๐บ๐ธ
TPI-Abuse
2026-06-09 18:25:19
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 172.70.80.164 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.80.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 14:25:14.290614 2026] [security2:error] [pid 21280:tid 21280] [client 172.70.80.164:10814] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.blythewoodanimalhospital.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.blythewoodanimalhospital.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "aihaij-SZ6Kefo1H1fYx5AAAAGA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-06-09 03:20:24
(2 days ago)
172.70.80.164 - - [09/Jun/2026:06:20:23 +0300] "GET /wp-admin/install.php HTTP/1.1" 404 684 "-" "-"
...
show more
172.70.80.164 - - [09/Jun/2026:06:20:23 +0300] "GET /wp-admin/install.php HTTP/1.1" 404 684 "-" "-"
172.70.80.164 - - [09/Jun/2026:06:20:24 +0300] "GET /cgi-bin/admin.php HTTP/1.1" 404 245 "-" "-"
...
show less
Web App Attack
๐ฌ๐ง
sandra361
2026-05-26 17:53:05
(2 weeks ago)
Port scan detected: 48 attempts across 1 ports (443). | Evidence: REAPER_TARPIT:IN=enp1s0f0 OUT= SRC ...
show more
Port scan detected: 48 attempts across 1 ports (443). | Evidence: REAPER_TARPIT:IN=enp1s0f0 OUT= SRC=172.70.80.164 LEN=60 TOS=0x00 PREC=0x00 TTL=54 ID=7989 DF PROTO=TCP SPT=10800 DPT=443 WINDOW=65535 RES=0x00 SYN URGP=0
show less
Port Scan
๐ฉ๐ช
www.mammazone.it
2026-05-24 13:24:45
(2 weeks ago)
fabiodirauso.it:80 172.70.80.164 - - [24/May/2026:15:24:36 +0200] "GET /test1.php HTTP/1.1" 200 1970 ...
show more
fabiodirauso.it:80 172.70.80.164 - - [24/May/2026:15:24:36 +0200] "GET /test1.php HTTP/1.1" 200 19703 "-" "-"
fabiodirauso.it:80 172.70.80.164 - - [24/May/2026:15:24:43 +0200] "GET /config.php HTTP/1.1" 200 19703 "-" "-"
...
show less
Hacking
๐ง๐พ
lns.bz
2026-05-15 10:48:24
(3 weeks ago)
Too many 404 requests [BY]
Web App Attack
๐ฉ๐ช
acadeova
2026-05-14 15:21:16
(3 weeks ago)
๐จ Recon detected (nft drop)
SRC=172.70.80.164
Observed=TCP dpt=80 in=enp0s6 ttl=56
Time=recent(journ ...
show more
๐จ Recon detected (nft drop)
SRC=172.70.80.164
Observed=TCP dpt=80 in=enp0s6 ttl=56
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-04-08 15:42:24
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.164 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 11:42:16.868033 2026] [security2:error] [pid 2947015:tid 2947015] [client 172.70.80.164:12794] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.octaviomontes.com"] [uri "/.env.json"] [unique_id "adZ3WMj9jw7sSSd0Z2ScXAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 10:36:33
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.164 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 06:36:29.599918 2026] [security2:error] [pid 2661957:tid 2661957] [client 172.70.80.164:9937] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.isaacrivas.com"] [uri "/.env"] [unique_id "adYvrbN6Y-8Py6RJ3Yb9LwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 09:49:35
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.164 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 05:49:31.962508 2026] [security2:error] [pid 1000067:tid 1000163] [client 172.70.80.164:9917] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.davidchapamusic.com"] [uri "/.env.dist"] [unique_id "adTTK0OMnFhX_NMPE_XEjQAAAQ4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 09:03:06
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.164 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 05:02:58.996039 2026] [security2:error] [pid 1443276:tid 1443276] [client 172.70.80.164:11023] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.rememberingjohnhanson.com"] [uri "/.env"] [unique_id "adTIQuU3_qFYZp0ZekfoIAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 17:31:13
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.164 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 13:31:02.918684 2026] [security2:error] [pid 218524:tid 218524] [client 172.70.80.164:9264] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "colbygrenier.com.jimgrenier.com"] [uri "/.env.production.local"] [unique_id "adPt1vNCKNjRlDPu8P2zdQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 17:02:36
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.164 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 13:02:32.106885 2026] [security2:error] [pid 10191:tid 10191] [client 172.70.80.164:9593] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mvpbees.com"] [uri "/.env.production"] [unique_id "adKVqFDgu_ljB0-1w71nogAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 12:56:14
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.164 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 08:56:07.443862 2026] [security2:error] [pid 22225:tid 22234] [client 172.70.80.164:9620] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "internationalbusinessschool.org"] [uri "/.env.bak"] [unique_id "adJb59iznFY0-4moLBJf2wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 08:18:04
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.164 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 04:17:59.062641 2026] [security2:error] [pid 31115:tid 31115] [client 172.70.80.164:11510] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.parkhan.com"] [uri "/.env.production"] [unique_id "adIat9lsqbOx2rOWv1nrxQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 20:04:32
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.164 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 16:04:26.290432 2026] [security2:error] [pid 20884:tid 20884] [client 172.70.80.164:9436] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.cottrillcyclodyne.com"] [uri "/.env.php"] [unique_id "adFuypy6Q0GQarCz2Y5hzAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack