๐ฉ๐ช
Grossmann-Gruppe
2026-08-26 06:39:31
(1 week ago)
Plesk Fail2Ban: plesk-modsecurity
Hacking
Brute-Force
๐ฉ๐ช
Grossmann-Gruppe
2026-08-23 23:44:04
(1 week ago)
Plesk Fail2Ban: plesk-modsecurity
Hacking
Brute-Force
๐ซ๐ท
Pays d'Angoulรชme
2026-08-20 14:23:51
(1 week ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /wp-admin/core/install.php
Web App Attack
๐ง๐ช
madeit
2026-08-09 02:37:27
(3 weeks ago)
Web App Attack
๐บ๐ธ
chrisj
2026-08-03 12:48:38
(4 weeks ago)
[Mon Aug 03 12:48:36.913978 2026] [proxy_fcgi:error] [pid 563790:tid 563830] [remote 172.70.247.17:1 ...
show more
[Mon Aug 03 12:48:36.913978 2026] [proxy_fcgi:error] [pid 563790:tid 563830] [remote 172.70.247.17:11002] AH01071: Got error 'Primary script unknown'
[Mon Aug 03 12:48:37.347270 2026] [proxy_fcgi:error] [pid 563790:tid 563831] [remote 172.70.247.17:11002] AH01071: Got error 'Primary script unknown'
[Mon Aug 03 12:48:37.799059 2026] [proxy_fcgi:error] [pid 563790:tid 563832] [remote 172.70.247.17:11002] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
๐บ๐ธ
chrisj
2026-08-02 17:04:18
(4 weeks ago)
[Sun Aug 02 17:04:18.261283 2026] [proxy_fcgi:error] [pid 546623:tid 546632] [remote 172.70.247.17:1 ...
show more
[Sun Aug 02 17:04:18.261283 2026] [proxy_fcgi:error] [pid 546623:tid 546632] [remote 172.70.247.17:10118] AH01071: Got error 'Primary script unknown'
[Sun Aug 02 17:04:18.506260 2026] [proxy_fcgi:error] [pid 546623:tid 546633] [remote 172.70.247.17:10118] AH01071: Got error 'Primary script unknown'
[Sun Aug 02 17:04:18.763667 2026] [proxy_fcgi:error] [pid 546623:tid 546634] [remote 172.70.247.17:10118] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
๐ท๐บ
DZBOT
2026-07-18 19:04:44
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
Anonymous
2026-06-05 01:20:07
(2 months ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-05-25 11:08:51
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.247.17 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.247.17 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 25 07:08:39.921818 2026] [security2:error] [pid 27143:tid 27172] [client 172.70.247.17:10681] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ilovemyparrot.teritemme.com"] [uri "/.env.save"] [unique_id "ahQtt1kWFwYV-Iie722sGgAAABg"], referer: https://www.google.com/search?q=www.ilovemyparrot.teritemme.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-24 06:49:12
(3 months ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
xxkodedxx
2026-05-23 19:15:24
(3 months ago)
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1ร honeypot-get in 10m window.
...
show more
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1ร honeypot-get in 10m window.
Active: 19:14:58โ19:14:59 UTC
Volume: 2 honeypot probe(s)
Bait taken: /wp-login.php, /wp-admin/install.php?step=1
UA: "http://zvxlabs.com/wp-admin/install.php?step=1"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-16 00:02:51
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.247.17 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.247.17 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 20:02:46.501406 2026] [security2:error] [pid 31293:tid 31293] [client 172.70.247.17:13890] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.goldeys.com"] [uri "/.env.save"] [unique_id "age0Jmsrc79aEBJQO6mNHAAAAAA"], referer: https://www.google.com/search?q=autodiscover.goldeys.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
dispensight
2026-05-15 17:52:12
(3 months ago)
Automated WordPress exploit probe caught via honeydomain infrastructure. Bot used http://dispensight ...
show more
Automated WordPress exploit probe caught via honeydomain infrastructure. Bot used http://dispensight.space/wp-admin/install.php?step=1 as User-Agent. Honeydomain operator-controlled bait; confirmed malicious WordPress scanner. Cloudflare Germany proxy.
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-15 11:09:21
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.247.17 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.247.17 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 07:09:15.237526 2026] [security2:error] [pid 2118:tid 2118] [client 172.70.247.17:13991] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rasuki.com"] [uri "/.env.backup"] [unique_id "agb-24L_Clp26ty3Ps6JAQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 12:12:22
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.247.17 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.247.17 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 08:12:14.685270 2026] [security2:error] [pid 5032:tid 5032] [client 172.70.247.17:9786] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "maprada92.com"] [uri "/.git/config"] [unique_id "af3THtsHWExCJXrmxdhNJwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack