πΊπΈ
TPI-Abuse
2026-10-02 11:19:25
(4 days ago)
(mod_security) mod_security (id:949110) triggered by 172.70.247.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 172.70.247.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 07:19:22.192913 2026] [security2:error] [pid 10734:tid 10734] [client 172.70.247.213:10124] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "novintzkiariste.net"] [uri "/.git/config"] [unique_id "ar-TOskuBLT_AwhUKolz1AAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
robotstxt
2026-10-01 15:33:48
(4 days ago)
172.70.247.213 - - [01/Oct/2026:15:32:52 +0000] "GET /wp-content/admin.php HTTP/2.0" 400 193 "-" "-" ...
show more
172.70.247.213 - - [01/Oct/2026:15:32:52 +0000] "GET /wp-content/admin.php HTTP/2.0" 400 193 "-" "-" "20.70.173.30" edge="172.70.247.213"
172.70.247.213 - - [01/Oct/2026:15:32:52 +0000] "GET /biufile.php HTTP/2.0" 400 193 "-" "-" "20.70.173.30" edge="172.70.247.213"
172.70.247.213 - - [01/Oct/2026:15:32:53 +0000] "GET /simple.php HTTP/2.0" 400 193 "-" "-" "20.70.173.30" edge="172.70.247.213"
172.70.247.213 - - [01/Oct/2026:15:32:54 +0000] "GET /yawa.php HTTP/2.0" 400 193 "-" "-" "20.70.173.30" edge="172.70.247.213"
172.70.247.213 - - [01/Oct/2026:15:32:54 +0000] "GET /sym.php HTTP/2.0" 400 193 "-" "-" "20.70.173.30" edge="172.70.247.213"
...
show less
Web Spam
Web App Attack
π©πͺ
altenglaner
2026-10-01 15:04:03
(4 days ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
π§πͺ
madeit
2026-10-01 10:27:41
(5 days ago)
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 12:18:52
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.70.247.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.247.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:18:44.974755 2026] [security2:error] [pid 29711:tid 29711] [client 172.70.247.213:11226] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "taskmasterstech.com"] [uri "/.git/config"] [unique_id "arz-JPaIjj63n4S_IzW7SwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
UnixPrime
2026-09-26 21:48:29
(1 week ago)
172.70.247.213 - - [26/Sep/2026:23:48:28 +0200] "GET /.env.dev HTTP/1.1" 404 4128 "-" "Mozilla/5.0 ( ...
show more
172.70.247.213 - - [26/Sep/2026:23:48:28 +0200] "GET /.env.dev HTTP/1.1" 404 4128 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
172.70.247.213 - - [26/Sep/2026:23:48:28 +0200] "GET /.env.prod HTTP/1.1" 404 4132 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-18 21:37:47
(2 weeks ago)
Blocked by UFW [2095/tcp] | SPT: 9754 | TTL: 56 | LEN: 60 | TOS: 0x00 β’ Reported by: github.com/sefi ...
show more
Blocked by UFW [2095/tcp] | SPT: 9754 | TTL: 56 | LEN: 60 | TOS: 0x00 β’ Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
π§πͺ
madeit
2026-09-15 19:20:47
(2 weeks ago)
Web App Attack
π§πͺ
madeit
2026-09-03 06:41:33
(1 month ago)
Web App Attack
π§πͺ
madeit
2026-08-19 03:33:17
(1 month ago)
Web App Attack
π³π±
homeshowdomain.nl
2026-08-14 21:59:30
(1 month ago)
Auto-ban: >3000 req/min op 2026-08-14
Web App Attack
SSH
Hacking
Anonymous
2026-07-11 23:20:04
(2 months ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
π©πͺ
BiancaNL
2026-06-24 22:24:20
(3 months ago)
Fail2Ban: jail=nginx-exploit-probes on <fqdn> (port=<port>)
Hacking
πΊπΈ
TPI-Abuse
2026-06-05 15:09:53
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.247.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.247.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 11:09:49.042037 2026] [security2:error] [pid 12541:tid 12541] [client 172.70.247.213:9554] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "birdlovers.net"] [uri "/.git/config"] [unique_id "aiLmvb6GjrEqNoRRPGQ5HgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-06-02 18:05:34
(4 months ago)
Abuse Detected (1)
Brute-Force
Web App Attack