๐บ๐ธ
TPI-Abuse
2026-08-27 22:58:15
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.92 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 18:58:10.600621 2026] [security2:error] [pid 7843:tid 7843] [client 162.158.155.92:11163] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.liyatalton.com"] [uri "/.git/config"] [unique_id "apDBAlWFNB9XpRa6tyEJwAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-26 17:46:30
(1 week ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 16:14:06
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.92 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 12:13:58.473658 2026] [security2:error] [pid 27004:tid 27004] [client 162.158.155.92:12199] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.saramics.net"] [uri "/.git/HEAD"] [unique_id "aoMzRqSRAxaGvaVTfiEnhQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-06 06:11:14
(3 weeks ago)
Web App Attack
Anonymous
2026-07-05 05:20:01
(1 month ago)
162.158.155.92 - - [05/Jul/2026:07:19:44 +0200] "GET /dashboard/%2egit/config HTTP/1.1" 403 124 "-" ...
show more
162.158.155.92 - - [05/Jul/2026:07:19:44 +0200] "GET /dashboard/%2egit/config HTTP/1.1" 403 124 "-" "curl/8.7.1"
162.158.155.92 - - [05/Jul/2026:07:19:44 +0200] "GET /down%2ehtml HTTP/1.1" 403 124 "-" "curl/8.7.1"
162.158.155.92 - - [05/Jul/2026:07:19:44 +0200] "GET /src/error%2elog HTTP/1.1" 403 124 "-" "curl/8.7.1"
162.158.155.92 - - [05/Jul/2026:07:19:44 +0200] "GET /admin/config/ses%2eenv HTTP/1.1" 403 124 "-" "curl/8.7.1"
162.158.155.92 - - [05/Jul/2026:07:19:45 +0200] "GET /admin/config/config%2eenv HTTP/1.1" 403 124 "-" "curl/8.7.1"
162.158.155.92 - - [05/Jul/2026:07:19:46 +0200] "GET /admin/config/readme%2eenv HTTP/1.1" 403 124 "-" "curl/8.7.1"
162.158.155.92 - - [05/Jul/2026:07:19:46 +0200] "GET /production/%2eenv%2eproduction%2elocal HTTP/1.1" 403 124 "-" "curl/8.7.1"
162.158.155.92 - - [05/Jul/2026:07:19:46 +0200] "GET /admin/env/secret%2eenv HTTP/1.1" 403 124 "-" "curl/8.7.1"
162.158.155.92 - - [05/Jul/2026:07:19:46 +0200] "GET /secrets/mailgun_credentials%2ejson HTTP/1.1"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-07-03 13:42:44
(1 month ago)
162.158.155.92 - - [03/Jul/2026:15:42:43 +0200] "GET //wp1/wp-includes/wlwmanifest.xml HTTP/1.1" 404 ...
show more
162.158.155.92 - - [03/Jul/2026:15:42:43 +0200] "GET //wp1/wp-includes/wlwmanifest.xml HTTP/1.1" 404 441 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
162.158.155.92 - - [03/Jul/2026:15:42:43 +0200] "GET //wp1/wp-includes/wlwmanifest.xml HTTP/1.1" 404 246 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
162.158.155.92 - - [03/Jul/2026:15:42:44 +0200] "GET //test/wp-includes/wlwmanifest.xml HTTP/1.1" 404 441 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
162.158.155.92 - - [03/Jul/2026:15:42:44 +0200] "GET //test/wp-includes/wlwmanifest.xml HTTP/1.1" 404 246 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
162.158.155.92 - - [03/Jul/2026:15:42:44 +0200] "GET //site/wp-includes/wlwmanifest.xml HTTP/1
...
show less
Brute-Force
Web App Attack
๐ง๐ท
maviei
2026-06-16 09:06:39
(2 months ago)
2026-06-16T06:06:36.373501-03:00 srv1251771 kernel: [1367625.561854] [UFW BLOCK] IN=eth0 OUT= MAC=40 ...
show more
2026-06-16T06:06:36.373501-03:00 srv1251771 kernel: [1367625.561854] [UFW BLOCK] IN=eth0 OUT= MAC=40:e8:d4:b8:29:bb:44:38:39:ff:ff:41:08:00 SRC=162.158.155.92 DST=72.61.36.27 LEN=60 TOS=0x00 PREC=0x00 TTL=52 ID=48990 DF PROTO=TCP SPT=13709 DPT=8443 WINDOW=65535 RES=0x00 SYN URGP=0
2026-06-16T06:06:37.430485-03:00 srv1251771 kernel: [1367626.618846] [UFW BLOCK] IN=eth0 OUT= MAC=40:e8:d4:b8:29:bb:44:38:39:ff:ff:41:08:00 SRC=162.158.155.92 DST=72.61.36.27 LEN=60 TOS=0x00 PREC=0x00 TTL=52 ID=48991 DF PROTO=TCP SPT=13709 DPT=8443 WINDOW=65535 RES=0x00 SYN URGP=0
2026-06-16T06:06:38.454635-03:00 srv1251771 kernel: [1367627.642041] [UFW BLOCK] IN=eth0 OUT= MAC=40:e8:d4:b8:29:bb:44:38:39:ff:ff:41:08:00 SRC=162.158.155.92 DST=72.61.36.27 LEN=60 TOS=0x00 PREC=0x00 TTL=52 ID=48992 DF PROTO=TCP SPT=13709 DPT=8443 WINDOW=65535 RES=0x00 SYN URGP=0
...
show less
Port Scan
๐จ๐ฆ
yukon.ca
2026-04-12 21:01:17
(4 months ago)
Web Server Enforcement Violation: Web Server Exposed Git Repository Information Disclosure
Port:80
Hacking
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-03-21 04:35:48
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.92 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 00:35:45.119231 2026] [security2:error] [pid 6996:tid 6996] [client 162.158.155.92:11920] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.brazilianthongs.brazilianbottom.com"] [uri "/.env.php"] [unique_id "ab4gIZRqJJ3FkqQxGBkxGwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-03-20 20:18:01
(5 months ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 09:31:21
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.92 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 05:31:17.999726 2026] [security2:error] [pid 3036:tid 3036] [client 162.158.155.92:9253] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.aticom.net"] [uri "/.env.backup"] [unique_id "ab0T5d34Fci6S3e1JeXcoAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 09:03:31
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.92 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 05:03:26.946696 2026] [security2:error] [pid 7610:tid 7610] [client 162.158.155.92:10194] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.mfleetservice.com"] [uri "/.env.production"] [unique_id "ab0NXvIkSmnT5F3N6xGukAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 08:42:52
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.92 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 04:42:46.398149 2026] [security2:error] [pid 24361:tid 24361] [client 162.158.155.92:12992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oxford-gliding-club.abbeygardensllandudno.com"] [uri "/.env1"] [unique_id "ab0IhiRF-2nrtBKOm52EmgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 07:39:43
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.92 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 03:39:37.312799 2026] [security2:error] [pid 31380:tid 31380] [client 162.158.155.92:9931] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.rooksfamily.com"] [uri "/.env.json"] [unique_id "abz5uQ-SsAj1LIENwkhbcgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 05:29:06
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.92 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 01:28:59.690181 2026] [security2:error] [pid 23469:tid 23469] [client 162.158.155.92:11234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.partybuseslansing.com"] [uri "/.env.dev"] [unique_id "abzbG2yoZnOufd9Q-rp5tAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack