๐บ๐ธ
TPI-Abuse
2026-10-01 18:54:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.156 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 14:54:51.914604 2026] [security2:error] [pid 9657:tid 9657] [client 162.158.155.156:13153] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stmaarten-boatcharters.com"] [uri "/wp-config.php"] [unique_id "ar6se0qY7A33bvfsAgEZUAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-10-01 01:19:46
(2 days ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 15:51:23
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.156 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:51:19.334221 2026] [security2:error] [pid 4651:tid 4657] [client 162.158.155.156:10450] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.crowns.org"] [uri "/wp-config.php"] [unique_id "ar0v97C6Ai5gio-Pz8DzlwAAAQQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 04:27:56
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.156 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 00:27:53.146898 2026] [security2:error] [pid 19342:tid 19364] [client 162.158.155.156:13528] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lavotel.com"] [uri "/.git/HEAD"] [unique_id "aryPyf7pg5rfyn4ImtdaLAAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 21:23:04
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 162.158.155.156 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.155.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 17:22:59.491286 2026] [security2:error] [pid 8648:tid 8648] [client 162.158.155.156:10890] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||earlyfordv8crrg10.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "earlyfordv8crrg10.com"] [uri "/index.php.bak"] [unique_id "arwsM_h_ZGjZ9MKIVRBH-wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 09:11:36
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.156 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 05:11:28.682249 2026] [security2:error] [pid 14495:tid 14495] [client 162.158.155.156:9323] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dpcfab.com"] [uri "/wp-config.php.bak"] [unique_id "aruAwJ2fcQ9yHj4G_5dszgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 15:33:31
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.156 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 11:33:24.024169 2026] [security2:error] [pid 28206:tid 28257] [client 162.158.155.156:12404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.myrtlebeachdiet.com"] [uri "/.htaccess"] [unique_id "arqIxID4jotFLAoWORej6QAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-09-14 14:46:29
(2 weeks ago)
Web App Attack
๐ง๐ช
madeit
2026-08-22 07:50:36
(1 month ago)
Web App Attack
๐บ๐ธ
mawan
2026-08-07 06:53:40
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-07-09 04:09:41
(2 months ago)
Wordpress malicious attack:[octaflood]
Web App Attack
Anonymous
2026-06-02 18:47:30
(4 months ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ฆ๐ฑ
router.al
2026-05-30 04:57:15
(4 months ago)
05/30/2026-04:57:14.984746 162.158.155.156 Protocol: 6 ET SCAN LeakIX Inbound User-Agent
Hacking
๐ฉ๐ช
Sรฉfora Srl
2026-04-27 16:02:00
(5 months ago)
Bad user agents ignoring web crawling rules. Draing bandwidth - detected by Fail2Ban in plesk-apache ...
show more
Bad user agents ignoring web crawling rules. Draing bandwidth - detected by Fail2Ban in plesk-apache-badbot jail
show less
Bad Web Bot
๐บ๐ธ
LotPhantom
2026-04-08 19:27:27
(5 months ago)
162.158.155.156 - - [08/Apr/2026:19:27:25 +0000] "GET / HTTP/1.1" 301 162 "-" "Go-http-client/1.1" " ...
show more
162.158.155.156 - - [08/Apr/2026:19:27:25 +0000] "GET / HTTP/1.1" 301 162 "-" "Go-http-client/1.1" "0"
...
show less
Web App Attack
Bad Web Bot