๐ฌ๐ง
OptimusGO
2026-06-18 05:42:04
(1 day ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-06-18 06:42:04 UTC
Log evidence:
06/18/2026-06:42:03.818389 [**] [1:1000103:1] SECURITY Management Port Probe - CRITICAL [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 172.70.240.40:9434 -> 185.127.18.66:8443
show less
Port Scan
Brute-Force
๐บ๐ธ
TNZ
2026-06-17 17:08:44
(2 days ago)
Automated honeypot: waf:RFI-001 | Path: /wp-admin/install.php | ISP: AS13335 Cloudflare, Inc. | ASN: ...
show more
Automated honeypot: waf:RFI-001 | Path: /wp-admin/install.php | ISP: AS13335 Cloudflare, Inc. | ASN: AS13335 Cloudflare, Inc. [PROXY] | Abuse score: 0 | Open ports: [] | UA: http://getkovashield.com/wp-admin/install.php?step=1
show less
Web App Attack
๐ฆ๐ฑ
router.al
2026-06-16 07:18:08
(3 days ago)
06/16/2026-07:18:07.981018 172.70.240.40 Protocol: 6 ET SCAN LeakIX Inbound User-Agent
Hacking
๐ฉ๐ช
big-cloud.nl
2026-06-04 09:05:38
(2 weeks ago)
Try to access /.git/config
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 17:07:06
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.40 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 13:07:01.237170 2026] [security2:error] [pid 21103:tid 21103] [client 172.70.240.40:11137] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ridefilmsinc.com"] [uri "/.git/config"] [unique_id "ah8NtYfRO0pTsgQNCVPYvQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 14:25:02
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.40 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 10:24:58.202740 2026] [security2:error] [pid 16651:tid 16651] [client 172.70.240.40:13131] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "affourtit-bowmaker.com"] [uri "/.git/config"] [unique_id "ah7nusVgfFiCKGF7YEuQQQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-05-31 12:51:49
(2 weeks ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 172.70.240.40 (DE/Germany/-): 1 in ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 172.70.240.40 (DE/Germany/-): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
mnsf
2026-05-31 02:05:03
(2 weeks ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐ฉ๐ช
abdubhai
2026-05-18 13:54:00
(1 month ago)
172.70.240.40 - - [18/May/2026:1
...
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-09 02:35:06
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.40 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 22:34:55.712238 2026] [security2:error] [pid 7889:tid 7889] [client 172.70.240.40:13924] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ridefilmsinc.com"] [uri "/.git/config"] [unique_id "af6dTz6qeZzNFY2Kba2-2QAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฎ
administrator
2026-05-04 16:37:38
(1 month ago)
2026-04-09 04:45:03,417 fail2ban.actions [1117]: NOTICE [apache-custom] Ban 172.70.240.40
20 ...
show more
2026-04-09 04:45:03,417 fail2ban.actions [1117]: NOTICE [apache-custom] Ban 172.70.240.40
2026-04-09 04:45:03,453 fail2ban.actions [1117]: NOTICE [apache-badbots] Ban 172.70.240.40
2026-04-09 04:45:03,417 fail2ban.actions [1117]: NOTICE [apache-custom] Ban 172.70.240.40
...
show less
Bad Web Bot
Web Spam
Email Spam
Blog Spam
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-30 17:04:54
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.40 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 13:04:49.855498 2026] [security2:error] [pid 21215:tid 21215] [client 172.70.240.40:12788] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.mcgmcg.com"] [uri "/.git/config"] [unique_id "afOLsbaZq5dD2Czv3MMqsQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐ฑ
router.al
2026-04-30 13:39:23
(1 month ago)
04/30/2026-13:39:23.342473 172.70.240.40 Protocol: 6 ET SCAN LeakIX Inbound User-Agent
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-30 08:51:23
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.40 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 04:51:18.884370 2026] [security2:error] [pid 10468:tid 10468] [client 172.70.240.40:14115] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.theurbanlogger.com"] [uri "/.git/config"] [unique_id "afMYBh7RG-BPUVXehd5USAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-30 07:57:49
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.40 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 03:57:42.148922 2026] [security2:error] [pid 24776:tid 24776] [client 172.70.240.40:11021] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.schlegelcreative.com"] [uri "/.git/config"] [unique_id "afMLdo9dXyRzWVw-L7mSJAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack