πΈπ¬
celestialcity
2026-09-30 04:12:22
(3 hours ago)
Blocked by UFW on celestialcityas [8443/tcp] | SPT: 12292 | TTL: 49 | LEN: 60 | TOS: 0x00 β’ Reported ...
show more
Blocked by UFW on celestialcityas [8443/tcp] | SPT: 12292 | TTL: 49 | LEN: 60 | TOS: 0x00 β’ Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-09-29 20:39:02
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.70.92.168 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.92.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 16:38:51.940792 2026] [security2:error] [pid 10317:tid 10317] [client 172.70.92.168:11833] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whore-cams.com"] [uri "/.env.dist"] [unique_id "arwh24fEW5mb5MOdJ2909wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
BlueWire Hosting
2026-09-26 20:45:54
(3 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack
π§πͺ
madeit
2026-09-18 15:26:13
(1 week ago)
Web App Attack
Anonymous
2026-09-14 00:47:25
(2 weeks ago)
(caddyscan) Scanner path probe from 172.70.92.168 (SG/Singapore/-): 5 in the last 3600 secs; Ports: ...
show more
(caddyscan) Scanner path probe from 172.70.92.168 (SG/Singapore/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 172.70.92.168 - - [14/Sep/2026:00:47:18 +0000] "GET /.env.preprod HTTP/1.1"
[REDACTED] 200 2627 172.70.92.168 - - [14/Sep/2026:00:47:19 +0000] "GET /.env~ HTTP/1.1"
[REDACTED] 200 2627 172.70.92.168 - - [14/Sep/2026:00:47:21 +0000] "GET /.env.yaml HTTP/1.1"
[REDACTED] 200 2627 172.70.92.168 - - [14/Sep/2026:00:47:22 +0000] "GET /web/.env HTTP/1.1"
[REDACTED] 200 2627 172.70.92.168 - - [14/Sep/2026:00:47:22 +0000] "GET /site/.env HTTP/1.1"
show less
Port Scan
π³π±
homeshowdomain.nl
2026-09-09 22:02:09
(2 weeks ago)
Auto-ban: >3000 req/min op 2026-09-09
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-09-08 20:32:52
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.92.168 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.92.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 16:32:48.367416 2026] [security2:error] [pid 28226:tid 28226] [client 172.70.92.168:13394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ultimatesportswrap.com"] [uri "/.env.test"] [unique_id "aqBw8Kilm0UGCLbrApRybwAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 22:28:05
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.92.168 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.92.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 18:28:00.370974 2026] [security2:error] [pid 23142:tid 23142] [client 172.70.92.168:14047] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.advantage-plus.net"] [uri "/.git/HEAD"] [unique_id "aoOK8IPImGwcx_RQ1KtNCwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 09:14:49
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.92.168 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.92.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 05:14:43.971092 2026] [security2:error] [pid 25243:tid 25243] [client 172.70.92.168:12791] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.kinkycouple4u.com"] [uri "/.git/HEAD"] [unique_id "aoLRA0_lMq53uIGHoV7_RQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 03:04:29
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.92.168 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.92.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 23:04:22.720287 2026] [security2:error] [pid 13889:tid 13889] [client 172.70.92.168:12901] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "certifiedfarmersmarkets.org"] [uri "/.git/HEAD"] [unique_id "aoJ6NmHw4JfNikI3zIamCgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
madeit
2026-08-13 16:53:52
(1 month ago)
Web App Attack
π§πͺ
madeit
2026-08-06 13:50:40
(1 month ago)
Web App Attack
π¦πΊ
trentwiles.com
2026-05-04 20:46:12
(4 months ago)
Unauthorized connection attempt detected from IP address 172.70.92.168 to port 80 [SYD]
Port Scan
πΈπ¬
drewf.ink
2026-03-18 05:34:38
(6 months ago)
[05:34] Port scanning. Port(s) scanned: TCP/8443
Port Scan
π¨π³
ThreatBook.io
2025-12-26 00:57:06
(9 months ago)
2025-12-25 08:45:41 /docs/security-howto.html
2025-12-25 04:28:07 /sendgrid/.env
Web App Attack