๐ท๐บ
DZBOT
2026-06-23 19:32:18
(17 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฉ๐ช
netclix.gr
2026-06-23 18:03:48
(18 hours ago)
(security_scan) Sensitive File Scan Blocked 172.70.248.190 (DE/Germany/-): 1 in the last 4600 secs; ...
show more
(security_scan) Sensitive File Scan Blocked 172.70.248.190 (DE/Germany/-): 1 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 172.70.248.190 - - [23/Jun/2026:21:03:19 +0300] "GET /.env HTTP/2.0" 404 532 "-" "Mozilla/5.0 (l9scan/2.0.7373e2537313e27363e2237313; +https://leakix.net)" "206.81.24.74"'/error_docs/404.html' '' '/opt/psa/admin/htdocs'
show less
Port Scan
๐ฉ๐ช
Blexyel
2026-06-23 08:57:30
(1 day ago)
172.70.248.190 - - [23/Jun/2026:10:57:30 +0200] "GET /backup/.git/info/exclude HTTP/1.1" 404 146 "-" ...
show more
172.70.248.190 - - [23/Jun/2026:10:57:30 +0200] "GET /backup/.git/info/exclude HTTP/1.1" 404 146 "-" "Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 04:03:25
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 00:03:21.469851 2026] [security2:error] [pid 16888:tid 16888] [client 172.70.248.190:9477] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.graymatterofdc.com"] [uri "/.git/config"] [unique_id "ajDLCYQMYaon7GWG0B9_ygAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 22:54:40
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 18:54:34.567311 2026] [security2:error] [pid 25645:tid 25645] [client 172.70.248.190:10221] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elsmithpest.com"] [uri "/.git/config"] [unique_id "ajCCqmsD2LP-RNPj3alUWgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
celestialcity
2026-06-07 00:23:56
(2 weeks ago)
Blocked by UFW on celestialcityas [8443/tcp] | SPT: 9865 | TTL: 38 | LEN: 60 | TOS: 0x00 โข Reported ...
show more
Blocked by UFW on celestialcityas [8443/tcp] | SPT: 9865 | TTL: 38 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ฆ๐น
Renรฉ Hickersberger
2026-06-05 20:18:24
(2 weeks ago)
malicious bot detected: violations="hit-honeypot"; user_agent="Mozilla/5.0 (Linux; Android 14; Pixel ...
show more
malicious bot detected: violations="hit-honeypot"; user_agent="Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.6422.113 Mobile Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 16:03:30
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 12:03:22.947969 2026] [security2:error] [pid 17089:tid 17089] [client 172.70.248.190:13283] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rlharmongroup.com"] [uri "/.git/config"] [unique_id "ah7-ysvG952eTEY7GnI6FwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 13:24:57
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 09:24:50.383788 2026] [security2:error] [pid 5864:tid 5864] [client 172.70.248.190:12059] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.drayvian.com"] [uri "/.git/config"] [unique_id "ah7Zoj2DZPnxyRiqUhBuQgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-02 13:06:15
(3 weeks ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-05-23 22:48:15
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-05-16 19:42:08
(1 month ago)
172.70.248.190 - - [16/May/2026:22:42:08 +0300] "GET /wp-includes/ HTTP/1.1" 404 768 "-" "Mozlila/5. ...
show more
172.70.248.190 - - [16/May/2026:22:42:08 +0300] "GET /wp-includes/ HTTP/1.1" 404 768 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
...
show less
Web App Attack
๐จ๐ฆ
dispensight
2026-05-15 17:30:52
(1 month ago)
Automated WordPress exploit probe via honeydomain. UA: dispensight.site. Cloudflare Germany proxy.
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-15 10:53:59
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 06:53:52.077909 2026] [security2:error] [pid 31686:tid 31686] [client 172.70.248.190:13138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.yukihouse.hk"] [uri "/.env.development"] [unique_id "agb7QChGVXltTuxbA1tLzQAAABA"], referer: https://www.google.com/search?q=webmail.yukihouse.hk
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐ฑ
router.al
2026-05-14 23:02:19
(1 month ago)
05/14/2026-23:02:18.822625 172.70.248.190 Protocol: 6 ET SCAN LeakIX Inbound User-Agent
Hacking