๐ง๐ฌ
Stoyko Stoykov
2026-07-28 04:48:47
(11 hours ago)
172.70.80.54 - - [28/Jul/2026:07:48:46 +0300] "GET /wp-content/plugins/hellopress/wp_filemanager.php ...
show more
172.70.80.54 - - [28/Jul/2026:07:48:46 +0300] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/2.0" 404 0 "-" "-"
...
show less
Hacking
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-07-25 16:58:59
(2 days ago)
172.70.80.54 - - [25/Jul/2026:19:58:59 +0300] "GET /wp-content/plugins/hellopress/wp_filemanager.php ...
show more
172.70.80.54 - - [25/Jul/2026:19:58:59 +0300] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 301 162 "-" "-"
...
show less
Hacking
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-07-15 19:41:23
(1 week ago)
172.70.80.54 - - [15/Jul/2026:22:41:22 +0300] "GET /ups.php HTTP/1.1" 301 162 "-" "-"
...
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 18:34:12
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 172.70.80.54 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.80.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 14:34:06.651853 2026] [security2:error] [pid 1462:tid 1462] [client 172.70.80.54:11562] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.callalbany.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.callalbany.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "ajwjHmjZEwmJ74Q2s2q3PwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
acadeova
2026-06-14 07:49:38
(1 month ago)
๐จ Recon detected (nft drop)
SRC=172.70.80.54
Observed=TCP dpt=80 in=enp0s6 ttl=56
Time=recent(journa ...
show more
๐จ Recon detected (nft drop)
SRC=172.70.80.54
Observed=TCP dpt=80 in=enp0s6 ttl=56
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐บ๐ธ
mnsf
2026-06-11 20:05:34
(1 month ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-06-09 13:06:27
(1 month ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-06-07 09:00:17
(1 month ago)
172.70.80.54 - - [07/Jun/2026:12:00:16 +0300] "GET /wp-content/plugins/hellopress/wp_filemanager.php ...
show more
172.70.80.54 - - [07/Jun/2026:12:00:16 +0300] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/2.0" 404 0 "-" "-"
...
show less
Hacking
Web App Attack
๐บ๐ธ
mnsf
2026-06-04 04:06:04
(1 month ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-05-28 08:02:10
(2 months ago)
172.70.80.54 - - [28/May/2026:11:02:10 +0300] "GET /wp-includes/ID3/about.php HTTP/1.1" 301 162 "-" ...
show more
172.70.80.54 - - [28/May/2026:11:02:10 +0300] "GET /wp-includes/ID3/about.php HTTP/1.1" 301 162 "-" "-"
...
show less
Hacking
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-05-18 11:21:17
(2 months ago)
172.70.80.54 - - [18/May/2026:14:21:08 +0300] "GET /wp-content/plugins/twenty/login.php HTTP/1.1" 40 ...
show more
172.70.80.54 - - [18/May/2026:14:21:08 +0300] "GET /wp-content/plugins/twenty/login.php HTTP/1.1" 404 789 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.70.80.54 - - [18/May/2026:14:21:16 +0300] "GET /amax.php HTTP/1.1" 404 789 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
Anonymous
2026-05-05 14:29:37
(2 months ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 21:58:12
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.54 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 17:58:07.456401 2026] [security2:error] [pid 2738525:tid 2738525] [client 172.70.80.54:14031] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.skeletron.com"] [uri "/.env.dev"] [unique_id "adbPb8JKJweldaVWu_bCFwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 01:14:12
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.54 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 21:14:09.089641 2026] [security2:error] [pid 945381:tid 945397] [client 172.70.80.54:9380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.charteredfinancialmanager.com"] [uri "/.env.staging"] [unique_id "adRaYbqyu9aCY1PBHBh8tAAAAQ0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 08:12:48
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.54 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 04:12:38.444055 2026] [security2:error] [pid 19263:tid 19263] [client 172.70.80.54:11186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.fourhillsco.com"] [uri "/site/.env"] [unique_id "adNq9lq8hL4fec5Ys6KY0wAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack