๐ฆ๐ฑ
router.al
2026-05-26 09:01:47
(2 weeks ago)
05/26/2026-09:01:46.887756 172.70.38.148 Protocol: 6 ET SCAN WordPress Scanner Performing Multiple R ...
show more
05/26/2026-09:01:46.887756 172.70.38.148 Protocol: 6 ET SCAN WordPress Scanner Performing Multiple Requests to Windows Live Writer XML
show less
Hacking
๐บ๐ธ
wimaxnz
2026-05-19 08:24:10
(3 weeks ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
๐ฒ๐ฝ
octageeks.com
2026-05-18 04:07:23
(3 weeks ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-14 22:05:25
(3 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-13.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-07 01:26:56
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.148 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 21:26:50.781146 2026] [security2:error] [pid 994019:tid 994019] [client 172.70.38.148:12566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.coconut-homes.com"] [uri "/.env.bak"] [unique_id "adRdWrMNJ91H_IUS_tCRrAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 06:21:53
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.148 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 02:21:49.533597 2026] [security2:error] [pid 12737:tid 12737] [client 172.70.38.148:13069] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.lemontreefoods.com"] [uri "/config/.env"] [unique_id "adNQ_VJ1O0YCwMAfc9SiAAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-04-05 23:10:52
(2 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: axios/1.13.6
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-05 09:01:26
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.148 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 05:01:19.116219 2026] [security2:error] [pid 26210:tid 26210] [client 172.70.38.148:11698] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.roguetechtalks.ficklepassionproductions.com"] [uri "/.env_secret"] [unique_id "adIk33IFH8z3MezpNE-ckQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 02:51:14
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.148 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 22:51:06.871242 2026] [security2:error] [pid 12955:tid 12955] [client 172.70.38.148:14310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.badwaterclaims.com"] [uri "/.git/logs/HEAD"] [unique_id "adHOGjaX7nxcssTr2s8sSwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 17:11:13
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.148 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 13:11:05.192624 2026] [security2:error] [pid 17007:tid 17007] [client 172.70.38.148:13021] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.fadcometal.com"] [uri "/core/.env"] [unique_id "adFGKY3ujWg-PMJNfJ95-QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 11:59:38
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.148 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 07:59:32.893519 2026] [security2:error] [pid 17586:tid 17586] [client 172.70.38.148:9537] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.c470techarchive.net"] [uri "/.env_backup"] [unique_id "adD9JDE6a3vrZS2lUhyoOwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 10:24:56
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.148 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 06:24:47.078197 2026] [security2:error] [pid 23359:tid 23359] [client 172.70.38.148:9599] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oxford-gliding-club.abbeygardensllandudno.com"] [uri "/.env.development"] [unique_id "adDm7_v9lnGAIUSP4tGbIwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 02:09:49
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.148 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 22:09:42.350861 2026] [security2:error] [pid 23377:tid 23377] [client 172.70.38.148:13877] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.tomhatcher.us"] [uri "/.env.dev"] [unique_id "adBy5kXYU5OuUS2WMFDaVAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 16:47:23
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.148 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 12:47:14.317260 2026] [security2:error] [pid 26555:tid 26555] [client 172.70.38.148:11319] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.takemehomedogrescue.org"] [uri "/.env.dev"] [unique_id "ac_vEon-M7BTZFBeRYtuLQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 14:28:14
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.148 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 10:28:05.140233 2026] [security2:error] [pid 17918:tid 17918] [client 172.70.38.148:14185] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.siedersoft.com.ar"] [uri "/.env.test"] [unique_id "ac_OddGwercKLXM26r7D6AAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack