๐ธ๐ฌ
cimee
2026-06-08 20:58:17
(6 days ago)
This IP accessed the path /.env.local, which is banned.
Bad Web Bot
Web App Attack
๐ฆ๐บ
oncord
2026-06-08 12:18:24
(6 days ago)
Form spam
Web Spam
๐ฉ๐ช
acadeova
2026-06-05 09:00:04
(1 week ago)
๐จ Recon detected (nft drop)
SRC=172.70.176.24
Observed=TCP dpt=80 in=enp0s6 ttl=56
Time=recent(journ ...
show more
๐จ Recon detected (nft drop)
SRC=172.70.176.24
Observed=TCP dpt=80 in=enp0s6 ttl=56
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐ฉ๐ช
Blexyel
2026-05-31 04:51:46
(2 weeks ago)
172.70.176.24 - - [31/May/2026:06:51:45 +0200] "GET /.git/config HTTP/1.1" 404 13 "-" "Mozilla/5.0 ( ...
show more
172.70.176.24 - - [31/May/2026:06:51:45 +0200] "GET /.git/config HTTP/1.1" 404 13 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36 Edg/147.0.0.0"
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
srtzero
2026-05-29 02:49:55
(2 weeks ago)
172.70.176.24 - - [29/May/2026:04:49:48 +0200] "GET /.env.local HTTP/1.1" 404 196 "-" "Mozilla/5.0 ( ...
show more
172.70.176.24 - - [29/May/2026:04:49:48 +0200] "GET /.env.local HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36"
172.70.176.24 - - [29/May/2026:04:49:53 +0200] "GET /.env.production.copy HTTP/1.1" 404 134 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:150.0) Gecko/20100101 Firefox/150.0"
172.70.176.24 - - [29/May/2026:04:49:54 +0200] "GET /.env.local.orig HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
...
show less
Port Scan
Bad Web Bot
Web App Attack
๐ธ๐ฌ
cimee
2026-05-20 10:51:19
(3 weeks ago)
This IP accessed the path /.env, which is banned.
Bad Web Bot
Web App Attack
๐ธ๐ฌ
cimee
2026-05-12 09:55:43
(1 month ago)
This IP accessed the path /.env.production, which is banned.
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-04-23 21:48:52
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐จ๐ฆ
yukon.ca
2026-03-13 21:35:32
(3 months ago)
Web Server Enforcement Violation: Sensitive Configuration File Disclosure
Port:80
Hacking
Exploited Host
๐ฆ๐บ
oncord
2026-03-08 13:57:41
(3 months ago)
Form spam
Web Spam
๐บ๐ธ
mawan
2026-02-14 06:01:15
(4 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฌ๐ง
2048
2026-02-13 14:45:42
(4 months ago)
2026-02-13T15:45:39.205442+01:00 machodeer kernel: [174960.245037] [UFW BLOCK] IN=ens3 OUT= MAC=REDA ...
show more
2026-02-13T15:45:39.205442+01:00 machodeer kernel: [174960.245037] [UFW BLOCK] IN=ens3 OUT= MAC=REDACTED SRC=172.70.176.24 DST=REDACTED LEN=60 TOS=0x00 PREC=0x00 TTL=55 ID=64792 DF PROTO=TCP SPT=22513 DPT=443 WINDOW=65535 RES=0x00 SYN URGP=0
2026-02-13T15:45:40.121085+01:00 machodeer kernel: [174961.160207] [UFW BLOCK] IN=ens3 OUT= MAC=REDACTED SRC=172.70.176.24 DST=REDACTED LEN=60 TOS=0x00 PREC=0x00 TTL=55 ID=62132 DF PROTO=TCP SPT=16311 DPT=443 WINDOW=65535 RES=0x00 SYN URGP=0
2026-02-13T15:45:41.015222+01:00 machodeer kernel: [174962.055600] [UFW BLOCK] IN=ens3 OUT= MAC=REDACTED SRC=172.70.176.24 DST=REDACTED LEN=60 TOS=0x00 PREC=0x00 TTL=55 ID=51691 DF PROTO=TCP SPT=64925 DPT=443 WINDOW=65535 RES=0x00 SYN URGP=0
show less
Port Scan
๐ช๐ธ
el-brujo
2026-01-10 19:21:23
(5 months ago)
10/Jan/2026:20:21:22.973267 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
10/Jan/2026:20:21:22.973267 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 172.70.176.24] ModSecurity: Warning. Pattern match "[\\\\\\\\n\\\\\\\\r]" at ARGS_NAMES:\\\\r\\\\n<methodCall>\\\\r\\\\n<methodName>system.listMethods</methodName>\\\\r\\\\n<params></params>\\\\r\\\\n</methodCall>\\\\r\\\\n\\\\r\\\\n\\\\r\\\\n\\\\r\\\\n. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-921-PROTOCOL-ATTACK.conf"] [line "172"] [id "921150"] [msg "HTTP Header Injection Attack via payload (CR/LF detected)"] [data "Matched Data: \\\\x0d found within ARGS_NAMES:\\\\x5cr\\\\x5cn<methodCall>\\\\x5cr\\\\x5cn<methodName>system.listMethods</methodName>\\\\x5cr\\\\x5cn<params></params>\\\\x5cr\\\\x5cn</methodCall>\\\\x5cr\\\\x5cn\\\\x5cr\\\\x5cn\\\\x5cr\\\\x5cn\\\\x5cr\\\\x5cn: \\\\x0d\\\\x0a<methodCall>\\\\x0d\\\\x0a<methodName>system.listMethods</methodName>\\\\x0d\\\\x0a<params></params>\\\\x0d\\\\x0a</methodCall>\\\\x0d\\\\x0a\\\\x0d\\\\x0a\\\\x0d\\\\x0a\\\\x0d\\\\x0a"] [
...
show less
Hacking
Web App Attack
๐ฎ๐น
alph44
2025-11-27 08:05:36
(6 months ago)
(mod_security) mod_security (id:949110) triggered by 172.70.176.24 (US/United States/-): 5 in the la ...
show more
(mod_security) mod_security (id:949110) triggered by 172.70.176.24 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-16 07:23:57
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.70.176.24 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.176.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 16 03:23:51.997675 2025] [security2:error] [pid 113698:tid 113698] [client 172.70.176.24:49796] [client 172.70.176.24] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.gibitsoft.com"] [uri "/.git/config"] [unique_id "aCboB3-nqvtteQQUjMfWZAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack