๐บ๐ธ
TPI-Abuse
2026-10-01 13:42:55
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 27.34.69.70 (70.69.34.27.dynamic.wlink.com.np): ...
show more
(mod_security) mod_security (id:210350) triggered by 27.34.69.70 (70.69.34.27.dynamic.wlink.com.np): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:42:47.607628 2026] [security2:error] [pid 3265:tid 3265] [client 27.34.69.70:64452] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||silsby.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "silsby.com"] [uri "/"] [unique_id "ar5jVyRKfRus2fHiIPJHqAAAAAg"], referer: https://linkmonitoring.website/dir/organic-seo-links-190213
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-09-01 01:54:51
(1 month ago)
Bogus Useragent: 27.34.69.70 - - [01/Sep/2026:03:54:51 +0200] "GET /protocol?id=st_3_68&offset=250&s ...
show more
Bogus Useragent: 27.34.69.70 - - [01/Sep/2026:03:54:51 +0200] "GET /protocol?id=st_3_68&offset=250&seq=278 HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; MSIE 8.0; Windows NT 5.2; Trident/3.0)" asn=17501 org="WorldLink Communications" country=NP
...
show less
Bad Web Bot
๐บ๐ธ
kosada.com
2026-08-31 12:34:23
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐ฎ๐ฉ
sockominfo
2026-08-12 11:01:00
(1 month ago)
Zimbra: Login failures from malicious IP: 27.34.69.70. Threat Score: 6.3/10 (MEDIUM). Confidence: 40 ...
show more
Zimbra: Login failures from malicious IP: 27.34.69.70. Threat Score: 6.3/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 4.6/10 (Medium). CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L. Bayesian Probability: 77%. MITRE ATT&CK: T1083 (File and Directory Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-08-12 10:00:09
(1 month ago)
Zimbra: Login failures from malicious IP: 27.34.69.70. Threat Score: 6/10 (MEDIUM). Reported by Tang ...
show more
Zimbra: Login failures from malicious IP: 27.34.69.70. Threat Score: 6/10 (MEDIUM). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-08-06 07:46:17
(1 month ago)
WooCommerce YITH AJAX Filder product_cat filter flood attempt with taxonomies
DDoS Attack
Bad Web Bot
Anonymous
2026-07-29 13:00:55
(2 months ago)
denied traffic to a honeypot network. destination port 55890.
Port Scan
Hacking
๐บ๐ธ
kosada.com
2026-07-11 08:21:57
(2 months ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐บ๐ธ
pixelmemory.us
2026-07-08 09:44:26
(2 months ago)
2026-07-08T09:41:58 27.34.69.70 GET /Photos/Vacation/t/DSC08303.jpg Mozilla/5.0 (Windows NT 10.0; Wi ...
show more
2026-07-08T09:41:58 27.34.69.70 GET /Photos/Vacation/t/DSC08303.jpg Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
...
show less
Bad Web Bot
๐ฎ๐ฉ
David Koswari
2026-07-01 05:25:00
(3 months ago)
REQ_BLOCKED_ACL
DDoS Attack
FTP Brute-Force
Ping of Death
Port Scan
Hacking
SQL Injection
Spoofing
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
IoT Targeted
๐ธ๐ฌ
mypatricks
2026-06-30 07:02:17
(3 months ago)
27.34.69.70 | Port: 13668 | DNS: 70.69.34.27.dynamic.wlink.com.np 2026-06-30T15:02:16+08:00 Asia/Kat ...
show more
27.34.69.70 | Port: 13668 | DNS: 70.69.34.27.dynamic.wlink.com.np 2026-06-30T15:02:16+08:00 Asia/Kathmandu | DYN Data Center/Web Hosting/Transit Spam list | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36 HTTP/1.1 443 GET | URL: /ms/?9ab9bb88ab8c98fbe=273 | Ref: https://xxxxxx/ms?9ab9bb88ab8c98fbe=273 | Country: NP/Nepal/+05:45 IP City: Lahฤn Windows a13b4de7eedb58b9-KTM/Kathmandu, Nepal 1 hits/0 secs Browser 1
show less
Brute-Force
Web App Attack
Blog Spam
Web Spam
Exploited Host
๐บ๐ธ
kosada.com
2026-06-29 09:44:24
(3 months ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐ฉ๐ช
SMARTNET
2026-05-27 06:03:53
(4 months ago)
Aisuru(Mirai variant) DDoS | Incident ID: eb7eac85-2c32-49f6-94ff-e8c25ad16083
DDoS Attack
๐ธ๐ฌ
mypatricks
2026-04-07 08:24:08
(5 months ago)
27.34.69.70 | Port: 10725 | DNS: 70.69.34.27.dynamic.wlink.com.np 2026-04-07T16:24:07+08:00 Asia/Kat ...
show more
27.34.69.70 | Port: 10725 | DNS: 70.69.34.27.dynamic.wlink.com.np 2026-04-07T16:24:07+08:00 Asia/Kathmandu | LINK Data Center/Web Hosting/Transit Spam list | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36 HTTP/1.1 443 GET | URL: /hashtag/music-notes/?95c0aa7ddd0af061864b0686b7388f4=JPY&code=JPY | Ref: https://xxxxxx/hashtag/music-notes/?31ee05876d14d=GBP&code=GBP | Country: NP/Nepal/+05:45 IP City: Butwฤl macOS 9e87a24c2bcfb01a-KTM/Kathmandu, Nepal 1 hits/0 secs Robots 4
show less
Brute-Force
Web App Attack
Blog Spam
Web Spam
Exploited Host
๐บ๐ธ
matt
2026-03-04 02:38:28
(7 months ago)
DDOS attack with query parameters attempting to overload WordPress site.
DDoS Attack