๐บ๐ธ
TPI-Abuse
2026-06-25 01:26:43
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.55 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 21:26:36.879606 2026] [security2:error] [pid 2167:tid 2167] [client 172.70.240.55:11005] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mhservice.mayan.abecasis.com"] [uri "/.env.bak"] [unique_id "ajyDzL5xzMaf_l71WrJWJgAAAA4"], referer: https://www.google.com/search?q=mhservice.mayan.abecasis.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
ISPLtd
2026-06-23 21:53:25
(2 days ago)
172.70.240.55 - - [23/Jun/2026:18:53:24 -0300] "GET /wp-PII/install.php?step=1
172.70.240.55 - - [23 ...
show more
172.70.240.55 - - [23/Jun/2026:18:53:24 -0300] "GET /wp-PII/install.php?step=1
172.70.240.55 - - [23/Jun/2026:18:53:25 -0300] "GET /wp-PII/install.php?step=1
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 11:19:25
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.55 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 07:19:21.164646 2026] [security2:error] [pid 16167:tid 16167] [client 172.70.240.55:12390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sawted.com"] [uri "/.env.test"] [unique_id "ajkaOUf1d-i3uZy_CzYWNwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
ISPLtd
2026-06-17 12:28:41
(1 week ago)
172.70.240.55 - - [17/Jun/2026:09:28:41 -0300] "GET /wp-PII/install.php?step=1
172.70.240.55 - - [17 ...
show more
172.70.240.55 - - [17/Jun/2026:09:28:41 -0300] "GET /wp-PII/install.php?step=1
172.70.240.55 - - [17/Jun/2026:09:28:41 -0300] "GET /wp-PII/install.php?step=1
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 09:32:26
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 172.70.240.55 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 172.70.240.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 05:32:23.195664 2026] [security2:error] [pid 32482:tid 32482] [client 172.70.240.55:10080] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "ritualistik.com"] [uri "/.git/config"] [unique_id "ajEYJ-3bfyTvFlc-TiONvQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-06-15 03:32:57
(1 week ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ณ๐ฑ
ipoac.nl
2026-06-07 03:16:55
(2 weeks ago)
-:443 172.70.240.55 - - [07/Jun/2026:05:16:53 +0200] - "GET /.git/config HTTP/2.0" 404 2707 "-" "Moz ...
show more
-:443 172.70.240.55 - - [07/Jun/2026:05:16:53 +0200] - "GET /.git/config HTTP/2.0" 404 2707 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0 like Mac OS X) AppleWebKit/605.1.15 Version/17.0 Mobile Safari/604.1"
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-03 03:40:44
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.55 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 23:40:41.104999 2026] [security2:error] [pid 30691:tid 30691] [client 172.70.240.55:11092] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kletzer.com"] [uri "/.git/config"] [unique_id "ah-iOd0MN9cT35ABVZKZLgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 09:29:38
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.55 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 05:29:31.841263 2026] [security2:error] [pid 32537:tid 32537] [client 172.70.240.55:9975] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "backspaced.com"] [uri "/.git/config"] [unique_id "ah6ie7CrEOb1uKvSZCOtwAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-05-31 15:05:13
(3 weeks ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 15:27:06
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.55 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 11:27:02.551732 2026] [security2:error] [pid 1859:tid 1859] [client 172.70.240.55:11434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "db.nyemdr.org"] [uri "/.git/config"] [unique_id "ahW7xjSeERSyZshtoWFMjwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-05-19 23:23:06
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-05-16 16:43:11
(1 month ago)
172.70.240.55 - - [16/May/2026:19:42:50 +0300] "GET /wp-includes/fonts/ HTTP/1.1" 404 770 "-" "Mozli ...
show more
172.70.240.55 - - [16/May/2026:19:42:50 +0300] "GET /wp-includes/fonts/ HTTP/1.1" 404 770 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
172.70.240.55 - - [16/May/2026:19:43:10 +0300] "GET /wp-includes/html-api/ HTTP/1.1" 404 770 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
...
show less
Web App Attack
๐ณ๐ฑ
COMPLEX
2026-05-16 00:29:32
(1 month ago)
Unsolicited TCP traffic | Action: DROP | Port 2087
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-15 11:09:31
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.240.55 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.240.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 07:09:23.724508 2026] [security2:error] [pid 2369:tid 2369] [client 172.70.240.55:11796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rasuki.com"] [uri "/.env.local"] [unique_id "agb-45nFaK35vN3eUuyzxAAAABU"], referer: https://www.google.com/search?q=rasuki.com
show less
Brute-Force
Bad Web Bot
Web App Attack