πΊπ¦
URAN Publishing Service
2026-09-21 09:54:55
(1 week ago)
[21/Sep/2026:12:54:55 +0300] -- 172.70.208.39 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[21/Sep/2026:12:54:55 +0300] -- 172.70.208.39 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.save HTTP/1.1
show less
Bad Web Bot
Web App Attack
π¦πΊ
Lazarus
2026-09-17 08:36:47
(1 week ago)
HTTP probe.
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-07 19:37:52
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.208.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.208.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 15:37:37.958565 2026] [security2:error] [pid 27207:tid 27207] [client 172.70.208.39:13006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.technlunch.ahijado.org"] [uri "/.env"] [unique_id "ap8SgbH0csndca0WnIJUJgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-06 05:33:25
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.208.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.208.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 01:33:14.808592 2026] [security2:error] [pid 377234:tid 377238] [client 172.70.208.39:14320] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pruebas.emehache.net"] [uri "/.env"] [unique_id "apz7GsrP8XMvsEK1w1xHZwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 23:18:54
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.208.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.208.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 19:18:47.606359 2026] [security2:error] [pid 23126:tid 23126] [client 172.70.208.39:11356] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.burdetteconsulting.com"] [uri "/.git/config"] [unique_id "aoOW17nl7xsYdtAiF3vIUwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 09:54:39
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.208.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.208.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 05:54:35.905966 2026] [security2:error] [pid 19774:tid 19774] [client 172.70.208.39:13781] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "caymancline.com"] [uri "/.git/HEAD"] [unique_id "aoLaW2a559Kj1o2jodo19AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 06:11:15
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.208.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.208.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 02:11:10.166778 2026] [security2:error] [pid 26379:tid 26379] [client 172.70.208.39:13615] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.thenotarymobile.com"] [uri "/.git/HEAD"] [unique_id "aoKl_nJ6JZWmqqtLgpyRTQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 03:48:26
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.208.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.208.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 23:48:17.744398 2026] [security2:error] [pid 29856:tid 29856] [client 172.70.208.39:10026] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.humandesignanalysis.org"] [uri "/.git/config"] [unique_id "aoKEgTaQwZLqTiEL7Xc45QAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-14 20:28:29
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.208.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.208.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 16:28:21.734906 2026] [security2:error] [pid 1066283:tid 1066293] [client 172.70.208.39:9521] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "accreditedfinancialanalyst.org"] [uri "/.git/HEAD"] [unique_id "an96Zbrutk-GlGKBOMQ6KAAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-14 03:46:55
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.208.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.208.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 23:46:51.361817 2026] [security2:error] [pid 272666:tid 272666] [client 172.70.208.39:13007] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.purlandpurr.com"] [uri "/.git/config"] [unique_id "an6Pq5kvlIPlWsiknKTJnwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-13 01:52:29
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.208.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.208.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 21:52:22.426972 2026] [security2:error] [pid 2933620:tid 2933620] [client 172.70.208.39:9973] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mylitta.com"] [uri "/.git/config"] [unique_id "an0jVi-ld_w3-UciRUR16AAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-04 20:09:37
(2 months ago)
172.70.208.39 - - [04/Jul/2026:22:09:29 +0200] "GET /wp-e0miea13.php HTTP/1.1" 404 124 "-" "-"
172.7 ...
show more
172.70.208.39 - - [04/Jul/2026:22:09:29 +0200] "GET /wp-e0miea13.php HTTP/1.1" 404 124 "-" "-"
172.70.208.39 - - [04/Jul/2026:22:09:30 +0200] "GET //av.php HTTP/1.1" 404 124 "-" "-"
172.70.208.39 - - [04/Jul/2026:22:09:30 +0200] "GET //wp-file.php HTTP/1.1" 404 124 "-" "-"
172.70.208.39 - - [04/Jul/2026:22:09:31 +0200] "GET //item.php HTTP/1.1" 404 124 "-" "-"
172.70.208.39 - - [04/Jul/2026:22:09:31 +0200] "GET /wp-dengko.php HTTP/1.1" 404 124 "-" "-"
172.70.208.39 - - [04/Jul/2026:22:09:31 +0200] "GET /wpxml.php HTTP/1.1" 404 124 "-" "-"
172.70.208.39 - - [04/Jul/2026:22:09:32 +0200] "GET //wp-admin/js/widgets/ HTTP/1.1" 404 124 "-" "-"
172.70.208.39 - - [04/Jul/2026:22:09:32 +0200] "GET /ova.php HTTP/1.1" 404 124 "-" "-"
172.70.208.39 - - [04/Jul/2026:22:09:33 +0200] "GET /sdm.php HTTP/1.1" 404 124 "-" "-"
172.70.208.39 - - [04/Jul/2026:22:09:33 +0200] "GET /wp-blog-header.php?p= HTTP/1.1" 404 124 "-" "-"
172.70.208.39 - - [04/Jul/2026:22:09:33 +0200] "GET /gtd7.php HTTP/1.1" 404 124
...
show less
Bad Web Bot
Web App Attack
π¦πΊ
dyln
2026-05-31 06:28:17
(3 months ago)
Dyls honeypot brute-force: proto8 (1 total hits)
Brute-Force
πΊπΈ
TPI-Abuse
2026-05-08 12:48:55
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.208.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.208.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 08:48:50.309794 2026] [security2:error] [pid 21094:tid 21117] [client 172.70.208.39:13386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "artbox.cibernetic.com"] [uri "/.env"] [unique_id "af3bspTo89PhSdaghhor8QAAANI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-04-20 22:03:52
(5 months ago)
Auto-ban: >3000 req/min op 2026-04-20
Web App Attack
SSH
Hacking