๐ง๐ช
madeit
2026-08-14 13:27:08
(1 month ago)
Web App Attack
Anonymous
2026-08-12 04:31:56
(1 month ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ซ๐ฎ
Erpelstolz
2026-07-19 08:46:24
(1 month ago)
external host: 172.70.243.163 - - [19/Jul/2026:10:46:23 +0200] "GET /wp-admin/install.php?step=1 HTT ...
show more
external host: 172.70.243.163 - - [19/Jul/2026:10:46:23 +0200] "GET /wp-admin/install.php?step=1 HTTP/1.1" 301 325 "-" "http://erpelstolz.com/wp-admin/install.php?step=1" CF-Ray:a1d874961e2c1cc7-FRA CF-IP:-
show less
Web App Attack
๐ซ๐ท
NetDevOPS
2026-07-17 00:18:05
(1 month ago)
GET /wp-admin/install.php?step=1 | UA: http://rootops.ovh/wp-admin/install.php?step=1
Web Spam
Bad Web Bot
Web App Attack
๐ฉ๐ช
F242
2026-05-16 01:25:30
(4 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 02:20:44
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.243.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.243.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 22:20:39.337867 2026] [security2:error] [pid 31349:tid 31349] [client 172.70.243.163:12681] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "villandance.com"] [uri "/.git/config"] [unique_id "af1Id8zMZ1DYhTPIKRu0YAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-11 06:32:26
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.243.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.243.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 11 02:32:20.385570 2026] [security2:error] [pid 1059481:tid 1059481] [client 172.70.243.163:11225] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.jmrlighting.com"] [uri "/.git/config"] [unique_id "adnq9Occ-hqwzcWwIJDlbQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
debaba
2026-04-07 15:39:18
(5 months ago)
[07/Apr/2026:15:39:17.212518 +0000] adUlJTDgD_rnZzcIoJAtGgAAAII 172.70.243.163 38930 127.0.0.1 7080
...
show more
[07/Apr/2026:15:39:17.212518 +0000] adUlJTDgD_rnZzcIoJAtGgAAAII 172.70.243.163 38930 127.0.0.1 7080
[07/Apr/2026:15:39:17.216137 +0000] adUlJcShzGFG-L
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 10:13:39
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.243.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.243.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 06:13:33.152068 2026] [security2:error] [pid 1870633:tid 1870633] [client 172.70.243.163:10497] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bairassoc.com.rogerandcarol.com"] [uri "/.git/HEAD"] [unique_id "adTYzdWfOw1iWHGwiqw77gAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 04:24:42
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.243.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.243.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 00:24:36.111064 2026] [security2:error] [pid 12375:tid 12391] [client 172.70.243.163:12050] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.ptinct.com"] [uri "/.git/refs/heads/master"] [unique_id "adM1hN1loYtlDWDCzgN6LAAAAQ0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 20:26:37
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.243.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.243.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 16:26:31.171551 2026] [security2:error] [pid 11340:tid 11340] [client 172.70.243.163:13819] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.kawkacevents.com"] [uri "/.git/index"] [unique_id "adLFd2KDYWl8sCX62H_RCAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-04-04 11:20:55
(5 months ago)
Blocked Cloudflare Worker request. Pattern match "." at REQUEST_HEADERS:Cf-Worker. (5025-195)
Hacking
๐ซ๐ท
masterguru
2026-04-04 09:30:40
(5 months ago)
Blocked Cloudflare Worker request. Pattern match "." at REQUEST_HEADERS:cf-worker. (5025-196)
Hacking
๐ซ๐ท
masterguru
2026-04-01 16:54:46
(5 months ago)
Blocked Cloudflare Worker request. Pattern match "." at REQUEST_HEADERS:cf-worker. (5025-193)
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-01 07:51:43
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.243.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.243.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 01 03:51:38.988272 2026] [security2:error] [pid 31980:tid 32076] [client 172.70.243.163:10796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.learndoexplore.com"] [uri "/.envrc"] [unique_id "aczOipXtKyQ96zVSoGTQGwAAAkQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack