๐ซ๐ท
chengkev
2026-09-21 20:12:08
(1 week ago)
Esta IP fue detectada por CrowdSec, activando crowdsecurity/http-bad-user-agent
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-21 06:04:41
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 162.158.108.33 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 162.158.108.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 02:04:35.601447 2026] [security2:error] [pid 8545:tid 8545] [client 162.158.108.33:9279] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "hamiltonbookings.com"] [uri "/.env"] [unique_id "arDI84k2XqQK5AUU8FTf3wAAABw"], referer: https://www.google.com/search?q=hamiltonbookings.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Diskominfo Lumajang
2026-09-20 20:10:05
(1 week ago)
Security Event Detected by SOC Diskominfo Lumajang: event=alert, hits=10
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-04 15:06:32
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.158.108.33 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.108.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:06:21.553029 2026] [security2:error] [pid 9630:tid 9630] [client 162.158.108.33:13393] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brentsagnotti.com"] [uri "/.env.backup"] [unique_id "aprebVevTo0UrTv3fksfAwAAAAs"], referer: https://www.google.com/search?q=brentsagnotti.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 05:07:09
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.108.33 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.108.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 01:07:01.847397 2026] [security2:error] [pid 14527:tid 14527] [client 162.158.108.33:10324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.diceknobs.com"] [uri "/.git/config"] [unique_id "aoKW9WhhZc4doCVuCTuDMwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 10:39:40
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.108.33 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.108.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 06:39:34.979310 2026] [security2:error] [pid 22841:tid 22841] [client 162.158.108.33:9799] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "therhclan.com"] [uri "/.git/config"] [unique_id "aoGTZrtddPK-ZRfhVLUX1AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 08:57:42
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.108.33 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.108.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 04:57:36.774296 2026] [security2:error] [pid 16039:tid 16039] [client 162.158.108.33:13638] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.canonarizona.com"] [uri "/.git/HEAD"] [unique_id "aoF7gJSqRMsBAGnwy4pMygAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-15 00:59:27
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.108.33 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.108.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 20:59:22.645318 2026] [security2:error] [pid 32650:tid 32650] [client 162.158.108.33:12846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.susanoneill.us"] [uri "/.git/config"] [unique_id "an-56uG9KjNQQADHPnzMSwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-13 19:19:56
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.108.33 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.108.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 15:19:51.072355 2026] [security2:error] [pid 761614:tid 761614] [client 162.158.108.33:11922] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.completemodular.com"] [uri "/.git/config"] [unique_id "an4Y13vmbGFi4_3nyT2fBwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-08 07:19:12
(1 month ago)
Web App Attack
๐ฆ๐ฑ
router.al
2026-07-17 08:16:43
(2 months ago)
07/17/2026-08:16:42.883075 162.158.108.33 Protocol: 6 ET SCAN LeakIX Inbound User-Agent
Hacking
๐ง๐พ
lns.bz
2026-06-28 00:15:14
(3 months ago)
.env scanning [BY]
Web App Attack
๐ฉ๐ช
acadeova
2026-06-27 07:38:20
(3 months ago)
๐จ Recon detected (nft drop)
SRC=162.158.108.33
Observed=TCP dpt=80 in=enp0s6 ttl=56
Time=recent(jour ...
show more
๐จ Recon detected (nft drop)
SRC=162.158.108.33
Observed=TCP dpt=80 in=enp0s6 ttl=56
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐บ๐ธ
mawan
2026-06-20 19:13:53
(3 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 19:19:08
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.108.33 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.108.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 15:19:01.628605 2026] [security2:error] [pid 28337:tid 28337] [client 162.158.108.33:11345] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "quakeprediction.com"] [uri "/.git/config"] [unique_id "aixbpTeeRND3kN6-Ts9b8AAAAC4"], referer: https://www.google.com/search?q=quakeprediction.com
show less
Brute-Force
Bad Web Bot
Web App Attack