Anonymous
2026-06-20 08:04:36
(11 hours ago)
Aggressive web scan
Web App Attack
πΊπΈ
mawan
2026-06-19 02:23:28
(1 day ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
Anonymous
2026-06-17 14:49:59
(3 days ago)
Aggressive web scan
Web App Attack
π©πͺ
FeG Deutschland
2026-06-13 10:34:43
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
π©πͺ
Blexyel
2026-05-24 10:25:43
(3 weeks ago)
172.70.80.28 - - [24/May/2026:12:25:38 +0200] "GET /wp-login.php HTTP/1.1" 451 33 "-" "-"
...
Brute-Force
Web App Attack
π©πͺ
Blexyel
2026-05-10 18:39:53
(1 month ago)
172.70.80.28 - - [10/May/2026:20:39:53 +0200] "GET /wp-includes/theme-compat/wp-login.php HTTP/1.1" ...
show more
172.70.80.28 - - [10/May/2026:20:39:53 +0200] "GET /wp-includes/theme-compat/wp-login.php HTTP/1.1" 404 13 "-" "-" "ip.pingusmc.org"
...
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-19 21:01:17
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 172.70.80.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.80.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 19 17:01:14.476214 2026] [security2:error] [pid 2351155:tid 2351155] [client 172.70.80.28:9524] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.jinkokyudojo.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.jinkokyudojo.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "aeVCmkOeSe64lgr_kfc59wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π¦
yukon.ca
2026-04-13 08:58:20
(2 months ago)
Web Server Enforcement Violation: ALFA Webshell Over HTTP
Port:80
Hacking
Exploited Host
π©πͺ
acadeova
2026-04-11 18:13:55
(2 months ago)
π¨ Recon detected (nft drop)
SRC=172.70.80.28
Observed=TCP dpt=80 in=enp0s6 ttl=56
Time=recent(journa ...
show more
π¨ Recon detected (nft drop)
SRC=172.70.80.28
Observed=TCP dpt=80 in=enp0s6 ttl=56
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-04-08 22:57:06
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 18:57:01.523520 2026] [security2:error] [pid 3509351:tid 3509351] [client 172.70.80.28:10408] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aslproud.deafinitely.com"] [uri "/private/.env"] [unique_id "adbdPSAwuYqXADsOFqvszQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-08 01:25:18
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 21:25:02.456049 2026] [security2:error] [pid 1907817:tid 1907817] [client 172.70.80.28:12629] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "9288889602.com.kingmanrents.com"] [uri "/.env"] [unique_id "adWubnlXk9Nvq-zPZb8iNQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-07 16:43:59
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 12:43:52.305934 2026] [security2:error] [pid 1030521:tid 1030539] [client 172.70.80.28:13849] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sandbarsteve.com"] [uri "/private/.env"] [unique_id "adU0SGwDxZCN0xCq71PvcAAAANA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-05 09:59:55
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 05:59:50.428236 2026] [security2:error] [pid 28486:tid 28486] [client 172.70.80.28:9575] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.alccontractorsllc.com"] [uri "/.env.production.local"] [unique_id "adIylkjUK1ojeCUtKnvu0gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-05 01:36:11
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 21:35:53.414930 2026] [security2:error] [pid 9544:tid 9544] [client 172.70.80.28:9897] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.genesis-one.com"] [uri "/.env.production"] [unique_id "adG8ee2qv-NvC5G2ZlNQUgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-04 22:20:34
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 18:20:28.333095 2026] [security2:error] [pid 24909:tid 24909] [client 172.70.80.28:10821] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.wonboyn.com"] [uri "/.env.dev"] [unique_id "adGOrAHVusn6D2myo3yrsQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack