๐ซ๐ท
chengkev
2026-09-21 20:12:11
(6 days ago)
Esta IP fue detectada por CrowdSec, activando crowdsecurity/http-bad-user-agent
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-21 06:08:23
(6 days ago)
(mod_security) mod_security (id:949110) triggered by 162.158.108.32 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 162.158.108.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 02:08:14.633254 2026] [security2:error] [pid 24011:tid 24011] [client 162.158.108.32:12753] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "hamiltonbookings.com"] [uri "/.env.test"] [unique_id "arDJzleok9DeG2zHKCZUTQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Diskominfo Lumajang
2026-09-20 20:10:05
(1 week ago)
Security Event Detected by SOC Diskominfo Lumajang: event=alert, hits=9
Brute-Force
๐ซ๐ท
dynamix
2026-09-17 14:25:22
(1 week ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
johnkarlhill
2026-09-11 12:11:15
(2 weeks ago)
WebKnight blocked malicious web request on johnkarlhill.com
Brute-Force
SSH
๐ธ๐ฌ
securejdprop
2026-09-01 14:28:09
(3 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/vpatch-git-config.
Hacking
๐ง๐ฌ
Stoyko Stoykov
2026-09-01 08:27:22
(3 weeks ago)
162.158.108.32 - - [01/Sep/2026:11:27:21 +0300] "GET /.env.prod HTTP/2.0" 404 134 "-" "crusader-work ...
show more
162.158.108.32 - - [01/Sep/2026:11:27:21 +0300] "GET /.env.prod HTTP/2.0" 404 134 "-" "crusader-worker/1.0"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 01:53:09
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.108.32 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.108.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 21:53:05.622486 2026] [security2:error] [pid 10092:tid 10092] [client 162.158.108.32:10583] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.utah17.com"] [uri "/.git/HEAD"] [unique_id "aoO7Aei4Vy0OkT22YpyLNAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 02:44:12
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.108.32 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.108.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 22:44:05.554911 2026] [security2:error] [pid 7404:tid 7404] [client 162.158.108.32:11028] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.flavornet.org"] [uri "/.git/config"] [unique_id "aoJ1dcwaXsi2xaNXnSur9wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 08:57:41
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.108.32 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.108.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 04:57:36.770901 2026] [security2:error] [pid 24490:tid 24490] [client 162.158.108.32:11118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.canonarizona.com"] [uri "/.git/config"] [unique_id "aoF7gCxu1MBU3REhZ5ofBAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-15 00:59:26
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.108.32 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.108.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 20:59:22.648878 2026] [security2:error] [pid 28213:tid 28213] [client 162.158.108.32:10128] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.susanoneill.us"] [uri "/.git/HEAD"] [unique_id "an-56vODbgg4crL6oW2ajAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-14 19:24:02
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.108.32 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.108.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 15:23:55.252091 2026] [security2:error] [pid 2960176:tid 2960176] [client 162.158.108.32:9414] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "margroberts.com"] [uri "/.git/config"] [unique_id "an9rSy1HO27mwguJbkh_1gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-13 19:19:57
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.108.32 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.108.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 15:19:51.073798 2026] [security2:error] [pid 762006:tid 762006] [client 162.158.108.32:14116] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.completemodular.com"] [uri "/.git/HEAD"] [unique_id "an4Y1y-2e_RAHfzfVvpZYwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-07 20:09:00
(1 month ago)
Web App Attack
๐ธ๐ฌ
anotherwatcher
2026-08-06 00:55:46
(1 month ago)
bad bot
Bad Web Bot