๐ซ๐ท
dynamix
2026-10-09 04:35:21
(17 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-30 03:45:15
(1 week ago)
172.70.50.161 - - [30/Sep/2026:03:45:14 +0000] "GET //js/kcfinder/upload.php HTTP/2.0" 404 198 "-" " ...
show more
172.70.50.161 - - [30/Sep/2026:03:45:14 +0000] "GET //js/kcfinder/upload.php HTTP/2.0" 404 198 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36" "143.110.223.161"
172.70.50.161 - - [30/Sep/2026:03:45:15 +0000] "GET //asset/kcfinder/upload.php HTTP/2.0" 404 198 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36" "143.110.223.161"
172.70.50.161 - - [30/Sep/2026:03:45:15 +0000] "GET //assets/js/kcfinder/upload.php HTTP/2.0" 404 198 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36" "143.110.223.161"
172.70.50.161 - - [30/Sep/2026:03:45:15 +0000] "GET //core/scripts/kcfinder/upload.php HTTP/2.0" 404 198 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36" "143.110.223.161"
172.70.50.161 - - [30/Sep/2026:03:45:15 +0000] "GET //js
...
show less
Port Scan
Brute-Force
๐ง๐ช
madeit
2026-09-23 17:05:20
(2 weeks ago)
Web App Attack
๐ซ๐ท
dynamix
2026-09-23 15:09:16
(2 weeks ago)
Multiple WAF Violations
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-09-21 20:45:52
(2 weeks ago)
172.70.50.161 - - [21/Sep/2026:23:45:51 +0300] "GET /.env.bak HTTP/2.0" 404 176 "-" "Mozilla/5.0 (X1 ...
show more
172.70.50.161 - - [21/Sep/2026:23:45:51 +0300] "GET /.env.bak HTTP/2.0" 404 176 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Hacking
Web App Attack
๐ฌ๐ง
cg-design.co.uk
2026-09-20 14:47:18
(2 weeks ago)
(mod_security) mod_security triggered on hostname [redacted] 172.70.50.161 (CA/Canada/-)
SQL Injection
๐ซ๐ท
dynamix
2026-09-16 02:35:54
(3 weeks ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
chrisj
2026-09-15 12:01:40
(3 weeks ago)
[Tue Sep 15 12:01:40.016570 2026] [proxy_fcgi:error] [pid 9043:tid 9056] [remote 172.70.50.161:11585 ...
show more
[Tue Sep 15 12:01:40.016570 2026] [proxy_fcgi:error] [pid 9043:tid 9056] [remote 172.70.50.161:11585] AH01071: Got error 'Primary script unknown'
[Tue Sep 15 12:01:40.114372 2026] [proxy_fcgi:error] [pid 9043:tid 9057] [remote 172.70.50.161:11585] AH01071: Got error 'Primary script unknown'
[Tue Sep 15 12:01:40.215083 2026] [proxy_fcgi:error] [pid 9043:tid 9058] [remote 172.70.50.161:11585] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Anonymous
2026-08-25 18:10:02
(1 month ago)
| SQL injection attempt.
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
mawan
2026-08-12 02:17:23
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ง๐ช
madeit
2026-08-06 05:11:39
(2 months ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-12 07:37:47
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 172.70.50.161 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.50.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 12 03:37:40.357611 2026] [security2:error] [pid 23847:tid 23847] [client 172.70.50.161:11062] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.sanvayu.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.sanvayu.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "alNERBHwSbc7XlYVrNhaGQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-29 23:58:35
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 172.70.50.161 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.50.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 19:58:31.367031 2026] [security2:error] [pid 4640:tid 4640] [client 172.70.50.161:11701] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.rjhills.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.rjhills.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "akMGp5dbdLlC6KwT_rwV8gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-27 04:09:36
(3 months ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 23:25:35
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 172.70.50.161 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.50.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 19:25:29.983348 2026] [security2:error] [pid 19871:tid 19871] [client 172.70.50.161:14114] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.surrenderhouse.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.surrenderhouse.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "aitD6W0LSU8Z6duwo-LEHwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack