๐ณ๐ฑ
COMPLEX
2026-07-27 00:18:33
(7 hours ago)
Unsolicited TCP traffic | Action: DROP | Port 8443
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-25 16:50:51
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 162.158.111.236 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.111.236 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 12:50:45.192617 2026] [security2:error] [pid 857891:tid 857891] [client 162.158.111.236:13184] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.fiveoceansconsulting.com|F|2"] [data "[email protected] "] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.fiveoceansconsulting.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "amTpZSHVKb0fkYoWQ2-CDwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ValtonTahiri
2026-07-16 03:00:52
(1 week ago)
UFW blocked a suspicious connection attempt to a closed or denied port. This activity is commonly as ...
show more
UFW blocked a suspicious connection attempt to a closed or denied port. This activity is commonly associated with port scanning, service discovery, or automated internet probing. Technical: source_ip=162.158.111.236; proto=TCP; source_port=11634; target_port=2087; flags=SYN
show less
Port Scan
๐จ๐ญ
backslash
2026-06-25 00:06:00
(1 month ago)
block ruleset bad bot: misc bad content F608233CC4C86EE814CE8DDDA9C4A0D3C79882F6
Bad Web Bot
๐ฉ๐ช
strxmpp
2026-06-20 18:45:56
(1 month ago)
162.158.111.236 - - [20/Jun/2026:20:45:55 +0200] "GET /wp-admin/install.php?step=1 HTTP/1.1" 301 681 ...
show more
162.158.111.236 - - [20/Jun/2026:20:45:55 +0200] "GET /wp-admin/install.php?step=1 HTTP/1.1" 301 681 "-" "http://jabberzueri.ch/wp-admin/install.php?step=1"
...
show less
Bad Web Bot
๐ฉ๐ช
Blexyel
2026-06-13 18:33:24
(1 month ago)
162.158.111.236 - - [13/Jun/2026:20:33:23 +0200] "GET /.git/info/grafts.old HTTP/1.1" 404 153 "-" "M ...
show more
162.158.111.236 - - [13/Jun/2026:20:33:23 +0200] "GET /.git/info/grafts.old HTTP/1.1" 404 153 "-" "Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0" "pingusmc.org"
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
strxmpp
2026-06-09 19:15:32
(1 month ago)
162.158.111.236 - - [09/Jun/2026:21:15:31 +0200] "GET /wp-admin/install.php?step=1 HTTP/1.1" 301 681 ...
show more
162.158.111.236 - - [09/Jun/2026:21:15:31 +0200] "GET /wp-admin/install.php?step=1 HTTP/1.1" 301 681 "-" "http://jabberzueri.ch/wp-admin/install.php?step=1"
...
show less
Bad Web Bot
๐บ๐ธ
mnsf
2026-06-02 10:05:39
(1 month ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐ฉ๐ช
AetherFox
2026-04-24 00:00:00
(3 months ago)
AetherFox VoidGuard detected: Scan path accessed: /.env | Scan path accessed: /.env.production | Sca ...
show more
AetherFox VoidGuard detected: Scan path accessed: /.env | Scan path accessed: /.env.production | Scan path accessed: /.env.development | Scan path accessed: /.env.dev | Scan path accessed: /.env.test | Scan path accessed: /.env.staging | Scan path accessed: /.env.bak | Scan path accessed: /.env.old | Scan path accessed: /.env.sa
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 04:51:39
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.111.236 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.111.236 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 00:51:34.325627 2026] [security2:error] [pid 706336:tid 706336] [client 162.158.111.236:12219] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.tulsatvmemories.com"] [uri "/.git/HEAD"] [unique_id "adSNVhEwEjIQWQ-vlq1DbwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 08:25:44
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.111.236 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.111.236 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 04:25:35.812733 2026] [security2:error] [pid 17021:tid 17021] [client 162.158.111.236:10068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.oakvillepiano.com"] [uri "/.git/HEAD"] [unique_id "adNt_987QZGmqpjrUJsC5AAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-04-05 16:35:11
(3 months ago)
Blocked Cloudflare Worker request. Pattern match "." at REQUEST_HEADERS:cf-worker. (5025-195)
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-04 20:29:59
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.111.236 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.111.236 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 16:29:51.566601 2026] [security2:error] [pid 14618:tid 14618] [client 162.158.111.236:10875] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.smoothiessoupssalads.com"] [uri "/.env.old"] [unique_id "adF0v6SLo2dwOWqymhrJIgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
jjnxpct
2026-04-04 03:53:35
(3 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /.env.development.local (Rule ID: 930130) - Restricted File Access Attempt
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-03 10:23:48
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.111.236 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.111.236 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 06:23:39.820173 2026] [security2:error] [pid 3832:tid 3832] [client 162.158.111.236:12172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.volkerjahn.link"] [uri "/.env.local"] [unique_id "ac-VK_OVR9vbTSFH2Rv1xQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack