๐ฉ๐ช
acadeova
2026-06-11 15:48:26
(2 days ago)
๐จ Recon detected (nft drop)
SRC=172.70.46.198
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journ ...
show more
๐จ Recon detected (nft drop)
SRC=172.70.46.198
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐ฉ๐ช
acadeova
2026-06-11 06:28:06
(2 days ago)
๐จ Recon detected (nft drop)
SRC=172.70.46.198
Observed=TCP dpt=80 in=enp0s6 ttl=58
Time=recent(journ ...
show more
๐จ Recon detected (nft drop)
SRC=172.70.46.198
Observed=TCP dpt=80 in=enp0s6 ttl=58
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐ฌ๐ง
pinguin
2026-02-08 18:37:38
(4 months ago)
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
thefoofighter
2026-01-06 08:41:21
(5 months ago)
[Tue Jan 06 08:41:20.035887 2026] [:error] [pid 1578011] [client 172.70.46.198:13803] [client 172.70 ...
show more
[Tue Jan 06 08:41:20.035887 2026] [:error] [pid 1578011] [client 172.70.46.198:13803] [client 172.70.46.198] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "93"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 7)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "sarahmcnally.com"] [uri "/new/.env"] [unique_id "aVzKsMHbr-jSRUSVY3AC1wAAAAE"]
[Tue Jan 06 08:41:20.631127 2026] [:error] [pid 1578011] [client 172.70.46.198:13803] [client 172.70.46.198] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "93"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 7)"] [severity "CRITICAL"] [ver "OWASP_CRS/3
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
MirrorImageGaming
2025-12-21 20:40:35
(5 months ago)
80 โ 443
GET / HTTP/1.1 http://bigbet303-d.com Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS ...
show more
80 โ 443
GET / HTTP/1.1 http://bigbet303-d.com Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1
show less
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2025-10-31 06:31:30
(7 months ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐ต๐ฑ
Niko's Stuff
2025-08-19 03:53:42
(9 months ago)
[1x] Triggered application-multi,language-multi platform-multi,attack-generic | Score: 5 | Msg: Inbo ...
show more
[1x] Triggered application-multi,language-multi platform-multi,attack-generic | Score: 5 | Msg: Inbound Anomaly Score Exceeded (Total Score: 5) | Uri: /administrator/.git/config | Client: 172.70.46.198 172.70.46.198 | Hostname: nikostuff.com | Blocked web application firewall detected attack
show less
Brute-Force
๐ฉ๐ช
Blexyel
2025-06-18 19:59:34
(11 months ago)
172.70.46.198 - - [18/Jun/2025:21:59:33 +0200] "GET /shop/wp-includes/wlwmanifest.xml HTTP/1.1" 404 ...
show more
172.70.46.198 - - [18/Jun/2025:21:59:33 +0200] "GET /shop/wp-includes/wlwmanifest.xml HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
...
show less
Brute-Force
Web App Attack
Anonymous
2025-06-09 17:53:16
(1 year ago)
(wordpress) Failed wordpress login from 172.70.46.198 (NL/The Netherlands/-): (CF_ENABLE)
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-05-28 17:21:08
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.70.46.198 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.46.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 28 13:21:04.804781 2025] [security2:error] [pid 1932675:tid 1932675] [client 172.70.46.198:40080] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "redish.org"] [uri "/.env"] [unique_id "aDdGAMwEkdJrerzXi-5JiAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-22 01:21:37
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.70.46.198 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.46.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 21 21:21:31.730390 2025] [security2:error] [pid 2876704:tid 2876704] [client 172.70.46.198:62206] [client 172.70.46.198] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.topbrand.co"] [uri "/.git/config"] [unique_id "aC58G5ZO-tWAVJ01YS9pkgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-05-20 17:02:38
(1 year ago)
Port probe to tcp/443 (https)
[srv125]
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-20 08:04:22
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.70.46.198 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.46.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 20 04:04:19.014338 2025] [security2:error] [pid 2977561:tid 2977561] [client 172.70.46.198:11352] [client 172.70.46.198] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nursetammytalks.com"] [uri "/.git/config"] [unique_id "aCw3g3Fl5hXQwYtlT9gZtAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-05-19 22:06:29
(1 year ago)
[Tue May 20 00:05:55.817149 2025] [authz_core:error] [pid 24549] [client 172.70.46.198:21546] AH0163 ...
show more
[Tue May 20 00:05:55.817149 2025] [authz_core:error] [pid 24549] [client 172.70.46.198:21546] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: 127.0.0.1
[Tue May 20 00:06:16.553679 2025] [authz_core:error] [pid 24543] [client 172.70.46.198:55882] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: 127.0.0.1
[Tue May 20 00:06:28.538729 2025] [authz_core:error] [pid 24566] [client 172.70.46.198:41116] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: 127.0.0.1
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-16 21:56:13
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.70.46.198 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.46.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 16 17:56:07.244800 2025] [security2:error] [pid 665212:tid 665212] [client 172.70.46.198:47508] [client 172.70.46.198] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "livpure.webfrog.ws"] [uri "/.git/config"] [unique_id "aCe0d86Xdu5QC4Wu9Hm7NgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack