π©πͺ
ghostwarriors
2026-08-21 10:50:09
(5 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
π©πͺ
yitzhaq
2026-08-21 10:29:07
(5 days ago)
172.70.34.34 - - [21/Aug/2026:08:16:13 +0200] "GET /wp-login.php HTTP/2.0" 404 341 "-" "Mozilla/5.0 ...
show more
172.70.34.34 - - [21/Aug/2026:08:16:13 +0200] "GET /wp-login.php HTTP/2.0" 404 341 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
172.70.34.34 - - [21/Aug/2026:12:29:03 +0200] "GET /plugin-editor.php HTTP/2.0" 404 341 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.70.34.34 - - [21/Aug/2026:12:29:03 +0200] "GET /files.php HTTP/2.0" 404 55 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.70.34.34 - - [21/Aug/2026:12:29:04 +0200] "GET /maxro.php HTTP/2.0" 404 78 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.70.34.34 - - [21/Aug/2026:12:29:04 +0200] "GET /w.php HTTP/2.0" 404 46 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.70
show less
Web App Attack
Hacking
π§πͺ
madeit
2026-08-21 05:26:54
(5 days ago)
Web App Attack
π©πͺ
ghostwarriors
2026-08-16 20:50:12
(1 week ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
π©πͺ
yitzhaq
2026-08-16 20:48:48
(1 week ago)
172.70.34.34 - - [16/Aug/2026:22:48:41 +0200] "GET / HTTP/2.0" 200 838 "-" "Mozilla/5.0 (Windows NT ...
show more
172.70.34.34 - - [16/Aug/2026:22:48:41 +0200] "GET / HTTP/2.0" 200 838 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.70.34.34 - - [16/Aug/2026:22:48:41 +0200] "GET /file61.php HTTP/2.0" 404 83 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.70.34.34 - - [16/Aug/2026:22:48:42 +0200] "GET /first.php HTTP/2.0" 404 78 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.70.34.34 - - [16/Aug/2026:22:48:47 +0200] "GET /gulu.php HTTP/2.0" 404 341 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.70.34.34 - - [16/Aug/2026:22:48:47 +0200] "GET /h.php HTTP/2.0" 404 55 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
show less
Web App Attack
Hacking
π§πͺ
madeit
2026-08-10 19:15:13
(2 weeks ago)
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-09 12:10:47
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.34.34 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.34.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 08:10:42.822073 2026] [security2:error] [pid 18693:tid 18749] [client 172.70.34.34:14237] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "inongap.com"] [uri "/.git/config"] [unique_id "af8kQnlZKOI8zvuiHlnZCwAAAMk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-02 10:34:13
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.34.34 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.34.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 06:34:07.012525 2026] [security2:error] [pid 9346:tid 9346] [client 172.70.34.34:13730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arcdesign.me"] [uri "/.env.production"] [unique_id "ac5GH_kgUc3h-8RO7pR-SAAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-31 11:36:16
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.34.34 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.34.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 07:36:10.842819 2026] [security2:error] [pid 19607:tid 19607] [client 172.70.34.34:11758] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.weathercarib.com"] [uri "/.env.production"] [unique_id "acuxqtbacsIH4xrFFVuCcAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-03-31 11:06:21
(4 months ago)
Scanning/Probing (16)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-31 09:54:49
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.34.34 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.34.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 05:54:45.759234 2026] [security2:error] [pid 31901:tid 31901] [client 172.70.34.34:11033] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.kristywernerauthor.com"] [uri "/.env.tmp"] [unique_id "acuZ5a8NwspJVe3BZr_ObQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-30 17:13:11
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.34.34 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.34.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 13:13:01.049255 2026] [security2:error] [pid 29569:tid 29569] [client 172.70.34.34:10994] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "1954topresent.paleopathologist.com"] [uri "/.env.example"] [unique_id "acqvHXuFYgNNDJxCotkj-AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-30 15:00:34
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.34.34 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.34.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 11:00:30.386713 2026] [security2:error] [pid 29901:tid 29901] [client 172.70.34.34:13300] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.lumentravel.com"] [uri "/.env.test"] [unique_id "acqQDv7wy3zSe2ZwOHvJxgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-30 13:45:56
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.34.34 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.34.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 09:45:50.948196 2026] [security2:error] [pid 10028:tid 10050] [client 172.70.34.34:12086] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.iguanablue.com"] [uri "/.env.development"] [unique_id "acp-jjoyBIoh7lB1K1R8fAAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-30 12:52:17
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.34.34 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.34.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 08:52:13.081329 2026] [security2:error] [pid 2851:tid 2851] [client 172.70.34.34:9491] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.anchorroots.com"] [uri "/.env.staging"] [unique_id "acpx_dgXZCKTp_VQ_l4wvgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack