๐บ๐ธ
TPI-Abuse
2026-10-01 12:51:57
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 162.158.154.24 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.154.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:51:53.230415 2026] [security2:error] [pid 4761:tid 4761] [client 162.158.154.24:14231] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||smogsandiego.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "smogsandiego.com"] [uri "/index.php.bak"] [unique_id "ar5XaS1RNuUuT4ukoEUVdAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 13:45:22
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 162.158.154.24 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.154.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:45:15.230405 2026] [security2:error] [pid 26196:tid 26207] [client 162.158.154.24:9638] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.linfoulk.org|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.linfoulk.org"] [uri "/index.php.bak"] [unique_id "ar0Sa3fNQRFUb5YEMkh5CwAAAUg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 09:07:26
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 162.158.154.24 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.154.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 05:07:18.940231 2026] [security2:error] [pid 14152:tid 14152] [client 162.158.154.24:13097] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||marianozaro.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "marianozaro.com"] [uri "/index.php.bak"] [unique_id "arzRRjVI32BWwHghJMUCFwAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 05:37:48
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.24 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 01:37:43.494600 2026] [security2:error] [pid 1011:tid 1011] [client 162.158.154.24:11790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "somewierdness.com"] [uri "/wp-config.php"] [unique_id "arygJ1IJxsdSGjCUB7eP9wAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 23:41:49
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.24 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 19:41:41.691451 2026] [security2:error] [pid 32178:tid 32178] [client 162.158.154.24:13741] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "offbeatcompassion.com"] [uri "/wp-config.php"] [unique_id "arxMtTfv28ypY9Vm2_fJTQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 20:27:39
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 162.158.154.24 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.154.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 16:27:35.724929 2026] [security2:error] [pid 6163:tid 6163] [client 162.158.154.24:13093] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.misscharlottemusic.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.misscharlottemusic.com"] [uri "/index.php.bak"] [unique_id "arwfNyPBgxja4Ut0sZGsIAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 09:42:17
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.24 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 05:42:10.566896 2026] [security2:error] [pid 25847:tid 25885] [client 162.158.154.24:11453] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "greencitymethods.com"] [uri "/.htaccess"] [unique_id "aro2cjfBSIQcUfEUtLQUOQAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-09-14 15:51:12
(2 weeks ago)
Web App Attack
๐ฉ๐ช
ValtonTahiri
2026-07-18 17:15:40
(2 months ago)
UFW blocked a suspicious connection attempt to a closed or denied port. This activity is commonly as ...
show more
UFW blocked a suspicious connection attempt to a closed or denied port. This activity is commonly associated with port scanning, service discovery, or automated internet probing. Technical: source_ip=162.158.154.24; proto=TCP; source_port=10955; target_port=2096; flags=SYN
show less
Port Scan
๐ฒ๐ฝ
octageeks.com
2026-07-09 04:12:43
(2 months ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 11:07:28
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.24 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 07:07:20.634918 2026] [security2:error] [pid 17976:tid 18082] [client 162.158.154.24:11662] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "asetiadi.net"] [uri "/.env"] [unique_id "ajUi6IcKFkpiNkLWwR9ucAAAAQg"], referer: https://www.google.com/search?q=asetiadi.net
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-05-19 04:07:09
(4 months ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐บ๐ธ
octageeks.com
2026-04-04 04:45:32
(6 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐จ๐ฆ
lakered
2026-03-31 03:57:46
(6 months ago)
Honeypot Lakered: Access attempt on config (Pattern: .env). IP automatically banned.
Port Scan
Anonymous
2026-03-22 12:19:20
(6 months ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack