πΊπΈ
TPI-Abuse
2026-06-25 02:04:47
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.60 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.60 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 22:04:43.577225 2026] [security2:error] [pid 18106:tid 18106] [client 172.70.80.60:9761] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thegreatleapforward.com.herecometheplanes.com"] [uri "/.env.production"] [unique_id "ajyMu_eX4Fb302OE2OFWcwAAABY"], referer: https://www.google.com/search?q=thegreatleapforward.com.herecometheplanes.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-24 19:57:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.60 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.60 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 15:57:52.377645 2026] [security2:error] [pid 28116:tid 28116] [client 172.70.80.60:22105] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "randykincaid.com"] [uri "/.env.old"] [unique_id "ajw2wIFpAQ_yppAZ_DziMwAAAAI"], referer: https://www.google.com/search?q=randykincaid.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-06-24 16:20:32
(1 day ago)
172.70.80.60 - - [24/Jun/2026:19:20:29 +0300] "GET /wp-content/uploads/index.php HTTP/1.1" 404 789 " ...
show more
172.70.80.60 - - [24/Jun/2026:19:20:29 +0300] "GET /wp-content/uploads/index.php HTTP/1.1" 404 789 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.70.80.60 - - [24/Jun/2026:19:20:32 +0300] "GET /wp-admin/user.php HTTP/1.1" 404 789 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
πΊπ¦
URAN Publishing Service
2026-06-23 10:03:28
(2 days ago)
172.70.80.60 - - [23/Jun/2026:13:03:20 +0300] "GET /wp-content/uploads/index.php HTTP/1.1" 404 789 " ...
show more
172.70.80.60 - - [23/Jun/2026:13:03:20 +0300] "GET /wp-content/uploads/index.php HTTP/1.1" 404 789 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.70.80.60 - - [23/Jun/2026:13:03:26 +0300] "GET /wp-admin/user.php HTTP/1.1" 404 789 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-21 07:12:25
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.60 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.60 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 03:12:17.767579 2026] [security2:error] [pid 21860:tid 21981] [client 172.70.80.60:11879] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gestorialuengo.gestorialuengo.com"] [uri "/.git/config"] [unique_id "ajeO0QWA2nKbsaKdkTTcFgAAAhU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-06-15 19:17:01
(1 week ago)
172.70.80.60 - - [15/Jun/2026:22:16:58 +0300] "GET /wp-content/themes/seotheme/mar.php HTTP/1.1" 404 ...
show more
172.70.80.60 - - [15/Jun/2026:22:16:58 +0300] "GET /wp-content/themes/seotheme/mar.php HTTP/1.1" 404 789 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.70.80.60 - - [15/Jun/2026:22:17:00 +0300] "GET /wp-admin/js/autoload_classmap.php HTTP/1.1" 404 789 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
π³π±
homeshowdomain.nl
2026-06-10 22:00:46
(2 weeks ago)
Auto-ban: >3000 req/min op 2026-06-10
Web App Attack
SSH
Hacking
Anonymous
2026-06-04 03:51:54
(3 weeks ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-01 23:44:07
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 172.70.80.60 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.80.60 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 19:43:59.372966 2026] [security2:error] [pid 18670:tid 18670] [client 172.70.80.60:11412] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.ronniescedarinn.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.ronniescedarinn.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "ah4ZP4IJ81VuC835b8PJrgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-01 19:56:30
(3 weeks ago)
Web App Attack
Brute-Force
Web App Attack
πΊπ¦
URAN Publishing Service
2026-05-30 19:14:52
(3 weeks ago)
172.70.80.60 - - [30/May/2026:22:14:47 +0300] "GET /wp-login.php HTTP/1.1" 404 3349 "-" "Mozilla/5.0 ...
show more
172.70.80.60 - - [30/May/2026:22:14:47 +0300] "GET /wp-login.php HTTP/1.1" 404 3349 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.70.80.60 - - [30/May/2026:22:14:51 +0300] "GET /xmlrpc.php HTTP/1.1" 404 789 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
Anonymous
2026-05-27 16:11:47
(4 weeks ago)
Web App Attack
Brute-Force
Web App Attack
πΊπ¦
URAN Publishing Service
2026-05-25 14:21:29
(1 month ago)
172.70.80.60 - - [25/May/2026:17:21:26 +0300] "GET /wp-content/plugins/hellopress/wp_filemanager.php ...
show more
172.70.80.60 - - [25/May/2026:17:21:26 +0300] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 404 768 "-" "-"
172.70.80.60 - - [25/May/2026:17:21:28 +0300] "GET /wp-content/plugins/twenty/login.php HTTP/1.1" 404 683 "-" "-"
...
show less
Web App Attack
Anonymous
2026-05-21 08:07:39
(1 month ago)
Web App Attack
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-08 14:31:14
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 172.70.80.60 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.80.60 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 10:31:10.487500 2026] [security2:error] [pid 17190:tid 17190] [client 172.70.80.60:9610] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.jeranny.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.jeranny.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "af3zrmJoak15GAaoMGyrUwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack