πΊπΈ
TPI-Abuse
2026-09-30 11:35:59
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 162.158.154.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.154.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 07:35:51.965670 2026] [security2:error] [pid 21278:tid 21278] [client 162.158.154.56:12155] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.anniesherbals.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.anniesherbals.com"] [uri "/index.php.bak"] [unique_id "arz0F8PFHaudMhHRtgDLXgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 04:13:36
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 162.158.154.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.154.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 00:13:29.184108 2026] [security2:error] [pid 21265:tid 21265] [client 162.158.154.56:13086] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.gospectre.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.gospectre.com"] [uri "/index.php.bak"] [unique_id "aryMafrd2x4v6ldro9IpPwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-28 13:39:12
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 09:39:04.873066 2026] [security2:error] [pid 6020:tid 6020] [client 162.158.154.56:12818] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.havilahmalone.com"] [uri "/wp-config.php.bak"] [unique_id "arpt-JXz_O2Xvk-e3AcTOwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
madeit
2026-09-10 00:42:46
(3 weeks ago)
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-25 00:21:33
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 20:21:25.970691 2026] [security2:error] [pid 20489:tid 20489] [client 162.158.154.56:12700] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.tarakanov.com"] [uri "/.git/config"] [unique_id "aozgBf1myD7I24HfXES01gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-24 13:21:56
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 09:21:50.028244 2026] [security2:error] [pid 11936:tid 11936] [client 162.158.154.56:11968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.stevedegroodt.com"] [uri "/.git/config"] [unique_id "aoxFbhdGDl2NMnZo53NGZwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
madeit
2026-08-06 06:09:59
(1 month ago)
Web App Attack
πΊπΈ
ratcarcher-labs
2026-08-05 14:46:25
(1 month ago)
[Ratcarcher Labs/MutantShield honeypot CTI] actor=human vector=brute_force_auth risk=80 attacks=6 de ...
show more
[Ratcarcher Labs/MutantShield honeypot CTI] actor=human vector=brute_force_auth risk=80 attacks=6 depth=2 node=node-ap-south canary=no human_score=65 agentic=15 cc=US asn=Cloudflare, Inc. | Data provided by Ratcarcher Labs Β· https://ratcarcher-labs.com Β· docs https://api.ratcarcher-labs.com/api/v1/public/docs
show less
Brute-Force
SSH
Anonymous
2026-06-28 04:20:22
(3 months ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
Anonymous
2026-06-21 22:19:23
(3 months ago)
Web App Attack
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-19 10:39:57
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 06:39:50.239586 2026] [security2:error] [pid 16551:tid 16551] [client 162.158.154.56:9869] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "caddydad.com"] [uri "/.env.dist"] [unique_id "ajUcdqx_Q4gmyHQGsxHpQAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-02 23:04:40
(3 months ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
π©πͺ
acadeova
2026-05-29 08:29:22
(4 months ago)
π¨ Recon detected (nft drop)
SRC=162.158.154.56
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(jour ...
show more
π¨ Recon detected (nft drop)
SRC=162.158.154.56
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
π¬π§
WebServ
2026-04-29 06:23:41
(5 months ago)
Blocked by ufw after 5 attempts in last 300s.
Brute-Force
πΊπΈ
octageeks.com
2026-04-10 04:08:24
(5 months ago)
Wordpress malicious attack:[octawp]
Web App Attack