Anonymous
2026-06-21 16:24:53
(6 hours ago)
162.158.111.214 - - [21/Jun/2026:16:24:52 +0000] "GET /wp-admin/install.php?step=1 HTTP/1.1" 404 437 ...
show more
162.158.111.214 - - [21/Jun/2026:16:24:52 +0000] "GET /wp-admin/install.php?step=1 HTTP/1.1" 404 437 "-" "http://ashleybutcher.eu/wp-admin/install.php?step=1"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
febrian.de
2026-06-17 21:18:55
(4 days ago)
Malicious HTTP(S) probing detected by Fail2Ban
Web App Attack
Anonymous
2026-06-16 08:01:16
(5 days ago)
162.158.111.214 - - [16/Jun/2026:08:01:16 +0000] "GET /wp-admin/install.php?step=1 HTTP/1.1" 404 437 ...
show more
162.158.111.214 - - [16/Jun/2026:08:01:16 +0000] "GET /wp-admin/install.php?step=1 HTTP/1.1" 404 437 "-" "http://ashleybutcher.eu/wp-admin/install.php?step=1"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
hackthetime
2026-06-15 07:26:13
(6 days ago)
Tried to access /wp-admin/install.php (auto-added by Hype UI)
Web App Attack
Anonymous
2026-06-13 20:17:17
(1 week ago)
162.158.111.214 - - [13/Jun/2026:20:17:16 +0000] "GET /wp-admin/install.php?step=1 HTTP/1.1" 404 437 ...
show more
162.158.111.214 - - [13/Jun/2026:20:17:16 +0000] "GET /wp-admin/install.php?step=1 HTTP/1.1" 404 437 "-" "http://ashleybutcher.eu/wp-admin/install.php?step=1"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-31 17:33:59
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 162.158.111.214 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.111.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 13:33:51.137059 2026] [security2:error] [pid 14628:tid 14628] [client 162.158.111.214:9696] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||help.gmacguffin.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "help.gmacguffin.com"] [uri "/backup.sql"] [unique_id "ahxw_5FApmaLqJ6E2Q-LIwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
omc
2026-04-04 10:12:08
(2 months ago)
Hacking login/admin service [QS]
Hacking
Bad Web Bot
๐บ๐ธ
omc
2026-04-04 10:12:07
(2 months ago)
AH01797: Unauthorized file
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-03 21:20:25
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.111.214 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.111.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 17:20:18.396536 2026] [security2:error] [pid 24447:tid 24497] [client 162.158.111.214:9969] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.tributetomarilyn.com"] [uri "/server/.env"] [unique_id "adAvEuCKzb3dsSkFl5zm1AAAAZI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-04-03 15:02:00
(2 months ago)
Blocked Cloudflare Worker request. Pattern match "." at REQUEST_HEADERS:Cf-Worker. (5025-193)
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-03 13:52:25
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.111.214 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.111.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 09:52:18.375543 2026] [security2:error] [pid 5112:tid 5112] [client 162.158.111.214:13229] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cultiplant.com"] [uri "/.git/HEAD"] [unique_id "ac_GEnyOPSJ-FdcPU44BdgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 04:12:05
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.111.214 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.111.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 00:11:55.907383 2026] [security2:error] [pid 21206:tid 21206] [client 162.158.111.214:14177] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.gamedayincentives.com"] [uri "/.git/config"] [unique_id "ac8-C2rv9F92ezZ27KDSewAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-02 20:56:29
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.111.214 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.111.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 16:56:22.547855 2026] [security2:error] [pid 14013:tid 14013] [client 162.158.111.214:14031] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.scothart.com"] [uri "/core/.env"] [unique_id "ac7X9h8pTcgNv2IPnGxGSwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-04-02 00:24:22
(2 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-01 20:08:06
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.111.214 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.111.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 01 16:07:56.552035 2026] [security2:error] [pid 16688:tid 16688] [client 162.158.111.214:11255] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.totalhomecarebvi.com"] [uri "/.git/refs/heads/master"] [unique_id "ac17HJrunORAz8KCVoVyJAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack