๐ฉ๐ช
brechtr
2026-09-14 19:17:59
(1 day ago)
[Press84-BanHammer] bad username โ Sourced from: powerstationcentric.com โ Request: POST /wp-login.p ...
show more
[Press84-BanHammer] bad username โ Sourced from: powerstationcentric.com โ Request: POST /wp-login.php
show less
Brute-Force
๐ง๐ช
madeit
2026-09-13 17:44:14
(2 days ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-06 10:46:03
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.158.108.42 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.108.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 06:45:56.269410 2026] [security2:error] [pid 4813:tid 4813] [client 162.158.108.42:11959] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.railfairofseo.com.powerlinemultimedia.net"] [uri "/.env.sample"] [unique_id "ap1EZFHVtlEjWq95NXZzwgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MPL
2026-09-04 20:23:23
(1 week ago)
tcp/443 (5 or more attempts)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-04 04:28:00
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.158.108.42 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.108.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 00:27:50.427082 2026] [security2:error] [pid 1562:tid 1562] [client 162.158.108.42:11692] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mothersdaybouquet.net"] [uri "/.env.test"] [unique_id "appIxvskBsD9BrhfQrtknwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 05:19:45
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.158.108.42 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.108.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 01:19:37.385748 2026] [security2:error] [pid 27389:tid 27389] [client 162.158.108.42:11467] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.texaspropertyinspection.com"] [uri "/.git/config"] [unique_id "aoKZ6eOb0mdEdS9nEakX4gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 03:50:18
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.158.108.42 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.108.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 23:50:10.887627 2026] [security2:error] [pid 7063:tid 7063] [client 162.158.108.42:14191] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.sinobit.org"] [uri "/.git/HEAD"] [unique_id "aoKE8lgbMCAcmWL_EX1NEQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 02:43:19
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.158.108.42 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.108.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 22:43:12.671427 2026] [security2:error] [pid 3746:tid 3746] [client 162.158.108.42:11406] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.cchockeyhistory.org"] [uri "/.git/HEAD"] [unique_id "aoJ1QCNPihqsxKc8WUNC4AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 23:55:03
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.158.108.42 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.108.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 19:54:58.121903 2026] [security2:error] [pid 4914:tid 4914] [client 162.158.108.42:9900] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.giveorcas.org"] [uri "/.git/config"] [unique_id "aoJN0kXDfkrQlJLrU7MWHwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 22:57:13
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.158.108.42 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.108.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 18:57:09.334438 2026] [security2:error] [pid 12755:tid 12755] [client 162.158.108.42:10280] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kirt.us"] [uri "/.git/HEAD"] [unique_id "aoJARQwMNdGiBAlktvBlcAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 05:51:20
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.108.42 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.108.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 01:51:12.481255 2026] [security2:error] [pid 3587560:tid 3587564] [client 162.158.108.42:14107] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.aaenroll.aafm.us"] [uri "/.git/HEAD"] [unique_id "aoFP0NtRr2GkZSEw84JIVgAAAUE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 03:48:09
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.108.42 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.108.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 23:48:02.946441 2026] [security2:error] [pid 5749:tid 5768] [client 162.158.108.42:14150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.siriuspharmaceuticals.com"] [uri "/.git/HEAD"] [unique_id "aoEy8r7m6l5rRB4tWX8B3AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-05 17:35:20
(1 month ago)
Web App Attack
๐บ๐ธ
mawan
2026-07-25 04:03:08
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฆ๐ฑ
router.al
2026-07-19 14:44:41
(1 month ago)
07/19/2026-14:44:41.671077 162.158.108.42 Protocol: 6 ET HUNTING Request for Webshell in .well-known ...
show more
07/19/2026-14:44:41.671077 162.158.108.42 Protocol: 6 ET HUNTING Request for Webshell in .well-known directory
show less
Hacking