๐บ๐ธ
TPI-Abuse
2026-06-19 12:26:57
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.158.108.138 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.108.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 08:26:44.685399 2026] [security2:error] [pid 4781:tid 4781] [client 162.158.108.138:11194] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fxztrader.com"] [uri "/.env.dist"] [unique_id "ajU1hBMTrSzaKgd5Vh3nygAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
freeutka
2026-05-15 05:56:59
(1 month ago)
WordPress brute-force login attempt on wp-login.php.
Brute-Force
Web App Attack
๐ฆ๐บ
aranguren.org
2026-05-13 16:24:37
(1 month ago)
162.158.108.138 - - [14/May/2026:02:24:36 +1000] "HEAD /api/fhir/metadata HTTP/2.0" 406 - "-" "Black ...
show more
162.158.108.138 - - [14/May/2026:02:24:36 +1000] "HEAD /api/fhir/metadata HTTP/2.0" 406 - "-" "BlackVeil-Security-Scanner/5.1.0 (https://blackveilsecurity.com; [email protected] )"
162.158.108.138 - - [14/May/2026:02:24:36 +1000] "HEAD /fhir/r4/metadata HTTP/2.0" 406 - "-" "BlackVeil-Security-Scanner/5.1.0 (https://blackveilsecurity.com; [email protected] )"
162.158.108.138 - - [14/May/2026:02:24:36 +1000] "HEAD /.well-known/smart-configuration HTTP/2.0" 406 - "-" "BlackVeil-Security-Scanner/5.1.0 (https://blackveilsecurity.com; [email protected] )"
162.158.108.138 - - [14/May/2026:02:24:36 +1000] "HEAD /epic/api/FHIR/R4/metadata HTTP/2.0" 406 - "-" "BlackVeil-Security-Scanner/5.1.0 (https://blackveilsecurity.com; [email protected] )"
162.158.108.138 - - [14/May/2026:02:24:36 +1000] "HEAD /cerner/api/FHIR/R4/metadata HTTP/2.0" 406 - "-" "BlackVeil-Security-Scanner/5.1.0 (https://blackveilsecurity.com; [email protected] )"
162.
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-11 05:03:02
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.108.138 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.108.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 01:02:49.126914 2026] [security2:error] [pid 32758:tid 32758] [client 162.158.108.138:10585] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davidfortier.com"] [uri "/.env.dev"] [unique_id "agFi-aoqvPfK3okzMM4I1gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 07:29:55
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.108.138 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.108.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 03:29:50.301918 2026] [security2:error] [pid 13949:tid 13949] [client 162.158.108.138:10128] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mirandaracewalks.com"] [uri "/.git/config"] [unique_id "af2Q7npg2mbZIE6KzCFFgQAAAAI"], referer: https://www.google.com/search?q=mirandaracewalks.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-08 00:55:36
(1 month ago)
[Fri May 08 02:55:34.309575 2026] [authz_core:error] [pid 7984] [client 162.158.108.138:14052] AH016 ...
show more
[Fri May 08 02:55:34.309575 2026] [authz_core:error] [pid 7984] [client 162.158.108.138:14052] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri May 08 02:55:35.785932 2026] [authz_core:error] [pid 7984] [client 162.158.108.138:14052] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri May 08 02:55:35.972890 2026] [authz_core:error] [pid 7984] [client 162.158.108.138:14052] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-07 16:48:13
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.108.138 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.108.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 12:48:04.889735 2026] [security2:error] [pid 410:tid 410] [client 162.158.108.138:13031] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ehrlichfamily.net.ehrlichmedia.com"] [uri "/.env"] [unique_id "afzCRDoscgElvN6-RnPU5AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-07 00:38:36
(1 month ago)
Web App Attack
Brute-Force
Web App Attack
๐บ๐ธ
freeutka
2026-05-05 16:18:56
(1 month ago)
WordPress brute-force login attempt on wp-login.php.
Brute-Force
Web App Attack
๐ฌ๐ง
pinguin
2026-05-04 23:20:23
(1 month ago)
Triggered Cloudflare WAF (firewallManaged) from SG.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from SG.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฌ๐ง
OptimusGO
2026-02-19 03:53:02
(4 months ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-02-19 03:53:02 UTC
Log evidence:
02/19/2026-03:51:18.613153 [**] [1:1000103:1] SECURITY Management Port Probe - CRITICAL [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 162.158.108.138:10603 -> 185.127.18.66:8443
02/19/2026-03:51:21.666145 [**] [1:1000101:2] SECURITY Port Scan Detected - Multiple Unauthorized Ports [**] [Classification: Attempted Information Leak] [Priority: 1] {TCP} 162.158.108.138:10603 -> 185.127.18.66:8443
show less
Port Scan
Brute-Force
๐ฉ๐ช
Blexyel
2026-02-11 05:20:26
(4 months ago)
162.158.108.138 - - [11/Feb/2026:06:20:25 +0100] "GET /wp-includes/id3/license.txt/blog/wp-includes/ ...
show more
162.158.108.138 - - [11/Feb/2026:06:20:25 +0100] "GET /wp-includes/id3/license.txt/blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "pingusmc.org"
...
show less
Brute-Force
Web App Attack
๐ธ๐ฌ
pusathosting.com
2025-12-26 20:36:07
(6 months ago)
2ds22 bruteforce
Brute-Force
Web App Attack
๐บ๐ธ
mawan
2025-11-13 22:41:56
(7 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฉ๐ช
abdubhai
2025-11-09 09:38:07
(7 months ago)
162.158.108.138 - - [09/Nov/2025
...
Brute-Force