๐บ๐ธ
TPI-Abuse
2026-08-23 11:26:08
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.70.135.22 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.135.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 07:25:54.928880 2026] [security2:error] [pid 21957:tid 21957] [client 172.70.135.22:12441] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "highfydelity.com.fydelity.net"] [uri "/.env.test"] [unique_id "aorYwp9a5-cTBNRdeNBaZAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-08-23 04:17:55
(4 days ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-21 18:20:10
(6 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-08-21 18:07:51
(6 days ago)
172.70.135.22 - - [21/Aug/2026:20:07:46 +0200] "GET /wp-content/classwithtostring.php HTTP/2.0" 404 ...
show more
172.70.135.22 - - [21/Aug/2026:20:07:46 +0200] "GET /wp-content/classwithtostring.php HTTP/2.0" 404 289 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.70.135.22 - - [21/Aug/2026:12:51:06 +0200] "GET /wp-includes/block-supports/autoload_classmap.php HTTP/2.0" 404 357 "-" "-"
172.70.135.22 - - [21/Aug/2026:12:51:07 +0200] "GET /wp-content/plugins/admin.php HTTP/2.0" 404 312 "-" "-"
172.70.135.22 - - [21/Aug/2026:12:51:07 +0200] "GET /index.php0 HTTP/2.0" 404 289 "-" "-"
172.70.135.22 - - [21/Aug/2026:20:07:46 +0200] "GET /wp-includes/blocks HTTP/2.0" 404 357 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.70.135.22 - - [21/Aug/2026:20:07:47 +0200] "GET /wp-admin/css/colors/ocean.php HTTP/2.0" 404 312 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
show less
Web App Attack
Brute-Force
๐บ๐ธ
mawan
2026-08-21 06:55:57
(6 days ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ง๐ช
madeit
2026-08-20 13:00:47
(1 week ago)
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-18 21:59:46
(1 week ago)
Auto-ban: >3000 req/min op 2026-08-18
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-17 08:52:21
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.135.22 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.135.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 04:52:17.248891 2026] [security2:error] [pid 32325:tid 32325] [client 172.70.135.22:10145] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.samcdevitt.com"] [uri "/.git/config"] [unique_id "aoLLwe5feDANL1rnxwhnxAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 05:34:56
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.135.22 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.135.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 01:34:48.829496 2026] [security2:error] [pid 18279:tid 18279] [client 172.70.135.22:9634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.no1sicko.com"] [uri "/.git/HEAD"] [unique_id "aoKdeDSzAdKY7XcDlLxq4AAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 07:29:23
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.135.22 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.135.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 03:29:14.580540 2026] [security2:error] [pid 5508:tid 5508] [client 172.70.135.22:9764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "transportdelivery.com"] [uri "/.git/config"] [unique_id "aoFmytS9d-sj0Z-AfA97wwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-09 00:48:05
(2 weeks ago)
Web App Attack
๐ฆ๐บ
oncord
2026-05-26 12:03:57
(3 months ago)
Form spam
Web Spam
๐บ๐ธ
mnsf
2026-04-08 02:05:13
(4 months ago)
Scanning/Probing (15)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-30 18:24:02
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.135.22 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.135.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 14:23:56.672841 2026] [security2:error] [pid 18345:tid 18345] [client 172.70.135.22:12512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.franzexpress.com"] [uri "/.env.tmp"] [unique_id "acq_vNmMGBqyQ4_pZlgmQQAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-30 14:49:23
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.135.22 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.135.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 10:49:18.695574 2026] [security2:error] [pid 20391:tid 20409] [client 172.70.135.22:10568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.wegelin.org"] [uri "/admin/.env"] [unique_id "acqNbvwm4quVGVvVssFN9gAAAo4"]
show less
Brute-Force
Bad Web Bot
Web App Attack