๐ท๐บ
genokrad
2026-09-19 01:49:20
(2 hours ago)
Website scan TCP 80/443 "/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KH"
Port Scan
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-18 21:59:15
(5 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-17.
show less
Web App Attack
SSH
Hacking
๐ณ๐ฑ
Roderic
2026-09-18 09:58:44
(17 hours ago)
*Port Scan* detected from 70.40.138.82 (TR/Tรผrkiye/-/-/82Jn5bnf.guzel.net.tr/[redacted]).
Port Scan
๐ฎ๐ณ
evicky2002
2026-09-18 06:00:02
(21 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฎ๐ฉ
David Koswari
2026-09-18 05:31:00
(22 hours ago)
REQ_BLOCKED_ACL
DDoS Attack
FTP Brute-Force
Ping of Death
Port Scan
Hacking
SQL Injection
Spoofing
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
IoT Targeted
๐ฌ๐ง
consul.to
2026-09-18 02:10:46
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-17 21:59:25
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-17
Web App Attack
SSH
Hacking
๐ฉ๐ช
BlueWire Hosting
2026-09-17 10:39:30
(1 day ago)
Probing websites for vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 10:17:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 70.40.138.82 (82Jn5bnf.guzel.net.tr): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 70.40.138.82 (82Jn5bnf.guzel.net.tr): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 06:17:23.927312 2026] [security2:error] [pid 18194:tid 18194] [client 70.40.138.82:40578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.j3pr.com"] [uri "/wp-config.php.orig"] [unique_id "aqu-M98S9WJY9VJnaPlhWAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TAY
2026-09-17 10:14:24
(1 day ago)
70.40.138.82 - - [17/Sep/2026:18:13:18 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 48441 "-" "Mozil ...
show more
70.40.138.82 - - [17/Sep/2026:18:13:18 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 48441 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
70.40.138.82 - - [17/Sep/2026:18:13:23 +0800] "GET /wp-config.php~ HTTP/1.1" 404 48441 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
70.40.138.82 - - [17/Sep/2026:18:13:38 +0800] "GET /wp-config.php.save HTTP/1.1" 404 48441 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
70.40.138.82 - - [17/Sep/2026:18:13:51 +0800] "GET /wp-config.php.old HTTP/1.1" 404 48441 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
70.40.138.82 - - [17/Sep/2026:18:14:08 +0800] "GET /wp-config.php.orig HTTP/1.1" 404 48441 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like
...
show less
Brute-Force
๐ซ๐ท
masterguru
2026-09-17 07:19:48
(1 day ago)
Too much 404 requests in 1 minute. Operator GE matched 10 at IP:block_script. (46020-193)
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-17 07:08:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 70.40.138.82 (82Jn5bnf.guzel.net.tr): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 70.40.138.82 (82Jn5bnf.guzel.net.tr): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 03:08:21.366141 2026] [security2:error] [pid 27584:tid 27584] [client 70.40.138.82:45360] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.modalguitarist.com"] [uri "/wp-config.php~"] [unique_id "aquR5VJcFkNJy4LHYLdB6QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
solution.it
2026-09-17 06:42:11
(1 day ago)
[Thu Sep 17 08:42:10.836602 2026] [php7:error] [pid 1855496:tid 1855496] [client 70.40.138.82:49882] ...
show more
[Thu Sep 17 08:42:10.836602 2026] [php7:error] [pid 1855496:tid 1855496] [client 70.40.138.82:49882] script '/var/www/html/internetriders.org/phpinfo.php' not found or unable to stat
show less
Web App Attack
๐ฌ๐ง
Apache
2026-09-17 06:37:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 70.40.138.82 (TR/Tรผrkiye/82Jn5bnf.guzel.net.tr) ...
show more
(mod_security) mod_security (id:210492) triggered by 70.40.138.82 (TR/Tรผrkiye/82Jn5bnf.guzel.net.tr): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-17 06:15:34
(1 day ago)
[ti-30al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-30al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 70.40.138.82 - - [17/Sep/2026:08:15:29 +0200] "GET /wp-config.php.save HTTP/1.1" 404 42903 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack