๐ฌ๐ง
OptimusGO
2026-08-13 19:02:45
(3 weeks ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-08-13 20:02:45 UTC
Log evidence:
172.70.250.6 - - [13/Aug/2026:20:02:27 +0100] "GET /___proxy_subdomain_whm/login HTTP/1.1" 301 162 "-" "Mozilla/5.0 (l9scan/2.0.0353e27343e21323e2430313; +https://leakix.net)"
172.70.250.6 - - [13/Aug/2026:20:02:27 +0100] "GET /___proxy_subdomain_cpanel HTTP/1.1" 301 162 "-" "Mozilla/5.0 (l9scan/2.0.0353e27343e21323e2430313; +https://leakix.net)"
08/13/2026-20:02:27.683065 [**] [1:2049255:1] ET SCAN LeakIX Inbound User-Agent [**] [Classification: Misc activity] [Priority: 3] {TCP} 172.70.250.6:9933 -> 185.127.18.66:80
show less
Port Scan
Brute-Force
๐ซ๐ฎ
inlink.ltd
2026-08-11 07:13:45
(3 weeks ago)
dot file probe
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-07-05 04:19:14
(2 months ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-06-10 06:15:33
(2 months ago)
172.70.250.6 - - [10/Jun/2026:09:15:06 +0300] "GET /wp-includes/http/ HTTP/1.1" 404 768 "-" "Mozlila ...
show more
172.70.250.6 - - [10/Jun/2026:09:15:06 +0300] "GET /wp-includes/http/ HTTP/1.1" 404 768 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
172.70.250.6 - - [10/Jun/2026:09:15:32 +0300] "GET /wp-includes/js/ HTTP/1.1" 404 768 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
...
show less
Web App Attack
๐ฉ๐ช
www.mammazone.it
2026-06-03 09:14:55
(3 months ago)
[Wed Jun 03 11:14:55.020816 2026] [proxy_fcgi:error] [pid 1799735] [client 172.70.250.6:11039] AH010 ...
show more
[Wed Jun 03 11:14:55.020816 2026] [proxy_fcgi:error] [pid 1799735] [client 172.70.250.6:11039] AH01071: Got error 'Primary script unknown'
...
show less
Hacking
Web App Attack
๐ฉ๐ช
iNetWorker
2026-05-23 19:16:26
(3 months ago)
trolling for resource vulnerabilities
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-05-14 08:02:55
(3 months ago)
Try to access /.aws/credentials
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 14:21:39
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.250.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.250.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 10:21:32.757830 2026] [security2:error] [pid 9152:tid 9152] [client 172.70.250.6:14283] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "greentirerecycling.com"] [uri "/.git/config"] [unique_id "af3xbJ3x0KJLMETaUQ60CgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
trentwiles.com
2026-05-05 20:41:44
(3 months ago)
Unauthorized connection attempt detected from IP address 172.70.250.6 to port 2087 [SYD]
Port Scan
๐บ๐ธ
TPI-Abuse
2026-04-30 11:26:46
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.250.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.250.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 07:26:42.789241 2026] [security2:error] [pid 28154:tid 28154] [client 172.70.250.6:13318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.theebees.com"] [uri "/.git/config"] [unique_id "afM8covBidSjKHTpsmCYcAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-29 10:32:53
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.250.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.250.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 29 06:32:48.523575 2026] [security2:error] [pid 12973:tid 12973] [client 172.70.250.6:12495] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.1214productions.com"] [uri "/.git/config"] [unique_id "afHeUFRZOq0PbdkFZHsx-QAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-04-07 03:12:28
(4 months ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-04-06 05:14:25
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.250.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.250.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 01:14:17.942109 2026] [security2:error] [pid 16259:tid 16259] [client 172.70.250.6:13471] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mijnlevensverhaal.com"] [uri "/.env"] [unique_id "adNBKeIwesDycrA1WwAnkAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 02:47:47
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.250.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.250.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 22:47:40.705559 2026] [security2:error] [pid 13835:tid 13835] [client 172.70.250.6:14042] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ixdnet.deubellzebub.com"] [uri "/.git/index"] [unique_id "adMezPtGWvXupR5CsVDiUgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-04-04 16:05:30
(5 months ago)
Blocked Cloudflare Worker request. Pattern match "." at REQUEST_HEADERS:Cf-Worker. (5025-193)
Hacking