๐ง๐ช
madeit
2026-08-27 19:30:59
(5 days ago)
Web App Attack
๐ง๐ช
madeit
2026-08-15 22:36:20
(2 weeks ago)
Web App Attack
๐ฉ๐ช
Blexyel
2026-08-09 00:40:16
(3 weeks ago)
172.70.242.242 - - [09/Aug/2026:02:40:15 +0200] "HEAD /cgi-bin/php-cgi HTTP/1.1" 404 0 "-" "Mozilla/ ...
show more
172.70.242.242 - - [09/Aug/2026:02:40:15 +0200] "HEAD /cgi-bin/php-cgi HTTP/1.1" 404 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 Edg/131.0.0.0" "pingusmc.org"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-13 05:00:32
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.242.242 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.242.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 13 01:00:27.064278 2026] [security2:error] [pid 31316:tid 31316] [client 172.70.242.242:10246] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "10bestattorneys.com"] [uri "/.env.test"] [unique_id "alRw6w3vtsNCZ1UJwC-QJwAAAA8"], referer: https://www.google.com/search?q=10bestattorneys.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
OptimusGO
2026-06-27 23:33:45
(2 months ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-06-28 00:33:45 UTC
Log evidence:
172.70.242.242 - - [28/Jun/2026:00:33:43 +0100] "GET /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings HTTP/1.1" 404 118 "-" "curl/8.7.1"
172.70.242.242 - - [28/Jun/2026:00:33:43 +0100] "GET /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings HTTP/1.1" 404 118 "-" "curl/8.7.1"
172.70.242.242 - - [28/Jun/2026:00:33:43 +0100] "GET /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings HTTP/1.1" 404 118 "-" "curl/8.7.1"
show less
Port Scan
Brute-Force
๐ฉ๐ช
femboy.cat
2026-06-16 22:57:39
(2 months ago)
Port scan to tcp/8443 from 172.70.242.242
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-08 07:15:37
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.242.242 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.242.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 03:15:31.466206 2026] [security2:error] [pid 4671:tid 4671] [client 172.70.242.242:14075] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aandbnaturalfoods.com"] [uri "/.git/config"] [unique_id "af2Nk3sq76XlTNyaGmJ8OQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
trentwiles.com
2026-04-22 19:26:13
(4 months ago)
Unauthorized connection attempt detected from IP address 172.70.242.242 to port 443 [SYD]
Port Scan
๐ฆ๐บ
oncord
2026-04-20 17:57:23
(4 months ago)
Form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2026-04-07 20:09:07
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.242.242 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.242.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 16:09:03.724009 2026] [security2:error] [pid 1494692:tid 1494692] [client 172.70.242.242:13072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.idahostem.org"] [uri "/.git/logs/HEAD"] [unique_id "adVkX_0flEAf5pYh6eruGgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
psauxit
2026-04-06 22:48:30
(4 months ago)
Fail2Ban - NGINX 403 forcing to access a restricted resource
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-06 21:44:10
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.242.242 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.242.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 17:44:03.149808 2026] [security2:error] [pid 1075804:tid 1075804] [client 172.70.242.242:11673] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.homewaterproofing.com"] [uri "/.git/HEAD"] [unique_id "adQpI_4vrArKamhydMtIcgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
findlab
2026-04-06 05:30:03
(4 months ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
Anonymous
2026-04-06 03:48:14
(4 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2026-04-06 02:54:37
(4 months ago)
Aggressive web scan
Web App Attack