๐บ๐ธ
Lee Daniel
2026-09-25 21:32:43
(1 day ago)
172.70.208.81 - - [25/Sep/2026:17:32:42 -0400] "GET /.env HTTP/1.1" 403 344 "-" "Mozilla/5.0 (compat ...
show more
172.70.208.81 - - [25/Sep/2026:17:32:42 -0400] "GET /.env HTTP/1.1" 403 344 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-09 06:02:07
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.208.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.208.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 02:01:55.980994 2026] [security2:error] [pid 1150:tid 1150] [client 172.70.208.81:11272] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kevinjewell.com"] [uri "/.env.old"] [unique_id "aqD2U2wHQOG27btk_f0muQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Grossmann-Gruppe
2026-09-08 17:38:27
(2 weeks ago)
Plesk Fail2Ban: plesk-modsecurity
Hacking
Brute-Force
๐ฌ๐ง
cg-design.co.uk
2026-09-08 07:59:32
(2 weeks ago)
(mod_security) mod_security triggered on hostname [redacted] 172.70.208.81 (SG/Singapore/-)
SQL Injection
๐บ๐ธ
Axel
2026-08-29 08:58:01
(4 weeks ago)
Blocked by UFW on LAXHH [443/tcp] | SPT: 19230 | TTL: 54 | LEN: 60 | TOS: 0x00 โข Reported by: github ...
show more
Blocked by UFW on LAXHH [443/tcp] | SPT: 19230 | TTL: 54 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ฉ๐ช
Grossmann-Gruppe
2026-08-26 06:39:23
(1 month ago)
Plesk Fail2Ban: plesk-modsecurity
Hacking
Brute-Force
๐ฆ๐ฑ
router.al
2026-08-21 00:01:48
(1 month ago)
08/21/2026-00:01:47.873625 172.70.208.81 Protocol: 6 ET HUNTING Request for Webshell in .well-known ...
show more
08/21/2026-00:01:47.873625 172.70.208.81 Protocol: 6 ET HUNTING Request for Webshell in .well-known directory
show less
Hacking
๐ฉ๐ช
Grossmann-Gruppe
2026-08-19 15:41:18
(1 month ago)
Plesk Fail2Ban: plesk-modsecurity
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-18 02:26:16
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.208.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.208.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 22:26:10.996799 2026] [security2:error] [pid 20763:tid 20763] [client 172.70.208.81:9746] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.sugarsdowntown.com"] [uri "/.git/config"] [unique_id "aoPCwgViGWIQ2HE4bVOEzgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 22:30:37
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.208.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.208.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 18:30:29.843669 2026] [security2:error] [pid 27481:tid 27481] [client 172.70.208.81:11765] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.equipoperu.org"] [uri "/.git/config"] [unique_id "aoOLhTH0RY5KEgtI2UpKdQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 08:18:13
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.208.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.208.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 04:18:09.927243 2026] [security2:error] [pid 31265:tid 31265] [client 172.70.208.81:9958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.infrared-heaters.us"] [uri "/.git/config"] [unique_id "aoLDwcvDYjuaaPju18pFKwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 03:50:30
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.208.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.208.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 23:50:23.786499 2026] [security2:error] [pid 30763:tid 30763] [client 172.70.208.81:11810] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.supportourlibrary.org"] [uri "/.git/HEAD"] [unique_id "aoKE_xXsLzFMeYEhWWsZFgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-08-12 08:04:41
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฉ๐ช
lolyay
2026-08-04 02:20:51
(1 month ago)
172.70.208.81 - - [04/Aug/2026:02:20:50 +0000] "GET /html/.git/config HTTP/1.1" 200 4 "-" "crusader- ...
show more
172.70.208.81 - - [04/Aug/2026:02:20:50 +0000] "GET /html/.git/config HTTP/1.1" 200 4 "-" "crusader-worker/1.0"
172.70.208.81 - - [04/Aug/2026:02:20:50 +0000] "GET /wordpress/.git/config HTTP/1.1" 200 4 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Bad Web Bot
๐ง๐ท
chronos
2026-08-03 15:01:56
(1 month ago)
2026-08-03 11:03:46 UTC-3||Unauthorized connection attempt detected for port scanning
Port Scan