๐บ๐ธ
TPI-Abuse
2026-06-21 01:38:53
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 21:38:48.783662 2026] [security2:error] [pid 11225:tid 11225] [client 172.71.118.252:12363] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "galvanizetm.com.thinkingepic.com"] [uri "/.git/config"] [unique_id "ajdAqJHRKbyIOO_DcJ3ZBwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
INTEQ
2026-06-19 23:37:16
(1 day ago)
Web attack from 172.71.118.252
Web App Attack
Anonymous
2026-06-17 14:02:36
(4 days ago)
172.71.118.252 - - [17/Jun/2026:16:02:34 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 184 ...
show more
172.71.118.252 - - [17/Jun/2026:16:02:34 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
172.71.118.252 - - [17/Jun/2026:16:02:35 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
172.71.118.252 - - [17/Jun/2026:16:02:35 +0200] "GET //wp/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
172.71.118.252 - - [17/Jun/2026:16:02:35 +0200] "GET //2019/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
172.71.118.252 - - [17/Jun/2026:16:02:36 +0200] "GET //shop/wp-includes/wlwmanifest.xml HTTP/1.1" 40
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
Blexyel
2026-06-14 13:13:40
(1 week ago)
172.71.118.252 - - [14/Jun/2026:15:13:39 +0200] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 ...
show more
172.71.118.252 - - [14/Jun/2026:15:13:39 +0200] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 13 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-06-11 04:10:55
(1 week ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐บ๐ธ
mnsf
2026-06-04 12:05:32
(2 weeks ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
mawan
2026-04-21 11:06:48
(2 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
mnsf
2026-03-21 22:05:09
(2 months ago)
Scanning/Probing (16)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-03-20 12:05:51
(3 months ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-03-19 11:05:44
(3 months ago)
Scanning/Probing (15)
Brute-Force
Web App Attack
๐ฒ๐น
Malta
2026-03-05 08:05:03
(3 months ago)
172.71.118.252 - - [05/Mar/2026:09:05:03 +0100] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows ...
show more
172.71.118.252 - - [05/Mar/2026:09:05:03 +0100] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
๐ณ๐ฑ
wolfemium
2026-02-14 14:12:20
(4 months ago)
172.71.118.252 - - [14/Feb/2026:16:12:18 +0200] "GET /wp-admin/about.php HTTP/1.1" 502 150 "-" "-"
1 ...
show more
172.71.118.252 - - [14/Feb/2026:16:12:18 +0200] "GET /wp-admin/about.php HTTP/1.1" 502 150 "-" "-"
172.71.118.252 - - [14/Feb/2026:16:12:19 +0200] "GET /gmo.php HTTP/1.1" 502 150 "-" "-"
172.71.118.252 - - [14/Feb/2026:16:12:19 +0200] "GET /wp-includes/ID3/about.php HTTP/1.1" 502 150 "-" "-"
172.71.118.252 - - [14/Feb/2026:16:12:19 +0200] "GET /css/index.php HTTP/1.1" 502 150 "-" "-"
172.71.118.252 - - [14/Feb/2026:16:12:19 +0200] "GET /wp-includes/SimplePie/wp-login.php HTTP/1.1" 502 150 "-" "-"
172.71.118.252 - - [14/Feb/2026:16:12:19 +0200] "GET /wp-content/themes/about.php HTTP/1.1" 502 150 "-" "-"
...
show less
DDoS Attack
๐ณ๐ฑ
wolfemium
2026-02-04 22:17:31
(4 months ago)
172.71.118.252 - - [05/Feb/2026:00:17:31 +0200] "GET /dashboard/i.php HTTP/1.1" 502 150 "-" "curl/8. ...
show more
172.71.118.252 - - [05/Feb/2026:00:17:31 +0200] "GET /dashboard/i.php HTTP/1.1" 502 150 "-" "curl/8.7.1"
172.71.118.252 - - [05/Feb/2026:00:17:31 +0200] "GET /dashboard/info.php HTTP/1.1" 502 150 "-" "curl/8.7.1"
172.71.118.252 - - [05/Feb/2026:00:17:31 +0200] "GET /dashboard/phpinfo.php HTTP/1.1" 502 150 "-" "curl/8.7.1"
172.71.118.252 - - [05/Feb/2026:00:17:31 +0200] "GET /dashboard/test.php HTTP/1.1" 502 150 "-" "curl/8.7.1"
172.71.118.252 - - [05/Feb/2026:00:17:31 +0200] "GET /db.php HTTP/1.1" 502 150 "-" "curl/8.7.1"
172.71.118.252 - - [05/Feb/2026:00:17:31 +0200] "GET /debug.php HTTP/1.1" 502 150 "-" "curl/8.7.1"
...
show less
DDoS Attack
๐บ๐ธ
thefoofighter
2025-07-19 23:15:10
(11 months ago)
[Sat Jul 19 23:15:10.434892 2025] [:error] [pid 552171] [client 172.71.118.252:64506] [client 172.71 ...
show more
[Sat Jul 19 23:15:10.434892 2025] [:error] [pid 552171] [client 172.71.118.252:64506] [client 172.71.118.252] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "93"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "sarahmcnally.com"] [uri "/.env"] [unique_id "aHwm_rWHP8DY1HFvZ2f2ygAAABw"]
[Sat Jul 19 23:15:10.593079 2025] [:error] [pid 552171] [client 172.71.118.252:64506] [client 172.71.118.252] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "93"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2025-07-06 02:15:19
(11 months ago)
Multiple WAF Violations
Web App Attack