πΊπΈ
TPI-Abuse
2026-07-15 09:18:43
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.127.239 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.127.239 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 05:18:34.391629 2026] [security2:error] [pid 19555:tid 19555] [client 172.70.127.239:12365] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gemexpressions.com"] [uri "/.env.test"] [unique_id "aldQauFft5FnJFkmaKMtWwAAAC8"], referer: https://www.google.com/search?q=gemexpressions.com
show less
Brute-Force
Bad Web Bot
Web App Attack
π―π΅
S.O.B.A. Dev.
2026-07-07 12:19:43
(2 weeks ago)
Persistent port scanning or vulnerability scanning
Port Scan
π―π΅
Kinsei Engineering Inc.
2026-06-13 10:50:11
(1 month ago)
UFW:High-frequency access to unused ports
Port Scan
π«π·
tavis.page
2026-05-18 04:38:18
(2 months ago)
Blocked by UFW on server [443/tcp]
Source port: 9910
TTL: 53
Packet length: 60
TOS: 0x00
This repor ...
show more
Blocked by UFW on server [443/tcp]
Source port: 9910
TTL: 53
Packet length: 60
TOS: 0x00
This report was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
π³π±
wolfemium
2026-05-12 12:48:42
(2 months ago)
172.70.127.239 - - [12/May/2026:15:48:28 +0300] "GET /wp-blog.php HTTP/1.1" 502 150 "-" "-"
172.70.1 ...
show more
172.70.127.239 - - [12/May/2026:15:48:28 +0300] "GET /wp-blog.php HTTP/1.1" 502 150 "-" "-"
172.70.127.239 - - [12/May/2026:15:48:41 +0300] "GET //admin.php HTTP/1.1" 502 150 "-" "-"
172.70.127.239 - - [12/May/2026:15:48:41 +0300] "GET /w2025.php HTTP/1.1" 502 150 "-" "-"
172.70.127.239 - - [12/May/2026:15:48:41 +0300] "GET /fvvff.php HTTP/1.1" 502 150 "-" "-"
172.70.127.239 - - [12/May/2026:15:48:41 +0300] "GET //edit.php HTTP/1.1" 502 150 "-" "-"
172.70.127.239 - - [12/May/2026:15:48:42 +0300] "GET /admin.php HTTP/1.1" 502 150 "-" "-"
...
show less
DDoS Attack
π―π΅
S.O.B.A. Dev.
2026-04-08 17:25:20
(3 months ago)
Persistent port scanning or vulnerability scanning
Port Scan
Anonymous
2026-03-26 17:52:26
(3 months ago)
172.70.127.239 - - [26/Mar/2026:19:51:50 +0200] "GET /.well-known/acme-challenge/cloud.php/wp-conten ...
show more
172.70.127.239 - - [26/Mar/2026:19:51:50 +0200] "GET /.well-known/acme-challenge/cloud.php/wp-content/themes/finley/expect.php HTTP/1.1" 404 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
172.70.127.239 - - [26/Mar/2026:19:51:51 +0200] "GET /.well-known/acme-challenge/cloud.php/wp-content/themes/finley/acme-challengeclass.api.php HTTP/1.1" 404 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
172.70.127.239 - - [26/Mar/2026:19:51:51 +0200] "GET /.well-known/acme-challenge/cloud.php/wp-content/themes/finley/certificatesmoon.php HTTP/1.1" 404 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
172.70.127.239 - - [26/Mar/2026:19:51:52 +0200] "GET /.well-known/acme-challenge/cloud.php/wp-content/themes/finley/ID3license.php HTTP/1.1" 404 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
172.70.127.239 - - [26/Mar/2026:19:51:52 +0200] "GET /.well-known/acme-challenge/cloud.php/wp-content/themes/finley/IXRcu
...
show less
Brute-Force
Web App Attack
π©πͺ
mattk
2026-01-21 04:52:02
(6 months ago)
port scan
Port Scan
πΊπΈ
mawan
2025-11-30 18:33:00
(7 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
Anonymous
2025-10-24 11:12:23
(9 months ago)
[Fri Oct 24 13:12:19.193607 2025] [authz_core:error] [pid 26964] [client 172.70.127.239:12621] AH016 ...
show more
[Fri Oct 24 13:12:19.193607 2025] [authz_core:error] [pid 26964] [client 172.70.127.239:12621] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri Oct 24 13:12:21.306897 2025] [authz_core:error] [pid 26964] [client 172.70.127.239:12621] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri Oct 24 13:12:22.337899 2025] [authz_core:error] [pid 26964] [client 172.70.127.239:12621] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
Anonymous
2025-10-23 18:15:52
(9 months ago)
[Thu Oct 23 20:15:47.659941 2025] [authz_core:error] [pid 4435] [client 172.70.127.239:12786] AH0163 ...
show more
[Thu Oct 23 20:15:47.659941 2025] [authz_core:error] [pid 4435] [client 172.70.127.239:12786] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu Oct 23 20:15:49.912759 2025] [authz_core:error] [pid 4435] [client 172.70.127.239:12786] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu Oct 23 20:15:51.664246 2025] [authz_core:error] [pid 4435] [client 172.70.127.239:12786] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
πͺπΈ
Hugopvigo
2025-06-01 16:19:15
(1 year ago)
172.70.127.239 - - [01/Jun/2025:07:46:19 +0200] "GET /es/producto/malawi-5-gb-30-dias/?add-to-cart=8 ...
show more
172.70.127.239 - - [01/Jun/2025:07:46:19 +0200] "GET /es/producto/malawi-5-gb-30-dias/?add-to-cart=869 HTTP/1.1" 302 5044 "-" "Scrapy/2.11.2 (+https://scrapy.org)"
172.70.127.239 - - [01/Jun/2025:07:46:26 +0200] "GET /es/producto/malta-5-gb-30-dias/?add-to-cart=870 HTTP/1.1" 302 1185 "-" "Scrapy/2.11.2 (+https://scrapy.org)"
172.70.127.239 - - [01/Jun/2025:07:46:35 +0200] "GET /es/producto/marigalante-20-gb-30-dias/?add-to-cart=884 HTTP/1.1" 302 1185 "-" "Scrapy/2.11.2 (+https://scrapy.org)"
172.70.127.239 - - [01/Jun/2025:07:46:43 +0200] "GET /es/producto/martinica-20-gb-30-dias/?add-to-cart=887 HTTP/1.1" 302 1185 "-" "Scrapy/2.11.2 (+https://scrapy.org)"
...
show less
Hacking
Brute-Force
Web App Attack
SSH
π³π±
Study Bitcoin π€
2025-05-13 15:26:50
(1 year ago)
Port probe to tcp/443 (https)
[srv125]
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
oncord
2025-03-09 17:21:10
(1 year ago)
Form spam
Web Spam
π³π±
Study Bitcoin π€
2025-03-04 19:06:42
(1 year ago)
Port probe to tcp/443 (https)
[srv125]
Port Scan
Brute-Force
Bad Web Bot
Web App Attack