π―π΅
S.O.B.A. Dev.
2026-09-27 23:30:03
(1 day ago)
Persistent port scanning or vulnerability scanning
Port Scan
π§πͺ
madeit
2026-09-18 18:10:19
(1 week ago)
Web App Attack
π©πͺ
LavrinenkoRM
2026-09-14 18:24:52
(2 weeks ago)
Sentinel WAF: web/rozfarbui.org.ua; scanner path; confidence=90; blocked_at=2026-09-14T18:24:17.0761 ...
show more
Sentinel WAF: web/rozfarbui.org.ua; scanner path; confidence=90; blocked_at=2026-09-14T18:24:17.076158+00:00
show less
Port Scan
π§πΎ
lns.bz
2026-08-27 03:24:13
(1 month ago)
Too many 404 requests [BY]
Web App Attack
π§πΎ
lns.bz
2026-08-13 19:02:14
(1 month ago)
Too many 404 requests [BY]
Web App Attack
π§πͺ
madeit
2026-08-12 21:36:57
(1 month ago)
Web App Attack
Anonymous
2026-07-13 10:58:01
(2 months ago)
[Mon Jul 13 12:57:59.718794 2026] [authz_core:error] [pid 26897] [client 172.70.80.188:13655] AH0163 ...
show more
[Mon Jul 13 12:57:59.718794 2026] [authz_core:error] [pid 26897] [client 172.70.80.188:13655] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon Jul 13 12:57:59.980587 2026] [authz_core:error] [pid 26897] [client 172.70.80.188:13655] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon Jul 13 12:58:00.113416 2026] [authz_core:error] [pid 26897] [client 172.70.80.188:13655] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
π©πͺ
FeG Deutschland
2026-06-06 16:40:54
(3 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
πΊπΈ
octageeks.com
2026-05-18 04:08:47
(4 months ago)
Wordpress malicious attack:[octawp]
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-17 14:33:05
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 172.70.80.188 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.80.188 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 10:32:58.933027 2026] [security2:error] [pid 16291:tid 16327] [client 172.70.80.188:10244] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.backcountrygardens.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.backcountrygardens.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "agnRmrpKEcAvivoUm9oaJgAAAIc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
COMPLEX
2026-05-06 03:13:28
(4 months ago)
Unsolicited TCP traffic | Action: DROP | Port 2087
Brute-Force
πΊπ¦
URAN Publishing Service
2026-04-11 05:45:38
(5 months ago)
172.70.80.188 - - [11/Apr/2026:08:45:37 +0300] "GET /amax.php HTTP/1.1" 404 769 "-" "Mozilla/5.0 (X1 ...
show more
172.70.80.188 - - [11/Apr/2026:08:45:37 +0300] "GET /amax.php HTTP/1.1" 404 769 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0"
172.70.80.188 - - [11/Apr/2026:08:45:38 +0300] "GET /wp-content/hello.php HTTP/1.1" 404 769 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36"
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-08 20:07:45
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.188 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.188 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 16:07:36.603518 2026] [security2:error] [pid 3492580:tid 3492580] [client 172.70.80.188:10492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.mindtekt.com"] [uri "/.env~"] [unique_id "ada1iJxgkDV40vmrBjvZ4gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-08 01:25:17
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.188 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.188 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 21:25:03.155429 2026] [security2:error] [pid 1908542:tid 1908542] [client 172.70.80.188:11847] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "9288889602.com.kingmanrents.com"] [uri "/.env.save"] [unique_id "adWub9TPWZZp582AOAO4igAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-07 05:56:39
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.188 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.188 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 01:56:34.812228 2026] [security2:error] [pid 786648:tid 786648] [client 172.70.80.188:11548] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.thewritekellys.com"] [uri "/.env1"] [unique_id "adSckldZx5hCv4_r44WpxAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack