๐บ๐ธ
TPI-Abuse
2026-10-01 04:23:27
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.233 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 00:23:19.962596 2026] [security2:error] [pid 30779:tid 30847] [client 162.158.155.233:13734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bobchaos.com"] [uri "/.svn/entries"] [unique_id "ar3gN6efsK571sIigJmcOQAAAYg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 03:03:32
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.233 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 23:03:28.439177 2026] [security2:error] [pid 23878:tid 23878] [client 162.158.155.233:13473] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mirandaracewalks.com"] [uri "/wp-config.php.bak"] [unique_id "ar3NgGVGYu6-lvGg2wl-PAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:52:10
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 162.158.155.233 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.155.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:52:07.237760 2026] [security2:error] [pid 23263:tid 23263] [client 162.158.155.233:10149] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.doctoredwinalvarez.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.doctoredwinalvarez.com"] [uri "/index.php.bak"] [unique_id "ar0iFw0A-ai7sK6vAzPDigAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:18:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.233 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:18:55.252133 2026] [security2:error] [pid 26808:tid 26808] [client 162.158.155.233:13898] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "worthhistory.org"] [uri "/.htaccess"] [unique_id "ar0aT6at2hq5ooiureHJ8QAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 13:34:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.233 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:34:22.592427 2026] [security2:error] [pid 11904:tid 11904] [client 162.158.155.233:10651] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.limobustacoma.com"] [uri "/.htaccess"] [unique_id "ar0P3kSBTjbjLZbXaH5iwAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 11:35:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.233 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 07:35:39.326859 2026] [security2:error] [pid 8617:tid 8617] [client 162.158.155.233:9233] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "barillaequipment.com"] [uri "/wp-config.php"] [unique_id "arz0Czsw5O6UpApi3TKa3wAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 05:55:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.233 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 01:54:59.867006 2026] [security2:error] [pid 7147:tid 7172] [client 162.158.155.233:10268] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gotlib.net"] [uri "/.htaccess"] [unique_id "arykM2JLoUnRVIHkJwOllgAAAIs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 15:15:25
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 162.158.155.233 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.155.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 11:15:19.930812 2026] [security2:error] [pid 9849:tid 9870] [client 162.158.155.233:10911] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||davidtung.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "davidtung.com"] [uri "/index.php.bak"] [unique_id "arvWB4V5syy6eBVakp1PQQAAARI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 08:24:09
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.233 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 04:24:04.443699 2026] [security2:error] [pid 17938:tid 17938] [client 162.158.155.233:12111] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tomweston.net"] [uri "/wp-config.php.bak"] [unique_id "art1pFrMrB3g6WDh5GhFLwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-09-11 07:28:01
(2 weeks ago)
Web App Attack
๐ฆ๐ฑ
router.al
2026-09-10 08:30:36
(3 weeks ago)
09/10/2026-08:30:35.952870 162.158.155.233 Protocol: 6 ET SCAN LeakIX Inbound User-Agent
Hacking
๐ง๐ช
madeit
2026-08-23 03:13:54
(1 month ago)
Web App Attack
๐ฉ๐ช
acadeova
2026-06-06 03:22:35
(3 months ago)
๐จ Recon detected (nft drop)
SRC=162.158.155.233
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(jou ...
show more
๐จ Recon detected (nft drop)
SRC=162.158.155.233
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
Anonymous
2026-05-17 05:31:05
(4 months ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ฎ๐ฉ
gonet.home
2026-05-09 14:10:12
(4 months ago)
Security Event Detected by SOC Gonet: event=alert, hits=1
Brute-Force