🇩🇪
pltcldvlpr
2026-09-07 12:57:06
(1 day ago)
CMS/framework probe: 158.173.241.146 - - [07/Sep/2026:14:57:05 +0200] "GET /.git/config HTTP/1.1" 30 ...
show more
CMS/framework probe: 158.173.241.146 - - [07/Sep/2026:14:57:05 +0200] "GET /.git/config HTTP/1.1" 301 178 "-" "Go-http-client/1.1" asn=212238 org="Datacamp Limited" country=SE
...
show less
Web App Attack
🇳🇱
mieg
2026-09-07 00:16:14
(1 day ago)
Web vulnerability probing
Brute-Force
Web App Attack
🇨🇭
4server
2026-09-04 00:07:30
(4 days ago)
[FriSep0402:07:27.9257722026][security2:error][pid2301329:tid2301537][client158.173.241.146:0]ModSec ...
show more
[FriSep0402:07:27.9257722026][security2:error][pid2301329:tid2301537][client158.173.241.146:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"hostingedominio.com\"][uri\"/.git/config\"][unique_id\"apoLv3wxOHpO3nyXwcX7oQAAAcM\"]
show less
Hacking
Web App Attack
🇩🇪
london2038.com
2026-09-03 00:22:53
(5 days ago)
Probing for exploits
158.173.241.146 - - [03/Sep/2026:02:22:50 +0200] "GET /.git/config HTTP/1.1" 42 ...
show more
Probing for exploits
158.173.241.146 - - [03/Sep/2026:02:22:50 +0200] "GET /.git/config HTTP/1.1" 422 0 "-" "Go-http-client/1.1"
158.173.241.146 - - [03/Sep/2026:02:22:50 +0200] "GET /.git/config HTTP/1.1" 422 0 "-" "Go-http-client/1.1"
show less
Hacking
Web App Attack
🇩🇪
Bedios GmbH
2026-09-03 00:02:58
(5 days ago)
Login credentials theft attempt
Hacking
🇬🇧
consul.to
2026-08-13 18:22:34
(3 weeks ago)
Web attack/malicious scanning detected
Web App Attack
🇬🇧
consul.to
2026-07-04 06:24:59
(2 months ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-06-03 20:58:08
(3 months ago)
(mod_security) mod_security (id:210801) triggered by 158.173.241.146 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210801) triggered by 158.173.241.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 16:58:01.531473 2026] [security2:error] [pid 20892:tid 20892] [client 158.173.241.146:37675] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||sigrc.org|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "sigrc.org"] [uri "/license.txt"] [unique_id "aiCVWc1Ev87cvkG9T6_XrwAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-03 19:19:42
(3 months ago)
(mod_security) mod_security (id:210801) triggered by 158.173.241.146 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210801) triggered by 158.173.241.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 15:19:35.967926 2026] [security2:error] [pid 20357:tid 20357] [client 158.173.241.146:22459] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||www.heartshapedboy.com|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "www.heartshapedboy.com"] [uri "/license.txt"] [unique_id "aiB-R2kVhKffkpEAEeJbxAAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-03 13:34:11
(3 months ago)
(mod_security) mod_security (id:210801) triggered by 158.173.241.146 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210801) triggered by 158.173.241.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 09:34:04.637242 2026] [security2:error] [pid 7427:tid 7427] [client 158.173.241.146:42383] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||sekel.org|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "sekel.org"] [uri "/license.txt"] [unique_id "aiAtTCQGXpqKDP105VuBaAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-03 05:28:41
(3 months ago)
(mod_security) mod_security (id:210801) triggered by 158.173.241.146 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210801) triggered by 158.173.241.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 01:28:33.321772 2026] [security2:error] [pid 12179:tid 12179] [client 158.173.241.146:65199] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||itre.org|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "itre.org"] [uri "/license.txt"] [unique_id "ah-7gY4XX7e87AxGoxmXEAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-02 11:40:36
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 158.173.241.146 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.241.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 07:40:30.263134 2026] [security2:error] [pid 23484:tid 23484] [client 158.173.241.146:52229] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "artbytracyjane.com"] [uri "/wp-config.php.bak"] [unique_id "ah7BLutPh1FZx9LFd6kWLgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-02 01:25:03
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 158.173.241.146 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.241.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 21:24:56.263911 2026] [security2:error] [pid 1391:tid 1413] [client 158.173.241.146:45955] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amazinglips.com"] [uri "/wp-config.php.bak"] [unique_id "ah4w6Mt4BtP-RfLWr1hkBAAAAYo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-01 20:57:02
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 158.173.241.146 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.241.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 16:56:56.805116 2026] [security2:error] [pid 14733:tid 14752] [client 158.173.241.146:54711] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ainavelas.com"] [uri "/wp-config.php.bak"] [unique_id "ah3yGAxWaqsNOZQSnQk_DAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-06-01 16:05:53
(3 months ago)
Abuse Detected (1)
Brute-Force
Web App Attack