πΊπΈ
TPI-Abuse
2026-10-01 15:35:47
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 162.158.154.35 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.154.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:35:41.821424 2026] [security2:error] [pid 6399:tid 6399] [client 162.158.154.35:10873] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.lemobba.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.lemobba.com"] [uri "/index.php.bak"] [unique_id "ar59zWtcq-qWif7lkNECugAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 04:46:13
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 162.158.154.35 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.154.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 00:46:10.453765 2026] [security2:error] [pid 11768:tid 11916] [client 162.158.154.35:11609] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.abusaimeh.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.abusaimeh.com"] [uri "/index.php.bak"] [unique_id "ar3lkqrOiL7pNktH4PHPawAAApc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 14:02:23
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.35 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:02:18.006451 2026] [security2:error] [pid 9038:tid 9038] [client 162.158.154.35:14075] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.yacht-register-holland.com"] [uri "/.htaccess"] [unique_id "ar0WalZ6XXLUigQY5_TmHAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 07:31:48
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.35 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 03:31:45.308916 2026] [security2:error] [pid 15538:tid 15551] [client 162.158.154.35:12330] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.projectmanagementcertification.org"] [uri "/.htaccess"] [unique_id "ary64ZodGAjQ5hYGwA_3-AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 01:57:30
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 162.158.154.35 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.154.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 21:57:23.410834 2026] [security2:error] [pid 1125:tid 1125] [client 162.158.154.35:10694] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||easy2surf.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "easy2surf.com"] [uri "/index.php.bak"] [unique_id "arxsg31ZTiSNoL0H0RCQJAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 18:09:38
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.35 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 14:09:34.719578 2026] [security2:error] [pid 19168:tid 19168] [client 162.158.154.35:12016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cameronwv.com"] [uri "/wp-config.php"] [unique_id "arv-3pZf6Nv1mIgNVPqSnAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
madeit
2026-09-18 19:49:31
(2 weeks ago)
Web App Attack
πΊπΈ
johnkarlhill
2026-09-09 05:55:34
(3 weeks ago)
WebKnight blocked malicious web request on johnkarlhill.com
Brute-Force
SSH
π§πͺ
madeit
2026-09-02 19:20:27
(1 month ago)
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 21:04:55
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.35 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 17:04:47.018545 2026] [security2:error] [pid 30278:tid 30278] [client 162.158.154.35:13107] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sewacheckbookcover.com"] [uri "/.git/config"] [unique_id "ao9U768L_0dFMAUfoSNaugAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 16:13:58
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.35 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 12:13:52.313813 2026] [security2:error] [pid 5620:tid 5620] [client 162.158.154.35:13225] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.ralserve.net"] [uri "/.git/HEAD"] [unique_id "aoMzQLAE1FUQ5dmKLQmNZAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
wiredalter
2026-06-25 22:37:19
(3 months ago)
Blocked by UFW on dVPS [8443/tcp]
Source Port: 10878
TTL: 53
Packet Length: 60
TOS: 0x00
Analyzed b ...
show more
Blocked by UFW on dVPS [8443/tcp]
Source Port: 10878
TTL: 53
Packet Length: 60
TOS: 0x00
Analyzed by https://ip.wiredalter.com
show less
Port Scan
Brute-Force
π©πͺ
acadeova
2026-05-08 21:53:25
(4 months ago)
π¨ Recon detected (nft drop)
SRC=162.158.154.35
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(jour ...
show more
π¨ Recon detected (nft drop)
SRC=162.158.154.35
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
π©πͺ
acadeova
2026-04-28 17:40:38
(5 months ago)
π¨ Recon detected (nft drop)
SRC=162.158.154.35
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(jour ...
show more
π¨ Recon detected (nft drop)
SRC=162.158.154.35
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
π©πͺ
acadeova
2026-04-20 18:31:38
(5 months ago)
π¨ Recon detected (nft drop)
SRC=162.158.154.35
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(jour ...
show more
π¨ Recon detected (nft drop)
SRC=162.158.154.35
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan