๐บ๐ธ
TPI-Abuse
2026-10-01 01:28:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.203 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.203 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 21:28:09.490260 2026] [security2:error] [pid 25864:tid 25864] [client 162.158.154.203:12772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gatheringsattheschool.com"] [uri "/wp-config.php"] [unique_id "ar23KTu06zq7A8WFgSBFCQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 15:58:38
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 162.158.154.203 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.154.203 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:58:33.593160 2026] [security2:error] [pid 5829:tid 5829] [client 162.158.154.203:10901] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lukeschicago.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lukeschicago.com"] [uri "/index.php.bak"] [unique_id "ar0xqcgvElwRGTUVzh3iBQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 14:26:08
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 162.158.154.203 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.154.203 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 10:26:04.270575 2026] [security2:error] [pid 15105:tid 15105] [client 162.158.154.203:13594] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.paleopathologist.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.paleopathologist.com"] [uri "/index.php.bak"] [unique_id "arvKfFXW9OlJoGu2-0uuYwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 13:56:08
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.203 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.203 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 09:56:01.983367 2026] [security2:error] [pid 9391:tid 9391] [client 162.158.154.203:11995] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "instagenii.com"] [uri "/.htaccess"] [unique_id "arvDcREnF-DOp5GkayuklQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 07:59:57
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 162.158.154.203 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.154.203 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 03:59:50.282591 2026] [security2:error] [pid 15097:tid 15097] [client 162.158.154.203:10713] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.gbcwoodbine.org|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.gbcwoodbine.org"] [uri "/index.php.bak"] [unique_id "artv9uKcW3ZrZ6qp9shk8AAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 20:36:49
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 162.158.154.203 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.154.203 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 16:36:44.875199 2026] [security2:error] [pid 22271:tid 22271] [client 162.158.154.203:11003] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ohanameetup.party|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ohanameetup.party"] [uri "/index.php.bak"] [unique_id "arrP3J6fX78FqgOMy9YSQAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-09-06 17:53:07
(3 weeks ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 18:42:27
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.203 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.203 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 14:42:18.968436 2026] [security2:error] [pid 7737:tid 7737] [client 162.158.154.203:10844] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.participation.direct"] [uri "/.git/config"] [unique_id "aoyQimHUQMwyYuFFVDiizQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-22 10:27:45
(1 month ago)
Web App Attack
๐ง๐ช
madeit
2026-08-12 10:11:16
(1 month ago)
Web App Attack
Anonymous
2026-07-25 05:44:37
(2 months ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ฉ๐ช
acadeova
2026-04-26 13:24:56
(5 months ago)
๐จ Recon detected (nft drop)
SRC=162.158.154.203
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(jou ...
show more
๐จ Recon detected (nft drop)
SRC=162.158.154.203
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐บ๐ธ
octageeks.com
2026-04-10 04:08:22
(5 months ago)
Wordpress malicious attack:[octawp]
Web App Attack
๐จ๐ฆ
lakered
2026-03-31 13:44:36
(6 months ago)
Honeypot Lakered: Access attempt on config (Pattern: .env). IP automatically banned.
Port Scan
๐บ๐ธ
TPI-Abuse
2026-03-21 16:54:51
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.203 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.203 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 12:54:44.374425 2026] [security2:error] [pid 21170:tid 21170] [client 162.158.154.203:9978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.thoughtage.org"] [uri "/.env.orig"] [unique_id "ab7NVGscOxo_3Kov0eykpgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack