๐ฌ๐ง
sandra361
2026-05-28 02:37:02
(2 weeks ago)
Port scan detected: 6 attempts across 1 ports (443). | Evidence: REAPER_TARPIT:IN=enp1s0f0 OUT= SRC= ...
show more
Port scan detected: 6 attempts across 1 ports (443). | Evidence: REAPER_TARPIT:IN=enp1s0f0 OUT= SRC=172.70.142.129 LEN=60 TOS=0x00 PREC=0x00 TTL=52 ID=20603 DF PROTO=TCP SPT=11251 DPT=443 WINDOW=65535 RES=0x00 SYN URGP=0
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-11 05:20:50
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.142.129 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.142.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 01:20:45.495641 2026] [security2:error] [pid 14742:tid 14742] [client 172.70.142.129:12049] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dr-taylor.com"] [uri "/.git/config"] [unique_id "agFnLVVzYVHRdd0KIg72cAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 04:37:13
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.142.129 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.142.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 00:37:03.333608 2026] [security2:error] [pid 24368:tid 24377] [client 172.70.142.129:13700] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.promoralchoice.thebiglies.com"] [uri "/.env.development"] [unique_id "agFc71ECkAJjqDk9x2Ex6gAAAQc"], referer: https://www.google.com/search?q=www.promoralchoice.thebiglies.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
www.mammazone.it
2026-04-08 22:30:27
(2 months ago)
[Thu Apr 09 00:30:27.227531 2026] [proxy_fcgi:error] [pid 1864174] [client 172.70.142.129:10345] AH0 ...
show more
[Thu Apr 09 00:30:27.227531 2026] [proxy_fcgi:error] [pid 1864174] [client 172.70.142.129:10345] AH01071: Got error 'Primary script unknown'
...
show less
Hacking
Web App Attack
Anonymous
2026-04-05 09:00:05
(2 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
mawan
2026-03-01 19:36:02
(3 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฉ๐ช
xbymilow
2026-01-04 10:39:33
(5 months ago)
172.70.142.129 - - [04/Jan/2026:11:39:33 +0100] "GET /login HTTP/2.0" 404 133 "http://xbymilow.xyz/l ...
show more
172.70.142.129 - - [04/Jan/2026:11:39:33 +0100] "GET /login HTTP/2.0" 404 133 "http://xbymilow.xyz/login" "Mozilla/5.0 (Android 13; Mobile; rv:117.0) Gecko/117.0 Firefox/117.0" rt=0.001 xff="161.118.250.104"
172.70.142.129 - - [04/Jan/2026:11:39:33 +0100] "GET /admin HTTP/2.0" 404 133 "http://xbymilow.xyz/admin" "Mozilla/5.0 (X11; Linux x86_64) Gecko/20100101 Firefox/117.0" rt=0.001 xff="161.118.250.104"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
xbymilow
2026-01-03 04:12:55
(5 months ago)
172.70.142.129 - - [03/Jan/2026:05:12:55 +0100] "GET /wp-login.php HTTP/2.0" 404 140 "http://xbymilo ...
show more
172.70.142.129 - - [03/Jan/2026:05:12:55 +0100] "GET /wp-login.php HTTP/2.0" 404 140 "http://xbymilow.xyz/wp-login.php" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_4_1 like Mac OS X) AppleWebKit/605.1.15 Mobile/15E148" rt=0.003 xff="134.185.83.182"
172.70.142.129 - - [03/Jan/2026:05:12:55 +0100] "GET /wp-admin/ HTTP/2.0" 404 137 "http://xbymilow.xyz/wp-admin/" "Mozilla/5.0 (Android 13; Mobile; rv:117.0) Gecko/117.0 Firefox/117.0" rt=0.002 xff="134.185.83.182"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
xbymilow
2026-01-02 08:31:43
(5 months ago)
172.70.142.129 - - [02/Jan/2026:09:31:42 +0100] "GET /wp-login.php HTTP/2.0" 404 140 "http://xbymilo ...
show more
172.70.142.129 - - [02/Jan/2026:09:31:42 +0100] "GET /wp-login.php HTTP/2.0" 404 140 "http://xbymilow.xyz/wp-login.php" "Mozilla/5.0 (Android 13; Mobile; rv:117.0) Gecko/117.0 Firefox/117.0" rt=0.003 xff="213.35.110.52"
172.70.142.129 - - [02/Jan/2026:09:31:43 +0100] "GET /wp-admin/ HTTP/2.0" 404 137 "http://xbymilow.xyz/wp-admin/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_5_1) AppleWebKit/605.1.15 Safari/605.1.15" rt=0.002 xff="213.35.110.52"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2025-12-27 04:42:15
(5 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-12-18 11:08:43
(5 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐จ๐ณ
ThreatBook.io
2025-12-14 22:08:11
(5 months ago)
ThreatBook Intelligence: Zombie more details on http://threatbook.io/ip/172.70.142.129
2025-12-14 19 ...
show more
ThreatBook Intelligence: Zombie more details on http://threatbook.io/ip/172.70.142.129
2025-12-14 19:24:19 /docs/images/fonts/OpenSans400italic.woff
show less
Web App Attack
Anonymous
2025-12-11 01:45:42
(6 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-12-08 07:45:05
(6 months ago)
Automatic report - Vulnerability scan
$ 403 /api/v3/color_settings/request
Web App Attack
๐ฎ๐ฉ
hermawan
2025-10-29 23:04:36
(7 months ago)
[Thu Oct 30 06:03:34.383379 2025] [security2:error] [pid 267517:tid 140406428260032] [client 172.70. ...
show more
[Thu Oct 30 06:03:34.383379 2025] [security2:error] [pid 267517:tid 140406428260032] [client 172.70.142.129:33511] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "CF-Connecting-IP" at REQUEST_HEADERS_NAMES:Cf-Connecting-Ip. [file "/etc/modsecurity/coreruleset-4.19.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "374"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: CF-Connecting-IP found within REQUEST_HEADERS_NAMES:Cf-Connecting-Ip: Cf-Connecting-Ip request_line = GET /images/Klimatologi/Prakiraan/04_Prakiraan_6_Bulanan/Prakiraan_Musim/Prakiraan_Musim_Kemarau/Provinsi_Jawa_Timur/2023/Peta_Prakiraan_Awal_Musim_Kemarau_Tahun_2023_Zona_Musim_di_Provinsi_Jawa_Timur.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/Klimatologi/Prakiraan/04_Prakiraan_6_Bulanan/Prakiraan_Musim/Prakiraan_Musim_Kemarau/Provinsi_Jawa_Timur/2023/Peta_Prakiraan_Awal_Musim_Kemarau_Tahun_2023_Zona_Musim_di_Pro
...
show less
Hacking
Web App Attack