🇺🇸
TPI-Abuse
2026-09-29 23:01:20
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.97 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 19:01:13.195586 2026] [security2:error] [pid 31973:tid 31973] [client 162.158.155.97:10214] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.platinumcapitalpartners.net"] [uri "/.htaccess"] [unique_id "arxDOWKVLOyrRCnKyOdxPgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇹🇷
crnpekgoz
2026-09-29 03:42:24
(23 hours ago)
Malicious HTTP GET request for '/.git/config' (HTTP 301) from 162.158.155.97. Threat: Web Güvenlik A ...
show more
Malicious HTTP GET request for '/.git/config' (HTTP 301) from 162.158.155.97. Threat: Web Güvenlik Açığı Taraması (.env/bot). Blocked by WardenGuard Web Shield.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-28 10:20:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.97 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 06:20:43.486385 2026] [security2:error] [pid 26553:tid 26553] [client 162.158.155.97:13616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.aquascapes.net"] [uri "/.htaccess"] [unique_id "aro_ezPlnYGLmpEjxjaevgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇹🇷
crnpekgoz
2026-09-25 14:11:46
(4 days ago)
Malicious HTTP GET request for '/.git/HEAD' (HTTP 301) from 162.158.155.97. Threat: Web Güvenlik Açı ...
show more
Malicious HTTP GET request for '/.git/HEAD' (HTTP 301) from 162.158.155.97. Threat: Web Güvenlik Açığı Taraması (.env/bot). Blocked by WardenGuard Web Shield.
show less
Web App Attack
🇺🇸
johnkarlhill
2026-09-14 20:20:30
(2 weeks ago)
WebKnight blocked malicious web request on johnkarlhill.com
Brute-Force
SSH
🇧🇪
madeit
2026-09-11 11:34:30
(2 weeks ago)
Web App Attack
🇫🇷
arsonist
2026-08-31 20:33:23
(4 weeks ago)
[fail2ban]
2026-08-31T20:33:23.289774+00:00 arson caddy[1890453]: {"level":"info","ts":1788208403.28 ...
show more
[fail2ban]
2026-08-31T20:33:23.289774+00:00 arson caddy[1890453]: {"level":"info","ts":1788208403.2896895,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"162.158.155.97","remote_port":"11048","client_ip":"162.158.155.97","proto":"HTTP/2.0","method":"GET","host":"ayuworks.xyz","uri":"/this_is_a_new_hello_world.php","headers":{"Cdn-Loop":["cloudflare; loops=1"],"Cf-Connecting-Ip":["52.139.44.162"],"Cf-Ipcountry":["CA"],"Cf-Visitor":["{\"scheme\":\"https\"}"],"X-Forwarded-Proto":["https"],"Accept-Encoding":["gzip, br"],"X-Forwarded-For":["52.139.44.162"],"Cf-Ray":["a33ecf56ba6443cb-EWR"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"ayuworks.xyz","ech":false}},"bytes_read":0,"user_id":"","duration":0.000124164,"size":7,"status":418,"resp_headers":{"Alt-Svc":["h3=\":443\"; ma=2592000"],"Content-Type":["text/plain; charset=utf-8"
...
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-08-19 05:17:16
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.97 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 01:17:08.916915 2026] [security2:error] [pid 27191:tid 27191] [client 162.158.155.97:9257] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.c470techarchive.net"] [uri "/.git/config"] [unique_id "aoU8VJ74Lbq919f8SQ3G4AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
polycoda
2026-04-03 14:14:25
(5 months ago)
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based)
Hacking
Web App Attack
🇺🇸
mnsf
2026-04-03 14:07:05
(5 months ago)
Scanning/Probing (15)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-03-21 05:11:10
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.97 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 01:11:02.190670 2026] [security2:error] [pid 6602:tid 6602] [client 162.158.155.97:10789] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.handcraftedparquet.chevronparkett.com"] [uri "/.env"] [unique_id "ab4oZjlqljp3bH5vuxGy5gAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-20 08:05:54
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.97 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 04:05:48.543344 2026] [security2:error] [pid 2348:tid 2348] [client 162.158.155.97:14188] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "beetreelabs.com"] [uri "/config/.env.local"] [unique_id "abz_3MxPLWFIXljuWKp1gAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-20 05:04:10
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.97 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 01:04:05.039524 2026] [security2:error] [pid 32399:tid 32399] [client 162.158.155.97:13430] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.franchiseconsultants.biz"] [uri "/srv/.env"] [unique_id "abzVRfcJlUvwNoyRa50k7gAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-20 02:39:14
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.97 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 22:39:09.141521 2026] [security2:error] [pid 14359:tid 14359] [client 162.158.155.97:13117] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.myomni.us"] [uri "/www/.env"] [unique_id "abyzTY0GZ_CGcLk4m19WWQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-20 01:41:08
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.97 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 21:41:00.449091 2026] [security2:error] [pid 30881:tid 30881] [client 162.158.155.97:12674] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.iwsa.info"] [uri "/.env_config"] [unique_id "abylrNMnZ1iv7M252k_MlQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack