๐บ๐ธ
mawan
2026-06-20 01:45:04
(8 hours ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 06:21:42
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.153 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 02:21:35.637121 2026] [security2:error] [pid 28334:tid 28334] [client 162.158.158.153:10227] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "templeantiques.org"] [uri "/.env.local"] [unique_id "aiz275UvoV5UkoMMFuWakAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-25 10:40:43
(1 month ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
octageeks.com
2026-04-07 04:06:35
(2 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack
Anonymous
2026-04-04 00:10:22
(2 months ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
mnsf
2026-04-01 11:05:45
(2 months ago)
Scanning/Probing (17)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 03:14:22
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.153 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 23:14:14.846413 2026] [security2:error] [pid 17206:tid 17206] [client 162.158.158.153:11937] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.geriterry.com"] [uri "/root/.env"] [unique_id "ab4NBi9bCnW6NEfW1YkDuQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 09:27:00
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.153 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 05:26:54.684772 2026] [security2:error] [pid 5780:tid 5780] [client 162.158.158.153:13923] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.kahnengineering.com"] [uri "/.envrc"] [unique_id "ab0S3n6lsnhVPG883oD33wAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 08:28:11
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.153 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 04:28:02.554152 2026] [security2:error] [pid 2894960:tid 2894960] [client 162.158.158.153:10931] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theartbrush.com"] [uri "/.env.php"] [unique_id "ab0FEqK9YSI1ftHdQSR1wQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 07:39:14
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.153 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 03:39:05.850347 2026] [security2:error] [pid 6191:tid 6191] [client 162.158.158.153:14185] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.instituteofscience.com"] [uri "/.env.save"] [unique_id "abz5mXmZynb9YwEqbmeOMgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 01:28:29
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.153 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 21:28:26.303079 2026] [security2:error] [pid 25399:tid 25399] [client 162.158.158.153:12530] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kingdomvalleyfarm.com"] [uri "/.env.dev.local"] [unique_id "abyiujBuAGiJviQIL1KUJAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 11:34:12
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.153 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:34:08.576365 2026] [security2:error] [pid 1583:tid 1583] [client 162.158.158.153:10340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.lockdownclaim.com"] [uri "/backend/.env"] [unique_id "abvfMGsushqpaehGiNHJkwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 10:55:43
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.153 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 06:55:34.446519 2026] [security2:error] [pid 22932:tid 22941] [client 162.158.158.153:13172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.kd2lst.us"] [uri "/.env_backup"] [unique_id "abvWJiKn5yZ2KhvpL3Hu_QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 10:26:54
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.153 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 06:26:51.190008 2026] [security2:error] [pid 20336:tid 20336] [client 162.158.158.153:10068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.zabyte.net"] [uri "/.env.docker"] [unique_id "abvPazNBtbwul1qoZ6ijjAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 10:08:21
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.153 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 06:08:15.604303 2026] [security2:error] [pid 24631:tid 24631] [client 162.158.158.153:11730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.meler.biz"] [uri "/www/.env"] [unique_id "abvLD8OX-waiBpjVasN6vwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack