Anonymous
2026-07-23 21:18:48
(8 hours ago)
Blocked by siteaihub.com: live autoban: immediate: /wp-admin/install.php
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-07-21 17:03:53
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 172.70.240.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.240.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 13:03:48.046373 2026] [security2:error] [pid 17177:tid 17177] [client 172.70.240.163:13330] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.bonefrog.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.bonefrog.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "al-mdKAxuM6IrOFs8upIsgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
OptimusGO
2026-07-20 22:24:24
(3 days ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-20 23:24:24 UTC
Log evidence:
07/20/2026-23:24:22.955683 [**] [1:1000103:1] SECURITY Management Port Probe - CRITICAL [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 172.70.240.163:11313 -> 185.127.18.66:8443
show less
Port Scan
Brute-Force
π·πΊ
DZBOT
2026-07-20 10:23:50
(3 days ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
Anonymous
2026-07-18 10:54:08
(5 days ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
πΊπΈ
mccsoft.io
2026-07-08 00:11:48
(2 weeks ago)
Web application attack / vulnerability scanning against our public nginx web server (TCP 80/443). So ...
show more
Web application attack / vulnerability scanning against our public nginx web server (TCP 80/443). Source matched a blocked-path security rule (jail nginx-444); server returned HTTP 444 (connection closed without response). TCP three-way handshake completed (full HTTP request received).
show less
Bad Web Bot
Web App Attack
π§π¬
Stoyko Stoykov
2026-07-03 20:58:44
(2 weeks ago)
172.70.240.163 - - [03/Jul/2026:23:58:43 +0300] "GET /.git/config HTTP/2.0" 404 134 "-" "git/2.39.2" ...
show more
172.70.240.163 - - [03/Jul/2026:23:58:43 +0300] "GET /.git/config HTTP/2.0" 404 134 "-" "git/2.39.2"
...
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-02 12:06:25
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 08:06:20.519108 2026] [security2:error] [pid 24895:tid 24895] [client 172.70.240.163:9317] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "janaia.com"] [uri "/.git/config"] [unique_id "akZUPMfDZKnvaEOpJCwiSAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
chillcog.com
2026-06-22 09:06:55
(1 month ago)
Blocked by on us-1-terraforge [8443/tcp] | SPT: 11003 | TTL: 55 | LEN: 60 | TOS: 0x00 β’ Reported by: ...
show more
Blocked by on us-1-terraforge [8443/tcp] | SPT: 11003 | TTL: 55 | LEN: 60 | TOS: 0x00 β’ Reported by: terraforge.fun
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-06-21 08:28:50
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 04:28:46.938101 2026] [security2:error] [pid 18460:tid 18460] [client 172.70.240.163:12422] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.humans2humans.org.asfmglobal.com"] [uri "/.env.dist"] [unique_id "ajegvj1vSUpc9fZ-SMSgMwAAAFM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§π¬
Stoyko Stoykov
2026-06-18 09:18:34
(1 month ago)
172.70.240.163 - - [18/Jun/2026:12:18:34 +0300] "GET //wp-includes/block-bindings/ HTTP/2.0" 404 134 ...
show more
172.70.240.163 - - [18/Jun/2026:12:18:34 +0300] "GET //wp-includes/block-bindings/ HTTP/2.0" 404 134 "-" "-"
...
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-16 11:06:28
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 07:06:20.478112 2026] [security2:error] [pid 10805:tid 10805] [client 172.70.240.163:14257] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thereddoorlounge.com"] [uri "/.env.local"] [unique_id "ajEuLDfBHgxHnxSWgIKLpAAAAAY"], referer: https://www.google.com/search?q=thereddoorlounge.com
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
IVski
2026-06-13 07:15:17
(1 month ago)
IVski WAF | Sensitive file probe detected - looking for .env
Port Scan
Brute-Force
Web App Attack
πΊπΈ
mccsoft.io
2026-06-11 00:06:32
(1 month ago)
Web application attack / vulnerability scanning against our public nginx web server (TCP 80/443). So ...
show more
Web application attack / vulnerability scanning against our public nginx web server (TCP 80/443). Source matched a blocked-path security rule (jail nginx-444); server returned HTTP 444 (connection closed without response). TCP three-way handshake completed (full HTTP request received).
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-04 21:43:19
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 17:43:16.219878 2026] [security2:error] [pid 29944:tid 29944] [client 172.70.240.163:12544] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sekel.org"] [uri "/.git/config"] [unique_id "aiHxdA4wajllB69VwniuHAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack