] [client 172.70.114.235:39148] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Sep 09 06:18:23.666938 2025] [authz_core:error] [pid 3823] [client 172.70.114.235:39148] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Sep 09 06:18:23.826595 2025] [authz_core:error] [pid 3823] [client 172.70.114.235:39148] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐บ๐ธ
Paschen J Ki
2025-09-09 03:54:23
(1 year ago)
Blocked by UFW [8008/tcp]
Source port: 27262
TTL: 47
Packet length: 60
TOS: 0x00
This report was ge ...
show more
Blocked by UFW [8008/tcp]
Source port: 27262
TTL: 47
Packet length: 60
TOS: 0x00
This report was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan