πΊπΈ
TPI-Abuse
2026-09-29 18:26:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.124 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 14:26:41.204625 2026] [security2:error] [pid 23648:tid 23648] [client 162.158.154.124:11139] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lusocleaningservice.com"] [uri "/.htaccess"] [unique_id "arwC4bEB2cnFZmcWO9EFPQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 10:46:58
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 162.158.154.124 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.154.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 06:46:54.365229 2026] [security2:error] [pid 11727:tid 11730] [client 162.158.154.124:10867] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.busybeerestaurant.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.busybeerestaurant.com"] [uri "/index.php.bak"] [unique_id "aruXHpCZy9aiwBj-uvyQvgAAAIA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-28 08:57:45
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.124 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 04:57:38.402096 2026] [security2:error] [pid 23020:tid 23045] [client 162.158.154.124:13279] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "certifiedfinancialanalyst.org"] [uri "/.htaccess"] [unique_id "arosAlJ6vvbUh46Fx6ZGXgAAAVc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-14 22:29:25
(1 month ago)
"Packet Flood; Triggered WAF; Persistent 404 Attempts"
DDoS Attack
π³π±
homeshowdomain.nl
2026-06-24 22:02:19
(3 months ago)
Auto-ban: >3000 req/min op 2026-06-24
Web App Attack
SSH
Hacking
πΊπΈ
freeutka
2026-05-07 02:21:05
(4 months ago)
WordPress brute-force login attempt on wp-login.php.
Brute-Force
Web App Attack
πΊπΈ
freeutka
2026-05-05 20:27:28
(4 months ago)
WordPress brute-force login attempt on wp-login.php.
Brute-Force
Web App Attack
Anonymous
2026-04-21 09:12:56
(5 months ago)
162.158.154.124 - - [21/Apr/2026:11:12:56 +0200] "GET //test/wp-includes/wlwmanifest.xml HTTP/1.0" 4 ...
show more
162.158.154.124 - - [21/Apr/2026:11:12:56 +0200] "GET //test/wp-includes/wlwmanifest.xml HTTP/1.0" 404 460 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36"
162.158.154.124 - - [21/Apr/2026:11:12:56 +0200] "GET //test/wp-includes/wlwmanifest.xml HTTP/1.1" 404 246 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36"
162.158.154.124 - - [21/Apr/2026:11:12:56 +0200] "GET //wp2/wp-includes/wlwmanifest.xml HTTP/1.0" 404 460 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36"
162.158.154.124 - - [21/Apr/2026:11:12:56 +0200] "GET //wp2/wp-includes/wlwmanifest.xml HTTP/1.1" 404 246 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36"
162.158.154.124 - - [21/Apr/2026:11:12:56 +0200] "GET //site/wp-includes/wlwmanifest.xml HTTP/1.0" 404 460 "-" "Mozilla/5.
...
show less
Brute-Force
Web App Attack
πΊπΈ
octageeks.com
2026-04-19 04:07:37
(5 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack
π¨π¦
yukon.ca
2026-04-07 23:19:23
(5 months ago)
Web Server Enforcement Violation: Web Server Exposed Git Repository Information Disclosure
Port:80
Hacking
Exploited Host
πΊπΈ
TPI-Abuse
2026-03-21 07:26:10
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.124 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 03:26:05.824870 2026] [security2:error] [pid 7706:tid 7706] [client 162.158.154.124:13659] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.drgas.com"] [uri "/.env.save"] [unique_id "ab5IDc896VTJZHoQcDvYFQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 08:28:49
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.124 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 04:28:41.489008 2026] [security2:error] [pid 12772:tid 12879] [client 162.158.154.124:14190] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.uniquelynoel.com"] [uri "/var/www/.env"] [unique_id "ab0FOUA7E_UMUN8q57y2LQAAARU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 08:05:31
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.124 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 04:05:26.385442 2026] [security2:error] [pid 17853:tid 17853] [client 162.158.154.124:13661] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.hydrogenplus.net"] [uri "/private/.env"] [unique_id "abz_xk6PtjbBdQp9znjDZgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 05:04:51
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.124 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 01:04:48.171142 2026] [security2:error] [pid 28097:tid 28097] [client 162.158.154.124:10124] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.kirbysmw.com"] [uri "/.env.old"] [unique_id "abzVcMeZYbpknR_QBwHgyAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 04:45:56
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.124 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 00:45:09.707183 2026] [security2:error] [pid 3988:tid 3988] [client 162.158.154.124:12790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.fvsllc.com"] [uri "/config/.env"] [unique_id "abzQ1eaEgtaXUnPQcKbL9gAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack