๐ณ๐ฑ
wolfemium
2026-08-22 14:17:57
(17 hours ago)
172.70.38.214 - - [22/Aug/2026:17:17:55 +0300] "GET /man.php HTTP/1.1" 502 150 "-" "-"
172.70.38.214 ...
show more
172.70.38.214 - - [22/Aug/2026:17:17:55 +0300] "GET /man.php HTTP/1.1" 502 150 "-" "-"
172.70.38.214 - - [22/Aug/2026:17:17:55 +0300] "GET /ffile.php HTTP/1.1" 502 150 "-" "-"
172.70.38.214 - - [22/Aug/2026:17:17:56 +0300] "GET /Sanskrit.php HTTP/1.1" 502 150 "-" "-"
172.70.38.214 - - [22/Aug/2026:17:17:56 +0300] "GET /pol.php HTTP/1.1" 502 150 "-" "-"
172.70.38.214 - - [22/Aug/2026:17:17:56 +0300] "GET /jlex.php HTTP/1.1" 502 150 "-" "-"
172.70.38.214 - - [22/Aug/2026:17:17:56 +0300] "GET /dejavu.php HTTP/1.1" 502 150 "-" "-"
...
show less
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 13:37:24
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.214 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 09:37:15.655345 2026] [security2:error] [pid 24129:tid 24129] [client 172.70.38.214:11090] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "register-boat-germany.com.boatregistrationdelaware.com"] [uri "/.git/HEAD"] [unique_id "aoMOi1gcGNKMdG_5_-LhNwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 12:08:18
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.214 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 08:08:09.742917 2026] [security2:error] [pid 32068:tid 32068] [client 172.70.38.214:13548] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yalaz.qcyprus.com"] [uri "/.git/HEAD"] [unique_id "aoL5qXH87neQ9FEu46rwGQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 05:41:05
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.214 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 01:40:58.872222 2026] [security2:error] [pid 18344:tid 18344] [client 172.70.38.214:9228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.leonardodecaprio.com"] [uri "/.git/config"] [unique_id "aoKe6t_sm9TCtEs1NvEWkAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 04:38:44
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.214 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 00:38:36.035568 2026] [security2:error] [pid 14673:tid 14673] [client 172.70.38.214:12045] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.oahupc.com"] [uri "/.git/HEAD"] [unique_id "aoKQTNnN9xMeI4wbgAY3JgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-11 03:31:24
(1 week ago)
Web App Attack
Anonymous
2026-06-16 09:50:08
(2 months ago)
172.70.38.214 - - > tecnicman.it [16/Jun/2026:11:50:03 +0200] "GET /xmlrpc.php HTTP/2.0" 301 162 "ht ...
show more
172.70.38.214 - - > tecnicman.it [16/Jun/2026:11:50:03 +0200] "GET /xmlrpc.php HTTP/2.0" 301 162 "http://tecnicman.it/xmlrpc.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0" "52.146.92.163"
172.70.38.214 - - > tecnicman.it [16/Jun/2026:11:50:05 +0200] "GET /blog/xmlrpc.php HTTP/2.0" 301 162 "http://tecnicman.it/blog/xmlrpc.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36" "52.146.92.163"
172.70.38.214 - - > tecnicman.it [16/Jun/2026:11:50:05 +0200] "GET /wp/xmlrpc.php HTTP/2.0" 301 162 "http://tecnicman.it/wp/xmlrpc.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36" "52.146.92.163"
172.70.38.214 - - > tecnicman.it [16/Jun/2026:11:50:06 +0200] "GET /wordpress/xmlrpc.php HTTP/2.0" 301 162 "http://tecnicman.it/wordpress/xmlrpc.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWe
...
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 08:38:55
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.214 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:37:44.599145 2026] [security2:error] [pid 3322:tid 3322] [client 172.70.38.214:10679] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.newlife12steprecovery.intnlc.org"] [uri "/.env.vercel"] [unique_id "agbbWDWb7tBYfGL347cozQAAAD8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 07:09:43
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.214 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 03:09:39.816744 2026] [security2:error] [pid 20000:tid 20000] [client 172.70.38.214:10691] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.jerryfeil.com"] [uri "/.env.staging"] [unique_id "adNcMwVFALGe8Y7qEC3RNAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 22:47:23
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.214 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 18:47:16.483436 2026] [security2:error] [pid 2464:tid 2464] [client 172.70.38.214:9851] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.jazzycatty.com"] [uri "/.env.test"] [unique_id "adLmdOvHcM4dUfoRkFLMSQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 10:08:16
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.214 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 06:08:12.994405 2026] [security2:error] [pid 23420:tid 23420] [client 172.70.38.214:13502] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.mandel.vc"] [uri "/.env_backup"] [unique_id "adI0jJBnJ46Qja0wkXuiaQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 04:07:40
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.214 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 00:07:34.577454 2026] [security2:error] [pid 4990:tid 4990] [client 172.70.38.214:12143] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bank.ic1.biz"] [uri "/.env.php"] [unique_id "adHgBunH8eVOINH5NoC7ewAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 01:01:54
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.214 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 21:01:50.584697 2026] [security2:error] [pid 1231:tid 1293] [client 172.70.38.214:10644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.velatorioslucenses.com"] [uri "/.env.production"] [unique_id "adG0ftUnsZvzHqEidZ6o8QAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 21:55:47
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.214 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 17:55:42.802015 2026] [security2:error] [pid 16183:tid 16183] [client 172.70.38.214:12062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ink2wear.com"] [uri "/.env.bak"] [unique_id "adGI3o7eEQHH8HZL9w6KYAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 13:59:14
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.214 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 09:59:07.644073 2026] [security2:error] [pid 16071:tid 16071] [client 172.70.38.214:12601] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.thebestac.com"] [uri "/public/.env"] [unique_id "adEZK4F5ykH0NAwN22Gm3gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack