๐ฉ๐ช
ghostwarriors
2026-08-24 16:50:06
(1 day ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-08-24 16:38:56
(1 day ago)
172.70.50.76 - - [24/Aug/2026:18:38:48 +0200] "GET /wp-content/plugins/admin.php HTTP/2.0" 404 357 " ...
show more
172.70.50.76 - - [24/Aug/2026:18:38:48 +0200] "GET /wp-content/plugins/admin.php HTTP/2.0" 404 357 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.70.50.76 - - [24/Aug/2026:18:38:48 +0200] "GET /wk/index.php HTTP/2.0" 404 289 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.70.50.76 - - [24/Aug/2026:18:38:49 +0200] "GET /elp.php HTTP/2.0" 404 318 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.70.50.76 - - [24/Aug/2026:18:38:49 +0200] "GET /.tmb/cloud.php HTTP/2.0" 404 289 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.70.50.76 - - [24/Aug/2026:18:38:54 +0200] "GET /.well-known HTTP/2.0" 404 357 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.
show less
Web App Attack
Hacking
๐ง๐ช
madeit
2026-08-21 16:23:45
(4 days ago)
Web App Attack
๐จ๐ฆ
internetworld
2026-08-16 07:29:32
(1 week ago)
172.70.50.76 - - [16/Aug/2026:07:29:29 +0000] "GET /.git/config HTTP/2.0" 200 314 "-" "Mozilla/5.0 ( ...
show more
172.70.50.76 - - [16/Aug/2026:07:29:29 +0000] "GET /.git/config HTTP/2.0" 200 314 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:126.0) Gecko/20100101 Firefox/126.0"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
yitzhaq
2026-08-01 22:01:04
(3 weeks ago)
172.70.50.76 - - [01/Aug/2026:04:36:07 +0200] "GET /tt.php HTTP/2.0" 404 341 "-" "Mozilla/5.0 (Windo ...
show more
172.70.50.76 - - [01/Aug/2026:04:36:07 +0200] "GET /tt.php HTTP/2.0" 404 341 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.70.50.76 - - [01/Aug/2026:04:36:08 +0200] "GET /FYbLA.php HTTP/2.0" 404 78 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.70.50.76 - - [01/Aug/2026:04:36:08 +0200] "GET /bdkr28.php HTTP/2.0" 404 55 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.70.50.76 - - [01/Aug/2026:04:36:08 +0200] "GET /wp-ws68.php HTTP/2.0" 404 55 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.70.50.76 - - [01/Aug/2026:04:36:08 +0200] "GET /bmlfvgdl.php HTTP/2.0" 404 55 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.70.50.7
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-31 09:01:26
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 172.70.50.76 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.50.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 05:01:22.416162 2026] [security2:error] [pid 30508:tid 30508] [client 172.70.50.76:10280] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.menzelassociates.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.menzelassociates.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "amxkYvOhwKjyINyYhyo1xgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
yitzhaq
2026-07-27 04:42:45
(4 weeks ago)
172.70.50.76 - - [27/Jul/2026:06:42:43 +0200] "GET /wp-content/plugins/twenty/login.php HTTP/2.0" 40 ...
show more
172.70.50.76 - - [27/Jul/2026:06:42:43 +0200] "GET /wp-content/plugins/twenty/login.php HTTP/2.0" 404 357 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.70.50.76 - - [27/Jul/2026:06:42:43 +0200] "GET /404.php HTTP/2.0" 404 295 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.70.50.76 - - [27/Jul/2026:06:42:43 +0200] "GET /file3.php HTTP/2.0" 404 55 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.70.50.76 - - [27/Jul/2026:06:42:44 +0200] "GET /wp-mail.php HTTP/2.0" 404 78 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.70.50.76 - - [27/Jul/2026:06:42:44 +0200] "GET /about.php HTTP/2.0" 404 55 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Sa
show less
Web App Attack
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-06-16 22:02:23
(2 months ago)
Auto-ban: >3000 req/min op 2026-06-16
Web App Attack
SSH
Hacking
๐บ๐ธ
mnsf
2026-06-13 06:05:42
(2 months ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-06-11 06:05:51
(2 months ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 15:27:52
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 172.70.50.76 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.50.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 11:27:48.957782 2026] [security2:error] [pid 13166:tid 13166] [client 172.70.50.76:13143] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.bendergloves.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.bendergloves.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "aiBH9Gifrj1_q_TFlTuIUAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-17 13:52:07
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 172.70.50.76 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.50.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 09:52:01.277740 2026] [security2:error] [pid 9690:tid 9697] [client 172.70.50.76:12554] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.a2zlns.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.a2zlns.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "agnIATNXaiFt1NZI_XhZ_wAAAMM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-11 11:00:06
(3 months ago)
Web App Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 16:14:16
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.50.76 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.50.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 12:14:12.398537 2026] [security2:error] [pid 2453744:tid 2453744] [client 172.70.50.76:12206] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.mydobdate.net"] [uri "/.git/index"] [unique_id "adZ-1FgkK5qx2W8er6oqZQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 19:46:55
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.50.76 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.50.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 15:46:49.671659 2026] [security2:error] [pid 1742571:tid 1742571] [client 172.70.50.76:11540] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.clinchspurs.com"] [uri "/.env.development.local"] [unique_id "adVfKYyFn4nKyJlkE58whwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack