Anonymous
2026-07-17 16:05:55
(3 days ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
πΊπΈ
xxkodedxx
2026-07-10 09:58:32
(1 week ago)
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1Γ honeypot-get in 10m window.
...
show more
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1Γ honeypot-get in 10m window.
Active: 09:58:10 UTC
Volume: 1 honeypot probe(s)
Bait taken: /wp-admin/install.php?step=1
UA: "http://zvxlabs.com/wp-admin/install.php?step=1"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-02 17:11:59
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.130 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 13:11:54.698903 2026] [security2:error] [pid 19027:tid 19027] [client 172.70.248.130:9526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "karturo.com"] [uri "/.git/config"] [unique_id "akab2jSe8ZzuSVPNCBs2ewAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπ¬
pusathosting.com
2026-06-15 13:30:05
(1 month ago)
24ds22 bruteforce
Brute-Force
Web App Attack
π³π΄
jad-abuse
2026-06-09 16:34:55
(1 month ago)
ThreatFeed automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin. Ob ...
show more
ThreatFeed automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin. Observed by 1 sensor(s); 2 hits.
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-07 00:06:35
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.130 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 20:06:29.477582 2026] [security2:error] [pid 18195:tid 18195] [client 172.70.248.130:13170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lognlumber.com"] [uri "/.git/config"] [unique_id "aiS2Ba27kAw3kaiUF30ljAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-02 10:04:22
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.130 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 06:04:16.456845 2026] [security2:error] [pid 18502:tid 18502] [client 172.70.248.130:12164] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "haerringer.com"] [uri "/.git/config"] [unique_id "ah6qoJg90lVQ1XYRzDJh-QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-25 01:55:20
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.130 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 24 21:55:14.769303 2026] [security2:error] [pid 19942:tid 19942] [client 172.70.248.130:13370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hischurchatwork.iworklife.org"] [uri "/.env.development.local"] [unique_id "ahOsAjxcMNL2DhMsLhvUdwAAAAo"], referer: https://www.google.com/search?q=www.hischurchatwork.iworklife.org
show less
Brute-Force
Bad Web Bot
Web App Attack
π·πΊ
DZBOT
2026-05-22 20:50:09
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
πΊπΈ
mawan
2026-05-21 06:39:20
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
Anonymous
2026-05-21 03:06:17
(1 month ago)
(caddyscan) Scanner path probe from 172.70.248.130 (DE/Germany/-): 5 in the last 3600 secs; Ports: * ...
show more
(caddyscan) Scanner path probe from 172.70.248.130 (DE/Germany/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 172.70.248.130 - - [21/May/2026:02:57:20 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.70.248.130 - - [21/May/2026:02:57:21 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.70.248.130 - - [21/May/2026:02:57:21 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.70.248.130 - - [21/May/2026:02:59:26 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.70.248.130 - - [21/May/2026:03:06:14 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-05-21 00:12:30
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.130 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 20:12:23.548599 2026] [security2:error] [pid 8078:tid 8078] [client 172.70.248.130:9749] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "weiqisociety.org.synergenicnetworks.com"] [uri "/.git/config"] [unique_id "ag5N54tOckDzrVj24APcVwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
pinguin
2026-05-20 01:20:33
(2 months ago)
Triggered Cloudflare WAF (firewallManaged) from DE.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from DE.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π¦πΊ
trentwiles.com
2026-05-17 19:54:56
(2 months ago)
Unauthorized connection attempt detected from IP address 172.70.248.130 to port 80 [SYD]
Port Scan
πΊπΈ
mawan
2026-05-16 09:55:34
(2 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack