๐บ๐ธ
TPI-Abuse
2026-08-23 11:26:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 162.158.152.200 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.152.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 07:25:55.035451 2026] [security2:error] [pid 18203:tid 18203] [client 162.158.152.200:11827] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "highfydelity.com.fydelity.net"] [uri "/.env.sample"] [unique_id "aorYwyXnnhUEARDp88e_MgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-08-22 06:19:48
(2 days ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possi ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possible exploited host). Evidence: AttackPattern: /[a-z0-9]{1,12}\.php (Match: /g.php)
show less
Hacking
Exploited Host
Web App Attack
๐ป๐ณ
cimee
2026-08-21 21:39:48
(2 days ago)
This IP accessed the path /.well-known/admin.php, which is banned.
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-08-21 16:19:39
(3 days ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ง๐ช
madeit
2026-08-11 06:04:23
(1 week ago)
Web App Attack
๐ธ๐ช
adaml1324
2026-05-13 18:53:29
(3 months ago)
Direct IP probe / invalid SNI
From server logs:
DIRECT_IP_HTTPS ip=[attacker] time=13/May/2026:07:5 ...
show more
Direct IP probe / invalid SNI
From server logs:
DIRECT_IP_HTTPS ip=[attacker] time=13/May/2026:07:50:27 +0200
DIRECT_IP_HTTPS ip=[attacker] time=13/May/2026:07:50:27 +0200
DIRECT_IP_HTTPS ip=[attacker] time=13/May/2026:07:50:27 +0200
DIRECT_IP_HTTPS ip=[attacker] time=13/May/2026:07:50:27 +0200
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-03 01:57:56
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.152.200 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.152.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 21:57:53.233612 2026] [security2:error] [pid 14286:tid 14286] [client 162.158.152.200:11975] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.synercom.org"] [uri "/.env.test"] [unique_id "ac8eoSfBX2jfXPJIut8VTwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-02 12:57:00
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.152.200 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.152.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 08:56:53.460814 2026] [security2:error] [pid 25196:tid 25294] [client 162.158.152.200:11573] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.upperwilds.com"] [uri "/config/.env"] [unique_id "ac5nlfTTqyi_RFZzWAOoYAAAAVg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-02 00:34:29
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.152.200 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.152.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 01 20:34:17.763885 2026] [security2:error] [pid 19446:tid 19446] [client 162.158.152.200:13571] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.systemcapacityoptimization.com"] [uri "/.env.save"] [unique_id "ac25iRAJ5ASOZByEUTfizQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-01 03:51:29
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.152.200 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.152.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 23:51:21.685824 2026] [security2:error] [pid 5623:tid 5623] [client 162.158.152.200:11889] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.trhs70.com"] [uri "/.env.backup"] [unique_id "acyWOQaMuWEY2uIV0pZOCwAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-01 02:43:19
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.152.200 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.152.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 22:43:12.059262 2026] [security2:error] [pid 21052:tid 21052] [client 162.158.152.200:11301] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.accordionfactory.com"] [uri "/app/.env"] [unique_id "acyGQLPJ_lu2CaPh7efIcwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 13:05:37
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.152.200 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.152.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 09:05:30.252606 2026] [security2:error] [pid 32418:tid 32418] [client 162.158.152.200:11952] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.jmarkcapital.com"] [uri "/admin/.env"] [unique_id "acvGmoX7SeG-oxGPE-cyzwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 11:50:42
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.152.200 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.152.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 07:50:33.469615 2026] [security2:error] [pid 4633:tid 4652] [client 162.158.152.200:12181] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.dba.center"] [uri "/.env2"] [unique_id "acu1CRlGXuGNID9sLxkypgAAAVE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 11:34:54
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.152.200 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.152.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 07:34:51.583825 2026] [security2:error] [pid 19425:tid 19425] [client 162.158.152.200:13621] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.fitnessdoctors.com"] [uri "/var/www/.env"] [unique_id "acuxW5ITQBFsglErrKWhuQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 11:09:09
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.152.200 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.152.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 07:09:03.167327 2026] [security2:error] [pid 21268:tid 21268] [client 162.158.152.200:13444] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.scoutmountaindistrict.org"] [uri "/.env.local.backup"] [unique_id "acurT5OSGarnOLP2eiy2DwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack