๐บ๐ธ
TPI-Abuse
2026-09-30 10:34:16
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.22 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 06:34:08.543964 2026] [security2:error] [pid 30169:tid 30169] [client 162.158.155.22:10283] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.redlinechemical.com"] [uri "/.htaccess"] [unique_id "arzloGtHvBjBY3bKP0u_vAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 08:15:52
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 162.158.155.22 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.155.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 04:15:45.473555 2026] [security2:error] [pid 6643:tid 6643] [client 162.158.155.22:12989] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.sjtent.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.sjtent.com"] [uri "/index.php.bak"] [unique_id "arzFMUehM0y3iLijbYqHfAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 05:50:24
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.22 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 01:50:18.984094 2026] [security2:error] [pid 30684:tid 30684] [client 162.158.155.22:14026] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "scoutinsignia.com"] [uri "/.htaccess"] [unique_id "aryjGvEyb1tfcmqUc1ksjAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 05:05:54
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 162.158.155.22 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.155.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 01:05:50.943747 2026] [security2:error] [pid 10734:tid 10734] [client 162.158.155.22:13410] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.mathgen.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.mathgen.com"] [uri "/index.php.bak"] [unique_id "aryYrqP5bsaBcdyvoEZE5gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 14:41:57
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.22 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 10:41:51.294021 2026] [security2:error] [pid 32361:tid 32361] [client 162.158.155.22:11362] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.nancybcatering.com"] [uri "/.htaccess"] [unique_id "arvOL6-1sNGEDuiuGf8sNAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 08:47:27
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.22 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 04:47:23.735965 2026] [security2:error] [pid 31162:tid 31162] [client 162.158.155.22:10757] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "modmove.com"] [uri "/wp-config.php"] [unique_id "art7G9OO-JDo-zv9Bo7EPAAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 00:21:08
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 162.158.155.22 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.155.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 20:21:03.514842 2026] [security2:error] [pid 12475:tid 12475] [client 162.158.155.22:11593] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||brbcash.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brbcash.com"] [uri "/index.php.bak"] [unique_id "arsEb9JJihKTc6wmjEdoVAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 18:24:47
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 162.158.155.22 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.155.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 14:24:43.734849 2026] [security2:error] [pid 4565:tid 4568] [client 162.158.155.22:13842] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||linfoulk.org|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "linfoulk.org"] [uri "/index.php.bak"] [unique_id "arqw6zUnyVEhx1eoZz0gMAAAAIE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 20:35:41
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.22 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 16:35:35.593616 2026] [security2:error] [pid 17957:tid 17957] [client 162.158.155.22:10322] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.misfitranch.com"] [uri "/.git/HEAD"] [unique_id "ao9OF14LWKmiPH0rRgH3IgAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 06:32:16
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.22 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 02:32:12.607105 2026] [security2:error] [pid 22713:tid 22713] [client 162.158.155.22:10855] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.johnpratt.net"] [uri "/.git/config"] [unique_id "aoVN7MoRVrr6JfZVjcjB2wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 03:26:10
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.22 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 23:26:03.375231 2026] [security2:error] [pid 10970:tid 10970] [client 162.158.155.22:12546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jpwatters.com.jpwatters.net"] [uri "/.git/config"] [unique_id "aoUiSxsAlD__b58VzIG18AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 06:48:24
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.22 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 02:48:16.105463 2026] [security2:error] [pid 29689:tid 29689] [client 162.158.155.22:9630] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.allautousa.com"] [uri "/.git/HEAD"] [unique_id "aoKusNygDwV04ps_yFjS0wAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
COMPLEX
2026-07-07 03:48:40
(2 months ago)
Unsolicited TCP traffic | Action: DROP | Port 8443
Brute-Force
๐ณ๐ฑ
COMPLEX
2026-07-03 02:34:40
(3 months ago)
Unsolicited TCP traffic | Action: DROP | Port 8443
Brute-Force
๐ฏ๐ต
S.O.B.A. Dev.
2026-06-23 18:30:22
(3 months ago)
Persistent port scanning or vulnerability scanning
Port Scan