๐บ๐ธ
TPI-Abuse
2026-09-18 12:45:58
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 78.38.90.70 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 78.38.90.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 08:45:54.926191 2026] [security2:error] [pid 22209:tid 22209] [client 78.38.90.70:32802] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fatcaverecords.fatcavemedia.com"] [uri "/wp-config.php.bak"] [unique_id "aq0ygsYfMAKhaGtZhpLGqwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-18 10:59:36
(9 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-09-18 08:26:16
(12 hours ago)
Try to access /.env.bak
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 06:59:31
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 78.38.90.70 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 78.38.90.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 02:59:29.158093 2026] [security2:error] [pid 19433:tid 19433] [client 78.38.90.70:34702] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crep-psych.org"] [uri "/wp-config.php.bak"] [unique_id "aqzhUSXnt7GjWv-lqWG1vQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ITSNF
2026-09-18 06:45:03
(13 hours ago)
Blocked by os-abuseipdb; 52 hits, proto=tcp, ports=443,80
Port Scan
Hacking
Anonymous
2026-09-18 06:41:02
(13 hours ago)
FPROCO WEBEXPLOIT 78.38.90.70 (78.38.90.70)
Web App Attack
๐บ๐ธ
TAY
2026-09-18 04:46:15
(15 hours ago)
78.38.90.70 - - [18/Sep/2026:12:45:54 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 54906 "-" "Mozill ...
show more
78.38.90.70 - - [18/Sep/2026:12:45:54 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 54906 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
78.38.90.70 - - [18/Sep/2026:12:46:01 +0800] "GET /wp-config.php~ HTTP/1.1" 404 54903 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
78.38.90.70 - - [18/Sep/2026:12:46:04 +0800] "GET /wp-config.php.save HTTP/1.1" 404 54907 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
78.38.90.70 - - [18/Sep/2026:12:46:07 +0800] "GET /wp-config.php.old HTTP/1.1" 404 54884 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
78.38.90.70 - - [18/Sep/2026:12:46:09 +0800] "GET /wp-config.php.orig HTTP/1.1" 404 54907 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko
...
show less
Brute-Force
๐บ๐ธ
mnsf
2026-09-17 22:05:06
(22 hours ago)
Abuse Detected (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 00:53:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 78.38.90.70 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 78.38.90.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 20:53:46.482598 2026] [security2:error] [pid 12868:tid 12882] [client 78.38.90.70:58706] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nimbll.com"] [uri "/wp-config.php.bak"] [unique_id "aqs6GmcSqzx8SZudKofuMQAAAIw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 18:36:05
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 78.38.90.70 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 78.38.90.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 14:35:56.621194 2026] [security2:error] [pid 2279:tid 2279] [client 78.38.90.70:51708] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.naturalacu.com"] [uri "/wp-config.php.bak"] [unique_id "aqrhjDOdD1eF9K61CtyKIgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-16 16:40:03
(2 days ago)
crowdsecurity/http-cve-probing
Brute-Force
Web App Attack
๐ง๐ช
taivas.nl
2026-09-16 16:32:17
(2 days ago)
Bad_requests
Bad Web Bot
๐ท๐ด
iulianh
2026-09-16 15:27:11
(2 days ago)
80,443
Brute-Force
SSH
๐ฌ๐ง
consul.to
2026-09-16 15:11:13
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 10:57:11
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 78.38.90.70 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 78.38.90.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 06:57:05.751994 2026] [security2:error] [pid 6935:tid 6935] [client 78.38.90.70:39410] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||arsenalfordemocracy.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "arsenalfordemocracy.com"] [uri "/wp-content/debug.log"] [unique_id "aqp2AaDVs4u_Aah0CbWz2wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack