๐บ๐ธ
TPI-Abuse
2026-10-01 13:20:13
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 162.158.155.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.155.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:20:08.091216 2026] [security2:error] [pid 2097:tid 2097] [client 162.158.155.164:10514] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.greenroomonline.org|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.greenroomonline.org"] [uri "/index.php.bak"] [unique_id "ar5eCHyh2i0ggnEUw8WbBwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 05:58:36
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 01:58:32.900660 2026] [security2:error] [pid 21571:tid 21571] [client 162.158.155.164:9827] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.empoweruohio.org"] [uri "/.htaccess"] [unique_id "ar32iFE0dm2BbMs7jI76jwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 03:16:01
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 23:15:53.946248 2026] [security2:error] [pid 27917:tid 27917] [client 162.158.155.164:12177] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.nearfieldchrist.com"] [uri "/wp-config.php"] [unique_id "ar3QaTSt08mx9yNDZwHHugAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 17:24:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 13:24:51.456125 2026] [security2:error] [pid 21746:tid 21746] [client 162.158.155.164:10695] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sb-adventures.com"] [uri "/wp-config.php"] [unique_id "arv0Y1FzHXCNoK-EsFLJ7wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 08:43:40
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 162.158.155.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.155.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 04:43:33.503741 2026] [security2:error] [pid 25025:tid 25025] [client 162.158.155.164:9396] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||art.mavikalem.org|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "art.mavikalem.org"] [uri "/index.php.bak"] [unique_id "art6NfLu6BMMLNr7YsZvVQAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 03:16:14
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 162.158.155.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.155.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 23:16:09.504089 2026] [security2:error] [pid 20185:tid 20206] [client 162.158.155.164:12816] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.e-dome.co.jp|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.e-dome.co.jp"] [uri "/index.php.bak"] [unique_id "arsteVkzsAAtya_vosA7HAAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 18:33:14
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 162.158.155.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.155.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 14:33:09.823053 2026] [security2:error] [pid 24088:tid 24088] [client 162.158.155.164:10455] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.thewellnessxperience.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.thewellnessxperience.com"] [uri "/index.php.bak"] [unique_id "arqy5R2EQwtxXxDGuGLrBAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-09-26 15:27:11
(5 days ago)
Web App Attack
๐ง๐ช
madeit
2026-09-14 21:52:16
(2 weeks ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 20:17:16
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 16:17:12.905485 2026] [security2:error] [pid 23774:tid 23774] [client 162.158.155.164:13661] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.businessgetwellcards.com"] [uri "/.git/HEAD"] [unique_id "ao9JyB3HIkaiFN4Y4zlfIwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-26 17:50:57
(1 month ago)
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-06-13 14:22:49
(3 months ago)
162.158.155.164 - - [13/Jun/2026:17:22:49 +0300] "GET /.env.development HTTP/2.0" 404 134 "-" "Mozil ...
show more
162.158.155.164 - - [13/Jun/2026:17:22:49 +0300] "GET /.env.development HTTP/2.0" 404 134 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 15_7_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/26.0 Safari/605.1.15"
...
show less
Hacking
Web App Attack
๐บ๐ธ
drewf.ink
2026-05-02 05:23:59
(4 months ago)
[05:23] Port scanning. Port(s) scanned: TCP/8080
Port Scan
๐บ๐ธ
drewf.ink
2026-03-27 16:47:33
(6 months ago)
[16:47] Port scanning. Port(s) scanned: TCP/2095
Port Scan
๐บ๐ธ
TPI-Abuse
2026-03-21 04:49:40
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 00:49:34.980949 2026] [security2:error] [pid 28341:tid 28341] [client 162.158.155.164:10192] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chrisbilder.com"] [uri "/var/www/html/.env"] [unique_id "ab4jXlqVp7TWMN1REZ-rXAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack