๐บ๐ธ
TPI-Abuse
2026-10-01 02:45:32
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.63 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 22:45:28.781402 2026] [security2:error] [pid 8462:tid 8462] [client 162.158.154.63:11764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nflelectronics.com"] [uri "/.htaccess"] [unique_id "ar3JSIL6votPI63NwS97EAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 07:17:51
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 162.158.154.63 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.154.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 03:17:46.071618 2026] [security2:error] [pid 29281:tid 29281] [client 162.158.154.63:9725] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.akronpartybuses.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.akronpartybuses.com"] [uri "/index.php.bak"] [unique_id "ary3mhOLS_D9o9GR9DLt9wAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 06:59:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.63 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 02:59:34.129913 2026] [security2:error] [pid 2168:tid 2168] [client 162.158.154.63:9862] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "modelengines.info"] [uri "/.htaccess"] [unique_id "aryzVipo5cpA-jID0bcimgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 22:47:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.63 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 18:47:28.225473 2026] [security2:error] [pid 9899:tid 10043] [client 162.158.154.63:10066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gafm.org"] [uri "/.htaccess"] [unique_id "arxAALjD7-oPOcKDwwGZrgAAAUw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 20:48:11
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 162.158.154.63 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.154.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 16:48:05.677034 2026] [security2:error] [pid 7282:tid 7282] [client 162.158.154.63:14143] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.konahawaiirealty.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.konahawaiirealty.com"] [uri "/index.php.bak"] [unique_id "arwkBevxAu-PoNucOvkhGwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-09-18 19:51:30
(1 week ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 11:33:24
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.63 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 07:33:17.134891 2026] [security2:error] [pid 30216:tid 30216] [client 162.158.154.63:13172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.jennifergiesler.com"] [uri "/.git/HEAD"] [unique_id "aowr_a28FML0h1f6fSI_ogAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-07-08 07:54:27
(2 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฌ๐ง
CrystalMaker
2026-07-02 01:30:59
(2 months ago)
Vulnerability scan - GET /status HTTP/2.0
Hacking
๐บ๐ธ
TPI-Abuse
2026-03-21 00:30:57
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.63 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 20:30:50.243228 2026] [security2:error] [pid 3492:tid 3492] [client 162.158.154.63:9901] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.acupressbooks.com"] [uri "/.env.dev"] [unique_id "ab3muqf94xKDnppnQfva9QAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 09:31:47
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.63 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 05:31:39.335153 2026] [security2:error] [pid 23996:tid 23996] [client 162.158.154.63:9759] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "district7vote.com"] [uri "/.env_backup"] [unique_id "ab0T-wpTulZzjU_qw0uUZwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 05:59:27
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.63 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 01:59:23.296605 2026] [security2:error] [pid 15414:tid 15414] [client 162.158.154.63:10549] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.mobileonlinecasinos.co"] [uri "/.env~"] [unique_id "abziO409hlTZJaxsgDWx8AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 04:02:58
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.63 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 00:02:48.485719 2026] [security2:error] [pid 16227:tid 16227] [client 162.158.154.63:12504] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.scr-publications.com"] [uri "/.env.backup"] [unique_id "abzG6JUz0Bzgj0uja-OfdwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 10:43:45
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.63 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 06:43:41.020835 2026] [security2:error] [pid 9286:tid 9286] [client 162.158.154.63:12318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.microbooty.com"] [uri "/.env.prod"] [unique_id "abvTXddcZke9xio974qVQAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 10:00:26
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.63 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 06:00:21.092376 2026] [security2:error] [pid 1028:tid 1028] [client 162.158.154.63:10842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trendwolf.org"] [uri "/var/www/html/.env"] [unique_id "abvJNTk8DrUR9BfpF4Pz8QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack