๐ฉ๐ช
ghostwarriors
2026-08-21 12:50:07
(5 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-08-21 12:31:47
(5 days ago)
162.158.155.30 - - [21/Aug/2026:14:31:45 +0200] "GET /wp-includes/Text/wp-conflg.php HTTP/2.0" 404 3 ...
show more
162.158.155.30 - - [21/Aug/2026:14:31:45 +0200] "GET /wp-includes/Text/wp-conflg.php HTTP/2.0" 404 357 "-" "-"
162.158.155.30 - - [21/Aug/2026:14:31:37 +0200] "GET /wp-content/plugins/index.php HTTP/2.0" 404 357 "-" "-"
162.158.155.30 - - [21/Aug/2026:14:31:38 +0200] "GET /wp-admin/js/widgets/ HTTP/2.0" 404 312 "-" "-"
162.158.155.30 - - [21/Aug/2026:14:31:45 +0200] "GET /wp-block.php HTTP/2.0" 404 295 "-" "-"
show less
Web App Attack
Brute-Force
๐ฎ๐ฉ
securejdprop
2026-08-21 05:48:40
(6 days ago)
This IP was detected by CrowdSec triggering custom/vpatch-bad-cloudflare.
Hacking
๐ฏ๐ต
S.O.B.A. Dev.
2026-08-09 13:56:49
(2 weeks ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐ง๐ช
madeit
2026-08-06 12:27:16
(2 weeks ago)
Web App Attack
๐ฉ๐ช
Blexyel
2026-06-16 02:41:06
(2 months ago)
162.158.155.30 - - [16/Jun/2026:04:41:05 +0200] "GET /wp-login.php HTTP/1.1" 403 326 "-" "Mozilla/5. ...
show more
162.158.155.30 - - [16/Jun/2026:04:41:05 +0200] "GET /wp-login.php HTTP/1.1" 403 326 "-" "Mozilla/5.0" "s3-proxied.fomx.gay"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 20:33:38
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.30 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 16:33:32.216089 2026] [security2:error] [pid 15857:tid 15857] [client 162.158.155.30:12887] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "menagri.com"] [uri "/.env.backup"] [unique_id "ai2-nIJJedTEUItIcxldrQAAAA8"], referer: https://www.google.com/search?q=menagri.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-04-09 02:05:37
(4 months ago)
Scanning/Probing (13)
Brute-Force
Web App Attack
๐บ๐ธ
octageeks.com
2026-04-08 04:06:16
(4 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 05:08:10
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.30 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 01:08:02.848075 2026] [security2:error] [pid 11023:tid 11023] [client 162.158.155.30:13631] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.415test.com"] [uri "/docker/.env.local"] [unique_id "abzWMjJCkuQaI0MqGDZ8SgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 04:11:56
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.30 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 00:11:50.716019 2026] [security2:error] [pid 11958:tid 11958] [client 162.158.155.30:14134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.landex.auction"] [uri "/.env.backup"] [unique_id "abzJBhvkS9GwjsDtOWd6SgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 11:44:29
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.30 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:44:08.100401 2026] [security2:error] [pid 9815:tid 9815] [client 162.158.155.30:13836] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "feministvoice.blog"] [uri "/.env.local"] [unique_id "abvhiGO0ba62rve4QOsSvAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 11:11:26
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.30 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:11:17.842284 2026] [security2:error] [pid 20198:tid 20198] [client 162.158.155.30:9877] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.fltsiminc.com"] [uri "/api/.env"] [unique_id "abvZ1XpJWTO90wxZ4CjT4AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 10:36:47
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.30 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 06:36:40.395039 2026] [security2:error] [pid 24312:tid 24312] [client 162.158.155.30:12278] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.premiumenterprisessolution.com"] [uri "/site/.env"] [unique_id "abvRuG6t7SVtQm9NqdAgRgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 10:20:50
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.30 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 06:20:47.150620 2026] [security2:error] [pid 5163:tid 5163] [client 162.158.155.30:12763] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.bbernal.com"] [uri "/.env.backup"] [unique_id "abvN_2TLbi3cs_BTdJmOXwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack