๐บ๐ธ
TPI-Abuse
2026-06-07 02:03:40
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.158.111.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.111.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 22:03:35.797316 2026] [security2:error] [pid 23587:tid 23587] [client 162.158.111.217:12682] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ncsgroup96.com"] [uri "/.git/config"] [unique_id "aiTRd7EUShLWy_K8Nv-AOQAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-05-23 01:15:51
(3 weeks ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐จ๐ฆ
dispensight
2026-05-17 07:00:00
(4 weeks ago)
Automated WordPress exploit probe caught via honeydomain. UA: dispensight.sbs/wp-admin/install.php?s ...
show more
Automated WordPress exploit probe caught via honeydomain. UA: dispensight.sbs/wp-admin/install.php?step=1. Cloudflare Germany proxy.
show less
Bad Web Bot
๐บ๐ธ
freeutka
2026-05-12 20:25:50
(1 month ago)
WordPress brute-force login attempt on wp-login.php.
Brute-Force
Web App Attack
๐บ๐ธ
freeutka
2026-05-05 04:07:58
(1 month ago)
WordPress brute-force login attempt on wp-login.php.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-23 07:36:05
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.111.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.111.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 23 03:35:57.792845 2026] [security2:error] [pid 20435:tid 20435] [client 162.158.111.217:12030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bjfrancislaw.com"] [uri "/.git/config"] [unique_id "aenL3R7vD0VkJ7XSrN-5fwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-15 00:19:48
(2 months ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-14 04:37:27
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.111.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.111.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 14 00:37:22.376655 2026] [security2:error] [pid 29095:tid 29095] [client 162.158.111.217:9242] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.the-board-shop.com"] [uri "/.git/config"] [unique_id "ad3EgloapmE5xWJRLZ1pVQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-14 03:58:30
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.111.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.111.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 13 23:58:24.923340 2026] [security2:error] [pid 3301051:tid 3301051] [client 162.158.111.217:12889] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.partiklezoo.com"] [uri "/.git/config"] [unique_id "ad27YGTUSZpWe1xjXkVn1AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-04-08 23:05:23
(2 months ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 07:47:09
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.111.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.111.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 03:47:03.067006 2026] [security2:error] [pid 2369615:tid 2369615] [client 162.158.111.217:11071] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "onlineteacher.info"] [uri "/.git/HEAD"] [unique_id "adYH9y8x82up6-FRs-kPZQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 01:21:48
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.111.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.111.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 21:21:40.395734 2026] [security2:error] [pid 3299934:tid 3299934] [client 162.158.111.217:13207] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.directoryofdrugs.com"] [uri "/.git/refs/heads/main"] [unique_id "adWtpGlC4brR2adsNgEGjAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-04-07 04:05:32
(2 months ago)
Scanning/Probing (53)
Brute-Force
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-04-06 15:37:39
(2 months ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-04-05 18:12:04
(2 months ago)
162.158.111.217 - - [05/Apr/2026:21:12:02 +0300] "GET /backend/.env HTTP/1.1" 404 789 "-" "-"
162.15 ...
show more
162.158.111.217 - - [05/Apr/2026:21:12:02 +0300] "GET /backend/.env HTTP/1.1" 404 789 "-" "-"
162.158.111.217 - - [05/Apr/2026:21:12:02 +0300] "GET /api/.env HTTP/1.1" 404 850 "-" "-"
...
show less
Web App Attack