๐ฌ๐ง
OptimusGO
2026-06-29 01:53:14
(1 day ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-06-29 02:53:14 UTC
Log evidence:
172.70.80.138 - - [29/Jun/2026:02:53:13 +0100] "GET /wp2/wp-includes/wlwmanifest.xml HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
172.70.80.138 - - [29/Jun/2026:02:53:13 +0100] "GET /site/wp-includes/wlwmanifest.xml HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
172.70.80.138 - - [29/Jun/2026:02:53:13 +0100] "GET /cms/wp-includes/wlwmanifest.xml HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
show less
Port Scan
Brute-Force
๐ณ๐ฑ
homeshowdomain.nl
2026-06-11 22:00:37
(2 weeks ago)
Auto-ban: >3000 req/min op 2026-06-11
Web App Attack
SSH
Hacking
๐บ๐ธ
mnsf
2026-06-04 03:05:25
(3 weeks ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-06-03 20:05:44
(3 weeks ago)
Abuse Detected (2)
Brute-Force
Web App Attack
Anonymous
2026-05-12 18:54:44
(1 month ago)
Web Probe / Attack
Web App Attack
Anonymous
2026-04-20 10:27:32
(2 months ago)
Web Probe / Attack
Web App Attack
Anonymous
2026-04-19 02:50:25
(2 months ago)
Web Probe / Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 16:15:42
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.138 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 12:15:37.538149 2026] [security2:error] [pid 3100611:tid 3100611] [client 172.70.80.138:9258] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.trapper.biz"] [uri "/.env.backup"] [unique_id "adZ_KQbijNOKGH8SofniSwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 23:43:36
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.138 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 19:43:31.116702 2026] [security2:error] [pid 1674192:tid 1674192] [client 172.70.80.138:13864] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.gunningphysio.com"] [uri "/.env.local"] [unique_id "adWWox8dh6ksMkO5IRi2PAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 18:36:58
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.138 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 14:36:53.958497 2026] [security2:error] [pid 416485:tid 416485] [client 172.70.80.138:10857] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.medicalexchangeasinc.com"] [uri "/.env.test"] [unique_id "adP9RUvRNMFPB0RK0At9ywAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 12:07:34
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.138 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 08:07:25.795591 2026] [security2:error] [pid 26058:tid 26058] [client 172.70.80.138:12477] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "reporting.thereddoorlounge.com"] [uri "/private/.env"] [unique_id "adJQfWRylOuhs-nQWiwiZgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 10:15:15
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.138 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 06:15:11.555569 2026] [security2:error] [pid 11368:tid 11368] [client 172.70.80.138:12065] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.drgracetomastolentino.com"] [uri "/config/.env"] [unique_id "adI2LzhT1akCb_GG2VsV5QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 03:13:38
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.138 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 23:13:32.292953 2026] [security2:error] [pid 4945:tid 4945] [client 172.70.80.138:10620] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.purlandpurr.com"] [uri "/.env.test"] [unique_id "adHTXDJjwcVz7VFewpAFDgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 00:27:22
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.138 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 20:27:16.887680 2026] [security2:error] [pid 10719:tid 10738] [client 172.70.80.138:13648] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.killerrockandroll.com"] [uri "/admin/.env"] [unique_id "adGsZBy5oOgbuS3ug8etmAAAAIg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 18:58:09
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.138 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 14:58:03.064947 2026] [security2:error] [pid 11077:tid 11077] [client 172.70.80.138:9878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.demircan.org"] [uri "/.env_backup"] [unique_id "adFfOwjzAgbfHkk4EINUCQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack