๐ฌ๐ง
OptimusGO
2026-06-22 07:12:54
(1 day ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-06-22 08:12:54 UTC
Log evidence:
172.70.115.6 - - [22/Jun/2026:08:12:53 +0100] "GET / HTTP/1.1" 200 409 "-" "Go-http-client/1.1"
06/22/2026-08:12:53.555567 [**] [1:1000201:1] SCANNER: Bot-like User-Agent Detected [**] [Classification: Attempted Information Leak] [Priority: 2] {TCP} 172.70.115.6:13376 -> 185.127.18.66:80
06/22/2026-08:12:53.555567 [**] [1:2060252:1] ET INFO Go-http-client User-Agent Observed Inbound [**] [Classification: Misc activity] [Priority: 3] {TCP} 172.70.115.6:13376 -> 185.127.18.66:80
show less
Port Scan
Brute-Force
๐ฆ๐ฑ
router.al
2026-05-29 07:44:15
(3 weeks ago)
05/29/2026-07:44:14.908984 172.70.115.6 Protocol: 6 ET SCAN WordPress Scanner Performing Multiple Re ...
show more
05/29/2026-07:44:14.908984 172.70.115.6 Protocol: 6 ET SCAN WordPress Scanner Performing Multiple Requests to Windows Live Writer XML
show less
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-04-21 22:04:09
(2 months ago)
Auto-ban: >3000 req/min op 2026-04-21
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-04 06:24:17
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 02:24:13.069438 2026] [security2:error] [pid 13185:tid 13185] [client 172.70.115.6:10946] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.teenybikini.com"] [uri "/.env.production.local"] [unique_id "adCujTf4RufGiY89Z2kNDAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-30 13:26:28
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 09:26:24.691284 2026] [security2:error] [pid 12896:tid 12896] [client 172.70.115.6:11575] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.psychoatomicpower.com"] [uri "/.env.backup"] [unique_id "acp6AOPcDxd5F1V6QN68-QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 06:21:59
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 02:21:52.755669 2026] [security2:error] [pid 28572:tid 28572] [client 172.70.115.6:11064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.notimallinckrodt.com.ar"] [uri "/.env.dist"] [unique_id "abzngEiek41lxUyejdu7hgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 05:36:32
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 01:36:25.092397 2026] [security2:error] [pid 5659:tid 5659] [client 172.70.115.6:11036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.globalweb123.com"] [uri "/.envrc"] [unique_id "abzc2SGwGZTLwMiFMCwLjwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 04:27:06
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 00:26:58.527580 2026] [security2:error] [pid 28353:tid 28353] [client 172.70.115.6:14145] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.sundancepei.com"] [uri "/api/.env"] [unique_id "abzMkmk16V5c1gPyrwi4-gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 02:13:12
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 22:13:07.464974 2026] [security2:error] [pid 31189:tid 31189] [client 172.70.115.6:9825] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thefleetnetwork.com.thesweetfam.com"] [uri "/.env.staging"] [unique_id "abytM-5nC1pcki0M9_0qHQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 01:17:03
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 21:16:51.810226 2026] [security2:error] [pid 31830:tid 31830] [client 172.70.115.6:10863] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "willowriver3.com"] [uri "/.env2"] [unique_id "abygA2LNUdn0YsdeZq0GMQAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bitpanda
2025-04-21 00:01:11
(1 year ago)
Malicious activity detected by Imunify360
Brute-Force
SSH
๐บ๐ธ
HJ5Ss4Ju
2025-04-08 07:17:56
(1 year ago)
WordPress XMLRPC scan :: 172.70.115.6 - - [08/Apr/2025:07:17:56 0000] "GET /xmlrpc.php HTTP/1.1" 40 ...
show more
WordPress XMLRPC scan :: 172.70.115.6 - - [08/Apr/2025:07:17:56 0000] "GET /xmlrpc.php HTTP/1.1" 405 53 "http://[censored_1]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 Edg/126.0.0.0"
show less
Hacking
Brute-Force
Web App Attack
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-03-22 01:32:35
(1 year ago)
Port probe to tcp/80 (http)
[srv125]
Port Scan
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-02-27 11:24:47
(1 year ago)
Port probe to tcp/443 (https)
[srv125]
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-02-27 06:56:06
(1 year ago)
[Thu Feb 27 07:55:44.789737 2025] [authz_core:error] [pid 18510] [client 172.70.115.6:25516] AH01630 ...
show more
[Thu Feb 27 07:55:44.789737 2025] [authz_core:error] [pid 18510] [client 172.70.115.6:25516] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu Feb 27 07:56:05.677226 2025] [authz_core:error] [pid 18546] [client 172.70.115.6:52250] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu Feb 27 07:56:05.855265 2025] [authz_core:error] [pid 18546] [client 172.70.115.6:52250] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack