๐บ๐ธ
TPI-Abuse
2026-10-01 09:34:18
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.128 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 05:34:11.082103 2026] [security2:error] [pid 31324:tid 31324] [client 162.158.155.128:10411] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.scpublicity.com"] [uri "/.htaccess"] [unique_id "ar4pE2Kp9YcI2CvoauTm4wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 11:46:34
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 162.158.155.128 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.155.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 07:46:27.938183 2026] [security2:error] [pid 17112:tid 17112] [client 162.158.155.128:9561] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||edesa.pamplonaserviciotecnico.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "edesa.pamplonaserviciotecnico.com"] [uri "/index.php.bak"] [unique_id "arz2k_XGYAeX-hpgJFmd_QAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 07:34:29
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.128 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 03:34:23.289750 2026] [security2:error] [pid 9622:tid 9622] [client 162.158.155.128:10133] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "staging.lindenwoodpark.org"] [uri "/.htaccess"] [unique_id "ary7f7umqtyHIzf2Um8r-gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 04:09:40
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.128 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 00:09:37.809773 2026] [security2:error] [pid 11248:tid 11248] [client 162.158.155.128:12006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hacertests.com"] [uri "/.htaccess"] [unique_id "aryLgR4_0SqUKqm7fPugZAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-09-29 15:35:23
(5 days ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 09:38:00
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.128 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 05:37:56.082342 2026] [security2:error] [pid 1884:tid 1884] [client 162.158.155.128:11989] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "icro.net"] [uri "/.htaccess"] [unique_id "aruG9MZkg-sYME2IhDITZAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-09-09 22:10:44
(3 weeks ago)
Web App Attack
๐ง๐ช
madeit
2026-09-01 15:20:02
(1 month ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 23:53:47
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.128 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 19:53:41.860891 2026] [security2:error] [pid 25689:tid 25689] [client 162.158.155.128:9891] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.waterarchitecture.com"] [uri "/.git/HEAD"] [unique_id "apDOBSdPY8vBI00pu55kggAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-08-20 22:23:59
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
mawan
2026-08-07 06:54:20
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
paulo.apoloni
2026-03-26 03:37:13
(6 months ago)
162.158.155.128 - - [26/Mar/2026:00:37:05 -0300] "GET /.envrc HTTP/2.0" 404 1805 "-" "-"
162.158.155 ...
show more
162.158.155.128 - - [26/Mar/2026:00:37:05 -0300] "GET /.envrc HTTP/2.0" 404 1805 "-" "-"
162.158.155.128 - - [26/Mar/2026:00:37:06 -0300] "GET /.env.docker HTTP/2.0" 404 1809 "-" "-"
162.158.155.128 - - [26/Mar/2026:00:37:06 -0300] "GET /.env_settings HTTP/2.0" 404 1810 "-" "-"
162.158.155.128 - - [26/Mar/2026:00:37:11 -0300] "GET /.env.production.local HTTP/2.0" 404 1810 "-" "-"
162.158.155.128 - - [26/Mar/2026:00:37:12 -0300] "GET /.env_backup HTTP/2.0" 404 1807 "-" "-"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 04:00:23
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.128 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 00:00:18.372699 2026] [security2:error] [pid 1448:tid 1448] [client 162.158.155.128:11909] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "healthpointphysicians.co"] [uri "/.env.container"] [unique_id "ab4X0qHEr6vS6HbygltBmgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 08:42:12
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.128 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 04:42:07.515964 2026] [security2:error] [pid 23146:tid 23146] [client 162.158.155.128:13149] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stellwagenmusic.com"] [uri "/.env.local.backup"] [unique_id "ab0IX2Q3uMVI_t3V2Gx7XwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 06:51:06
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.128 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 02:50:58.076502 2026] [security2:error] [pid 3097:tid 3097] [client 162.158.155.128:10064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.eatatlotone.com"] [uri "/.env.backup"] [unique_id "abzuUkCkIV2h6tG7mhYcBAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack