๐บ๐ธ
TPI-Abuse
2026-08-25 17:41:21
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 13:41:13.460800 2026] [security2:error] [pid 27087:tid 27087] [client 162.158.154.193:12748] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.lucypower.com"] [uri "/.git/HEAD"] [unique_id "ao3TuSRjb_n05HZS72zK4gAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 21:28:29
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 17:28:20.803304 2026] [security2:error] [pid 22054:tid 22054] [client 162.158.154.193:13651] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.tjsworld.net"] [uri "/.git/config"] [unique_id "aoN89B7Bv6os3EC4_EXu5AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 09:04:42
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 05:04:37.864242 2026] [security2:error] [pid 25433:tid 25433] [client 162.158.154.193:12797] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.mikeziegler.com"] [uri "/.git/HEAD"] [unique_id "aoLOpV6onXZZiLChPVUCpQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
abdubhai
2026-06-24 04:26:30
(2 months ago)
162.158.154.193 - - [24/Jun/2026
...
Brute-Force
๐ฉ๐ช
abdubhai
2026-06-23 12:14:58
(2 months ago)
162.158.154.193 - - [23/Jun/2026
...
Brute-Force
๐บ๐ธ
HJ5Ss4Ju
2026-05-18 16:18:28
(3 months ago)
WordPress XMLRPC scan :: 162.158.154.193 - - [18/May/2026:16:18:27 0000] "GET /xmlrpc.php?rsd HTTP/ ...
show more
WordPress XMLRPC scan :: 162.158.154.193 - - [18/May/2026:16:18:27 0000] "GET /xmlrpc.php?rsd HTTP/1.1" 200 322 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
wimaxnz
2026-05-13 06:29:49
(3 months ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
๐บ๐ธ
wimaxnz
2026-04-15 05:00:52
(4 months ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
๐บ๐ธ
TPI-Abuse
2026-04-02 13:54:58
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 162.158.154.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.154.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 09:54:52.196256 2026] [security2:error] [pid 3843:tid 3843] [client 162.158.154.193:10038] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.nearfieldchrist.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.nearfieldchrist.com"] [uri "/config/master.key"] [unique_id "ac51LLrIoxe7c9Xf3SdwAAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 08:46:59
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 04:46:52.162554 2026] [security2:error] [pid 26762:tid 26762] [client 162.158.154.193:12754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.comparevision.com"] [uri "/.env.test"] [unique_id "ab0JfKZd_IUb2rFUr_smmQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 08:10:43
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 04:10:37.923509 2026] [security2:error] [pid 25119:tid 25119] [client 162.158.154.193:13118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "networkmediasoftware.com"] [uri "/.env.production"] [unique_id "ab0A_SY0QfqPp47ZGQBfkwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 03:41:46
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 23:41:38.723142 2026] [security2:error] [pid 30576:tid 30576] [client 162.158.154.193:12867] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.fernfield.com"] [uri "/docker/.env.local"] [unique_id "abzB8oBvjgt8DIpSsu3elgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 11:17:33
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:17:28.233561 2026] [security2:error] [pid 27896:tid 27896] [client 162.158.154.193:9946] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.spiht.com"] [uri "/root/.env"] [unique_id "abvbSMpQHwQDylUKYJ3FZwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 10:18:16
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 06:18:11.952194 2026] [security2:error] [pid 8797:tid 8797] [client 162.158.154.193:12727] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.wsdtc.net"] [uri "/.env.json"] [unique_id "abvNY9sB1IRjRSCfnGvm6wAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 09:59:13
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 05:59:08.859767 2026] [security2:error] [pid 23874:tid 23874] [client 162.158.154.193:11851] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.manb.org"] [uri "/.env.container"] [unique_id "abvI7E9Ha_HH9z3nJZhxuwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack