๐ฏ๐ต
S.O.B.A. Dev.
2026-09-20 13:41:34
(51 minutes ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐ซ๐ท
chengkev
2026-09-19 12:56:10
(1 day ago)
Esta IP fue detectada por CrowdSec, activando crowdsecurity/http-sensitive-files
Web App Attack
Hacking
Anonymous
2026-09-14 16:27:58
(5 days ago)
(caddyscan) Scanner path probe from 172.70.216.112 (IT/Italy/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 172.70.216.112 (IT/Italy/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 172.70.216.112 - - [14/Sep/2026:16:27:52 +0000] "GET /v1/.env HTTP/1.1"
[REDACTED] 200 2627 172.70.216.112 - - [14/Sep/2026:16:27:53 +0000] "GET /v3/.env HTTP/1.1"
[REDACTED] 200 2627 172.70.216.112 - - [14/Sep/2026:16:27:53 +0000] "GET /rest/.env HTTP/1.1"
[REDACTED] 200 2627 172.70.216.112 - - [14/Sep/2026:16:27:54 +0000] "GET /microservice/.env HTTP/1.1"
[REDACTED] 200 2627 172.70.216.112 - - [14/Sep/2026:16:27:54 +0000] "GET /api/v3/.env HTTP/1.1"
show less
Port Scan
Anonymous
2026-09-10 04:05:18
(1 week ago)
(caddyscan) Scanner path probe from 172.70.216.112 (IT/Italy/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 172.70.216.112 (IT/Italy/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 172.70.216.112 - - [10/Sep/2026:04:05:02 +0000] "GET /shared/.env HTTP/1.1"
[REDACTED] 200 2627 172.70.216.112 - - [10/Sep/2026:04:05:15 +0000] "GET /codeigniter/.env HTTP/1.1"
[REDACTED] 200 2627 172.70.216.112 - - [10/Sep/2026:04:05:15 +0000] "GET /cakephp/.env HTTP/1.1"
[REDACTED] 200 2627 172.70.216.112 - - [10/Sep/2026:04:05:15 +0000] "GET /zend/.env HTTP/1.1"
[REDACTED] 200 2627 172.70.216.112 - - [10/Sep/2026:04:05:15 +0000] "GET /yii/.env HTTP/1.1"
show less
Port Scan
Anonymous
2026-09-09 14:27:52
(1 week ago)
(caddyscan) Scanner path probe from 172.70.216.112 (IT/Italy/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 172.70.216.112 (IT/Italy/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 172.70.216.112 - - [09/Sep/2026:14:27:45 +0000] "GET /src/.env HTTP/1.1"
[REDACTED] 200 2627 172.70.216.112 - - [09/Sep/2026:14:27:46 +0000] "GET /core/app/.env HTTP/1.1"
[REDACTED] 200 2627 172.70.216.112 - - [09/Sep/2026:14:27:47 +0000] "GET /bootstrap/.env HTTP/1.1"
[REDACTED] 200 2627 172.70.216.112 - - [09/Sep/2026:14:27:48 +0000] "GET /var/www/.env HTTP/1.1"
[REDACTED] 200 2627 172.70.216.112 - - [09/Sep/2026:14:27:49 +0000] "GET /release/.env HTTP/1.1"
show less
Port Scan
๐ฉ๐ช
abdubhai
2026-09-09 02:18:51
(1 week ago)
172.70.216.112 - - [09/Sep/2026:
...
Brute-Force
๐ซ๐ท
arsonist
2026-09-02 08:33:35
(2 weeks ago)
[fail2ban]
2026-09-02T08:33:34.982898+00:00 arson caddy[1890453]: {"level":"info","ts":1788338014.98 ...
show more
[fail2ban]
2026-09-02T08:33:34.982898+00:00 arson caddy[1890453]: {"level":"info","ts":1788338014.982857,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"172.70.216.112","remote_port":"14202","client_ip":"172.70.216.112","proto":"HTTP/2.0","method":"GET","host":"ayuworks.xyz","uri":"/wp-admin/","headers":{"Referer":["https://www.facebook.com/"],"Accept-Encoding":["gzip, br"],"Sec-Fetch-Dest":["document"],"Cdn-Loop":["cloudflare; loops=1"],"Cf-Connecting-Ip":["62.60.130.215"],"Cf-Visitor":["{\"scheme\":\"https\"}"],"X-Forwarded-Proto":["https"],"Sec-Fetch-Mode":["navigate"],"Sec-Fetch-User":["?1"],"Sec-Ch-Ua-Mobile":["?0"],"X-Forwarded-For":["62.60.130.215"],"Accept-Language":["en-US,en;q=0.9,ar;q=0.8"],"Upgrade-Insecure-Requests":["1"],"Cf-Ipcountry":["LT"],"Sec-Fetch-Site":["cross-site"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (
...
show less
Bad Web Bot
๐ซ๐ท
arsonist
2026-08-26 11:20:10
(3 weeks ago)
This IP accessed the path /wp-admin/maint/index.php, which is banned. Powered by ListenCaddy
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-05 00:19:31
(1 month ago)
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-08-02 02:34:08
(1 month ago)
172.70.216.112 - - [02/Aug/2026:05:34:07 +0300] "GET /wp-content/plugins/hellopress/wp_filemanager.p ...
show more
172.70.216.112 - - [02/Aug/2026:05:34:07 +0300] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/2.0" 404 114 "-" "-"
...
show less
Hacking
Web App Attack
๐ฉ๐ช
palla89
2026-07-25 17:16:28
(1 month ago)
(wordpress) Failed wordpress login from 172.70.216.112 (IT/Italy/-)
Brute-Force
๐จ๐ญ
4server
2026-07-17 09:37:18
(2 months ago)
[FriJul1711:37:15.5701012026][security2:error][pid3821124:tid3821443][client172.70.216.112:0]ModSecu ...
show more
[FriJul1711:37:15.5701012026][security2:error][pid3821124:tid3821443][client172.70.216.112:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"annunci-ticino.ch\"][uri\"/.git/HEAD\"][unique_id\"aln3ywr_r1yjP7Tn31df9QAAAMg\"]\,referer:https://www.google.com/search\?q=annunci-ticino.ch
show less
Hacking
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-04-25 22:00:37
(4 months ago)
Auto-ban: >3000 req/min op 2026-04-25
Web App Attack
SSH
Hacking
๐จ๐ญ
SOC [GOLINE SA]
2026-02-18 14:03:06
(7 months ago)
FortiGate detected IPS attack from IPv4 address 172.70.216.112
Hacking
๐บ๐ฆ
URAN Publishing Service
2026-02-05 11:02:06
(7 months ago)
172.70.216.112 - - [05/Feb/2026:13:02:05 +0200] "GET /wp-admin/network/natural.php HTTP/1.1" 404 280 ...
show more
172.70.216.112 - - [05/Feb/2026:13:02:05 +0200] "GET /wp-admin/network/natural.php HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95"
...
show less
Web App Attack