๐ง๐ช
madeit
2026-08-25 20:20:36
(6 hours ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-08 01:30:26
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 172.70.115.125 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.115.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 07 21:30:20.062841 2026] [security2:error] [pid 21377:tid 21377] [client 172.70.115.125:44165] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kln.ne.jp|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kln.ne.jp"] [uri "/jehovah/debug.log"] [unique_id "ak2oLFxdWli4spL-KZ5g5gAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Campus France
2026-04-20 14:45:09
(4 months ago)
[Mon Apr 20 16:44:55.502635 2026] [php:error] [pid 641000] [client 172.70.115.125:11125] script '/va ...
show more
[Mon Apr 20 16:44:55.502635 2026] [php:error] [pid 641000] [client 172.70.115.125:11125] script '/var/www/html/leaf.php' not found or unable to stat
[Mon Apr 20 16:44:55.641853 2026] [php:error] [pid 641000] [client 172.70.115.125:11125] script '/var/www/html/grsiuk.php' not found or unable to stat
[Mon Apr 20 16:44:56.012147 2026] [php:error] [pid 641000] [client 172.70.115.125:11125] script '/var/www/html/fs.php' not found or unable to stat
[Mon Apr 20 16:45:07.850099 2026] [php:error] [pid 644150] [client 172.70.115.125:11571] script '/var/www/html/wp-Blogs.php' not found or unable to stat
[Mon Apr 20 16:45:08.275178 2026] [php:error] [pid 644150] [client 172.70.115.125:11571] script '/var/www/html/ws83.php' not found or unable to stat
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-30 16:40:35
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.125 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 12:40:30.214100 2026] [security2:error] [pid 30258:tid 30258] [client 172.70.115.125:13007] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.whaletailpuckerbutt.com"] [uri "/docker/.env.local"] [unique_id "acqnflId7W8lMjTvSL987QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 07:41:34
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.125 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 03:41:23.291233 2026] [security2:error] [pid 27223:tid 27223] [client 172.70.115.125:12142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.goatedlottosecrets.com"] [uri "/backend/.env"] [unique_id "abz6I6zm8IKi_WrNdetVnAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 04:06:09
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.125 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 00:06:02.879665 2026] [security2:error] [pid 3985:tid 4064] [client 172.70.115.125:12993] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.cspmedia.com"] [uri "/.env.dist"] [unique_id "abzHqmwtECI3TSJa-CIItwAAAFA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 02:42:48
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.125 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 22:42:40.631836 2026] [security2:error] [pid 20773:tid 20773] [client 172.70.115.125:12401] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.wwts.io"] [uri "/home/.env"] [unique_id "aby0ILa8KuVzsVERgQfjwAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 01:06:29
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.125 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 21:05:52.862818 2026] [security2:error] [pid 31559:tid 31559] [client 172.70.115.125:11502] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.disabilitydespair.com"] [uri "/server/.env"] [unique_id "abydcOcuPubE_bpA1ifg5wAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 00:34:48
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.125 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 20:34:43.975430 2026] [security2:error] [pid 9060:tid 9060] [client 172.70.115.125:12269] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.musiclips4spotify.com"] [uri "/.env_settings"] [unique_id "abyWI8OpSuarHL6sKmksHgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-03-02 13:18:18
(5 months ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
Anonymous
2025-10-25 05:52:46
(10 months ago)
[Sat Oct 25 07:52:42.994859 2025] [authz_core:error] [pid 18788] [client 172.70.115.125:9975] AH0163 ...
show more
[Sat Oct 25 07:52:42.994859 2025] [authz_core:error] [pid 18788] [client 172.70.115.125:9975] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sat Oct 25 07:52:44.407587 2025] [authz_core:error] [pid 18788] [client 172.70.115.125:9975] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sat Oct 25 07:52:45.296045 2025] [authz_core:error] [pid 18788] [client 172.70.115.125:9975] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐บ๐ธ
HJ5Ss4Ju
2025-09-03 16:04:23
(11 months ago)
WordPress XMLRPC scan :: 172.70.115.125 - - [03/Sep/2025:16:04:23 0000] "POST /xmlrpc.php HTTP/1.1" ...
show more
WordPress XMLRPC scan :: 172.70.115.125 - - [03/Sep/2025:16:04:23 0000] "POST /xmlrpc.php HTTP/1.1" 503 18967 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
HJ5Ss4Ju
2025-08-26 07:06:39
(11 months ago)
WordPress XMLRPC scan :: 172.70.115.125 - - [26/Aug/2025:07:06:38 0000] "GET /xmlrpc.php HTTP/1.1" ...
show more
WordPress XMLRPC scan :: 172.70.115.125 - - [26/Aug/2025:07:06:38 0000] "GET /xmlrpc.php HTTP/1.1" 405 53 "http://[censored_1]" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 Edg/126.0.0.0"
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
HJ5Ss4Ju
2025-08-17 18:55:10
(1 year ago)
WordPress XMLRPC scan :: 172.70.115.125 - - [17/Aug/2025:18:55:09 0000] "GET /xmlrpc.php?rsd HTTP/1 ...
show more
WordPress XMLRPC scan :: 172.70.115.125 - - [17/Aug/2025:18:55:09 0000] "GET /xmlrpc.php?rsd HTTP/1.1" 200 322 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36"
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
HJ5Ss4Ju
2025-08-16 13:10:27
(1 year ago)
WordPress XMLRPC scan :: 172.70.115.125 - - [16/Aug/2025:13:10:26 0000] "GET /xmlrpc.php HTTP/1.1" ...
show more
WordPress XMLRPC scan :: 172.70.115.125 - - [16/Aug/2025:13:10:26 0000] "GET /xmlrpc.php HTTP/1.1" 405 53 "http://[censored_1]" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.5790.102 Safari/537.36"
show less
Hacking
Brute-Force
Web App Attack