๐บ๐ธ
mawan
2026-06-28 00:52:26
(6 hours ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-16 22:03:11
(1 week ago)
Auto-ban: >3000 req/min op 2026-06-16
Web App Attack
SSH
Hacking
๐บ๐ธ
HJ5Ss4Ju
2026-06-09 18:32:32
(2 weeks ago)
WordPress XMLRPC scan :: 162.158.158.132 - - [09/Jun/2026:18:32:32 0000] "GET /xmlrpc.php HTTP/1.1" ...
show more
WordPress XMLRPC scan :: 162.158.158.132 - - [09/Jun/2026:18:32:32 0000] "GET /xmlrpc.php HTTP/1.1" 405 53 "https://mockbox.net/xmlrpc.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
HJ5Ss4Ju
2026-06-09 05:12:12
(2 weeks ago)
WordPress XMLRPC scan :: 162.158.158.132 - - [09/Jun/2026:05:12:11 0000] "GET /xmlrpc.php HTTP/1.1" ...
show more
WordPress XMLRPC scan :: 162.158.158.132 - - [09/Jun/2026:05:12:11 0000] "GET /xmlrpc.php HTTP/1.1" 405 53 "https://mockbox.net/xmlrpc.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
show less
Hacking
Brute-Force
Web App Attack
Anonymous
2026-05-03 21:40:15
(1 month ago)
Probing for known exploit paths (.env, .git, wp-admin, shell files, etc.). Single-strike ban policy ...
show more
Probing for known exploit paths (.env, .git, wp-admin, shell files, etc.). Single-strike ban policy โ zero tolerance for exploit scanning. Banned May 3, 21:40 UTC. Origin: United States, New York.
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-03-31 14:07:40
(2 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐จ๐ฆ
lakered
2026-03-30 18:10:31
(2 months ago)
Honeypot Lakered: Access attempt on config (Pattern: .env). IP automatically banned.
Port Scan
๐บ๐ธ
octageeks.com
2026-03-21 04:06:50
(3 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 01:52:06
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.132 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.132 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 21:52:00.192095 2026] [security2:error] [pid 2381:tid 2381] [client 162.158.158.132:13132] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.doreenkimura.com"] [uri "/.git/refs/heads/main"] [unique_id "ab35wBbrDFzBIxCzN03QSAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 06:29:23
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.132 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.132 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 02:29:20.673008 2026] [security2:error] [pid 22178:tid 22178] [client 162.158.158.132:9690] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ajvaage.com"] [uri "/.env.staging"] [unique_id "abzpQOOgoK3GTPBnLleJNwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 03:53:49
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.132 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.132 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 23:53:44.378652 2026] [security2:error] [pid 28813:tid 28813] [client 162.158.158.132:11774] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.uglykid.net"] [uri "/admin/.env"] [unique_id "abzEyIn8JNPQVqeQyAugAAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 02:39:36
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.132 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.132 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 22:39:29.105013 2026] [security2:error] [pid 14359:tid 14359] [client 162.158.158.132:9388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.fatcaverecords.com"] [uri "/.env.production"] [unique_id "abyzYY0GZ_CGcLk4m19WXwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 11:34:12
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.132 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.132 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:34:08.124104 2026] [security2:error] [pid 30301:tid 30301] [client 162.158.158.132:13646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ppichardocigars.com"] [uri "/.env.development.local"] [unique_id "abvfMJ2kDit26bjJlJ9X7gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 11:11:53
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.132 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.132 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:11:49.970127 2026] [security2:error] [pid 14785:tid 14785] [client 162.158.158.132:10256] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.smoothiessoupssalads.com"] [uri "/.env.orig"] [unique_id "abvZ9dcoYhT5qyef-f0XTAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 10:41:08
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.132 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.132 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 06:41:02.492484 2026] [security2:error] [pid 3999:tid 3999] [client 162.158.158.132:13263] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.comsew.com.au"] [uri "/server/.env"] [unique_id "abvSvk868uLRri61jWXTZAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack