Anonymous
2026-09-09 21:08:55
(1 day ago)
Blocked by firewall on hugin [8443/tcp] | Rule: UFW | SPT: 24892 | TTL: 57 | LEN: 60 | TOS: 0x00 โข R ...
show more
Blocked by firewall on hugin [8443/tcp] | Rule: UFW | SPT: 24892 | TTL: 57 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ง๐ช
madeit
2026-09-09 11:29:14
(1 day ago)
Web App Attack
๐บ๐ธ
craudiovizai
2026-09-09 06:30:32
(2 days ago)
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. ...
show more
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. Blocked at the edge.
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-09 22:44:51
(1 month ago)
(mod_security) mod_security (id:949110) triggered by 172.70.242.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 172.70.242.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 09 18:44:40.754283 2026] [security2:error] [pid 1136380:tid 1136380] [client 172.70.242.59:10043] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "advancedrentalandservice.com"] [uri "/.env"] [unique_id "ankC2OXm9Z_ohL71S7dk8QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 22:37:38
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.242.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.242.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 18:37:25.649969 2026] [security2:error] [pid 24469:tid 24469] [client 172.70.242.59:13333] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.unified-dispatch.com"] [uri "/.env.save"] [unique_id "anZeJRtXEya_2h3KV-YwJwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-08-07 10:31:03
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฉ๐ช
acadeova
2026-05-14 15:35:16
(3 months ago)
๐จ Recon detected (nft drop)
SRC=172.70.242.59
Observed=TCP dpt=80 in=enp0s6 ttl=59
Time=recent(journ ...
show more
๐จ Recon detected (nft drop)
SRC=172.70.242.59
Observed=TCP dpt=80 in=enp0s6 ttl=59
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐ฟ๐ฆ
Tokolosh Hunters
2026-05-05 15:17:32
(4 months ago)
AutoBlockWindow-Known bad useragent query-2026-05-05 15:17:31
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-29 04:31:13
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.242.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.242.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 29 00:31:09.422909 2026] [security2:error] [pid 29524:tid 29524] [client 172.70.242.59:10665] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "solutionsint.com.crestrong.com"] [uri "/.git/config"] [unique_id "afGJjYK_V-WdDDfGcVHD5wAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-23 18:53:19
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.242.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.242.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 23 14:53:11.756732 2026] [security2:error] [pid 25743:tid 25743] [client 172.70.242.59:14155] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amazinghydraulics.com"] [uri "/.git/config"] [unique_id "aepql-xXfumudzAmanObZAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 18:44:03
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.242.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.242.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 14:43:59.945361 2026] [security2:error] [pid 3406849:tid 3406875] [client 172.70.242.59:9455] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.miltonthepuppy.com"] [uri "/.git/refs/heads/master"] [unique_id "adVQb6loIGt8wd3CQrfKnQAAAJg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 06:50:55
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.242.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.242.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 02:50:44.706408 2026] [security2:error] [pid 31184:tid 31195] [client 172.70.242.59:11733] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.catishly.com"] [uri "/.git/HEAD"] [unique_id "adNXxPDhr4uwahs4YWKPKAAAAQg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-04-05 20:20:07
(5 months ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-04-05 17:55:27
(5 months ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 14:28:39
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.242.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.242.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 10:28:31.551480 2026] [security2:error] [pid 5969:tid 5969] [client 172.70.242.59:11237] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.wendywonjungkim.com"] [uri "/.git/config"] [unique_id "adJxj44-Yr845SugNVTMTgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack