π§πͺ
madeit
2026-09-29 07:23:32
(1 day ago)
Web App Attack
π©πͺ
netclix.gr
2026-09-28 10:30:17
(1 day ago)
(bot_kill_mega) Aggressive Bot Blocked: Go-http-client 172.70.49.220 (JP/Japan/-): 1 in the last 460 ...
show more
(bot_kill_mega) Aggressive Bot Blocked: Go-http-client 172.70.49.220 (JP/Japan/-): 1 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 172.70.49.220 - - [28/Sep/2026:13:28:30 +0300] "GET /login_up.php HTTP/2.0" 200 29667 "-" "Go-http-client/1.1" "47.74.11.247"'/login_up.php' '' '/opt/psa/admin/htdocs'
show less
Port Scan
π©πͺ
netclix.gr
2026-09-25 19:15:24
(4 days ago)
(bot_kill_mega) Aggressive Bot Blocked: Go-http-client 172.70.49.220 (JP/Japan/-): 1 in the last 460 ...
show more
(bot_kill_mega) Aggressive Bot Blocked: Go-http-client 172.70.49.220 (JP/Japan/-): 1 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 172.70.49.220 - - [25/Sep/2026:22:13:43 +0300] "GET /login_up.php HTTP/2.0" 200 29667 "-" "Go-http-client/1.1" "47.74.11.247"'/login_up.php' '' '/opt/psa/admin/htdocs'
show less
Port Scan
Anonymous
2026-09-21 22:38:40
(1 week ago)
(caddyscan) Scanner path probe from 172.70.49.220 (JP/Japan/-): 5 in the last 3600 secs; Ports: *; D ...
show more
(caddyscan) Scanner path probe from 172.70.49.220 (JP/Japan/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 172.70.49.220 - - [21/Sep/2026:22:38:38 +0000] "GET /cloud/.env HTTP/1.1"
[REDACTED] 200 2627 172.70.49.220 - - [21/Sep/2026:22:38:38 +0000] "GET /infrastructure/.env HTTP/1.1"
[REDACTED] 200 2627 172.70.49.220 - - [21/Sep/2026:22:38:39 +0000] "GET /k8s/.env HTTP/1.1"
[REDACTED] 200 2627 172.70.49.220 - - [21/Sep/2026:22:38:39 +0000] "GET /terraform/.env HTTP/1.1"
[REDACTED] 200 2627 172.70.49.220 - - [21/Sep/2026:22:38:40 +0000] "GET /.git/.env HTTP/1.1"
show less
Port Scan
Anonymous
2026-09-02 00:24:23
(4 weeks ago)
(caddyscan) Scanner path probe from 172.70.49.220 (JP/Japan/-): 5 in the last 3600 secs; Ports: *; D ...
show more
(caddyscan) Scanner path probe from 172.70.49.220 (JP/Japan/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 172.70.49.220 - - [02/Sep/2026:00:24:19 +0000] "GET /sitemaps/.env HTTP/1.1"
[REDACTED] 200 2627 172.70.49.220 - - [02/Sep/2026:00:24:19 +0000] "GET /.env.backup1 HTTP/1.1"
[REDACTED] 200 2627 172.70.49.220 - - [02/Sep/2026:00:24:20 +0000] "GET /logs/.env HTTP/1.1"
[REDACTED] 200 2627 172.70.49.220 - - [02/Sep/2026:00:24:20 +0000] "GET /mailer/.env HTTP/1.1"
[REDACTED] 200 2627 172.70.49.220 - - [02/Sep/2026:00:24:20 +0000] "GET /mail/.env HTTP/1.1"
show less
Port Scan
πΊπΈ
mawan
2026-07-18 06:05:34
(2 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
π¬π§
sandra361
2026-05-28 04:19:01
(4 months ago)
Port scan detected: 7 attempts across 1 ports (443). | Evidence: GHOST_SCAN:IN=enp1s0f0 OUT= SRC=172 ...
show more
Port scan detected: 7 attempts across 1 ports (443). | Evidence: GHOST_SCAN:IN=enp1s0f0 OUT= SRC=172.70.49.220 LEN=60 TOS=0x00 PREC=0x00 TTL=53 ID=23592 DF PROTO=TCP SPT=12757 DPT=443 WINDOW=65535 RES=0x00 SYN URGP=0
show less
Port Scan
πΊπΈ
mnsf
2025-11-06 18:05:39
(10 months ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
Anonymous
2025-08-09 18:53:53
(1 year ago)
access denied too many times (more than 12 attempts in 60 seconds)
...
Brute-Force
Web App Attack
πΊπΈ
mawan
2025-08-02 18:23:51
(1 year ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
π³π±
mawan
2025-08-02 06:27:45
(1 year ago)
Suspected of having performed illicit activity on AMS server.
Web App Attack
Anonymous
2025-08-01 05:51:05
(1 year ago)
[Fri Aug 01 07:51:04.245040 2025] [authz_core:error] [pid 20185] [client 172.70.49.220:14240] AH0163 ...
show more
[Fri Aug 01 07:51:04.245040 2025] [authz_core:error] [pid 20185] [client 172.70.49.220:14240] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri Aug 01 07:51:04.786294 2025] [authz_core:error] [pid 20185] [client 172.70.49.220:14240] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri Aug 01 07:51:05.032181 2025] [authz_core:error] [pid 20185] [client 172.70.49.220:14240] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
Anonymous
2025-07-29 22:42:12
(1 year ago)
[Wed Jul 30 00:42:11.571277 2025] [authz_core:error] [pid 18205] [client 172.70.49.220:42960] AH0163 ...
show more
[Wed Jul 30 00:42:11.571277 2025] [authz_core:error] [pid 18205] [client 172.70.49.220:42960] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Wed Jul 30 00:42:11.820734 2025] [authz_core:error] [pid 18205] [client 172.70.49.220:42960] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Wed Jul 30 00:42:12.068274 2025] [authz_core:error] [pid 18205] [client 172.70.49.220:42960] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
π³π±
mawan
2025-07-29 21:14:10
(1 year ago)
Suspected of having performed illicit activity on AMS server.
Web App Attack
π³π±
mawan
2025-07-25 02:05:53
(1 year ago)
Suspected of having performed illicit activity on AMS server.
Web App Attack