๐ซ๐ฎ
Erpelstolz
2026-07-23 04:00:52
(16 hours ago)
external host: 162.158.111.80 - - [23/Jul/2026:06:00:49 +0200] "GET /wp-admin/install.php?step=1 HTT ...
show more
external host: 162.158.111.80 - - [23/Jul/2026:06:00:49 +0200] "GET /wp-admin/install.php?step=1 HTTP/1.1" 404 5663 "-" "http://erpelstolz.com/wp-admin/install.php?step=1" CF-Ray:a1f7c7c42d173602-FRA CF-IP:-
show less
Web App Attack
๐ฉ๐ช
Sรฉfora Srl
2026-07-07 11:03:18
(2 weeks ago)
Bad user agents ignoring web crawling rules. Draing bandwidth - detected by Fail2Ban in plesk-apache ...
show more
Bad user agents ignoring web crawling rules. Draing bandwidth - detected by Fail2Ban in plesk-apache-badbot jail
show less
Bad Web Bot
๐บ๐ธ
TNZ
2026-06-17 12:08:34
(1 month ago)
Automated honeypot: waf:RFI-001 | Path: /wp-admin/install.php | ISP: AS13335 Cloudflare, Inc. | ASN: ...
show more
Automated honeypot: waf:RFI-001 | Path: /wp-admin/install.php | ISP: AS13335 Cloudflare, Inc. | ASN: AS13335 Cloudflare, Inc. [PROXY] | Abuse score: 0 | Open ports: [] | UA: http://getkovamail.com/wp-admin/install.php?step=1
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-06-10 06:11:00
(1 month ago)
162.158.111.80 - - [10/Jun/2026:09:10:59 +0300] "GET /wp-admin/css/ HTTP/1.1" 404 768 "-" "Mozlila/5 ...
show more
162.158.111.80 - - [10/Jun/2026:09:10:59 +0300] "GET /wp-admin/css/ HTTP/1.1" 404 768 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
162.158.111.80 - - [10/Jun/2026:09:11:00 +0300] "GET /wp-admin/erase-personal-data/ HTTP/1.1" 404 767 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
...
show less
Web App Attack
๐ฆ๐บ
trentwiles.com
2026-05-01 08:02:09
(2 months ago)
Unauthorized connection attempt detected from IP address 162.158.111.80 to port 8443 [SYD]
Port Scan
๐ฌ๐ง
Axel
2026-04-09 09:26:02
(3 months ago)
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.env Server: ...
show more
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.env Server: UK-01
show less
Web App Attack
Hacking
SQL Injection
๐ฎ๐ฉ
Burayot
2026-04-06 07:43:31
(3 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 162.158.111.80 (DE/Germany/-): 1 in ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 162.158.111.80 (DE/Germany/-): 1 in the last 3600 secs
show less
Web App Attack
Anonymous
2026-04-04 16:33:08
(3 months ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ซ๐ท
masterguru
2026-04-04 09:51:14
(3 months ago)
Blocked Cloudflare Worker request. Pattern match "." at REQUEST_HEADERS:cf-worker. (5025-197)
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-04 08:40:14
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.111.80 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.111.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 04:40:06.765133 2026] [security2:error] [pid 29993:tid 29993] [client 162.158.111.80:13817] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "xmlprotocol.com"] [uri "/.git/logs/HEAD"] [unique_id "adDOZvZlLUyX-_88oXEi2gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 01:50:31
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.111.80 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.111.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 21:50:22.253099 2026] [security2:error] [pid 24599:tid 24599] [client 162.158.111.80:10195] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.tlphotogifts.com"] [uri "/.git/index"] [unique_id "adBuXgyrP6CzBvXtyAD4nQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 11:13:50
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.111.80 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.111.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 07:13:45.198193 2026] [security2:error] [pid 21685:tid 21685] [client 162.158.111.80:13283] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blosoms.org"] [uri "/config/.env"] [unique_id "ac-g6bsFq_23kjTtNbEgvQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-30 09:44:00
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.111.80 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.111.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 05:43:53.783592 2026] [security2:error] [pid 26434:tid 26434] [client 162.158.111.80:12968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.jikishin-kai.org"] [uri "/.git/logs/HEAD"] [unique_id "acpF2RZvpRBTeWpN7h1n2gAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-30 05:53:24
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.111.80 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.111.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 01:53:17.752772 2026] [security2:error] [pid 23244:tid 23257] [client 162.158.111.80:10936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.oplconnect.com"] [uri "/.git/logs/HEAD"] [unique_id "acoPzYEYlsddrzOiTffkXQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-03-30 01:06:52
(3 months ago)
Scanning/Probing (13)
Brute-Force
Web App Attack