๐ง๐ช
madeit
2026-09-27 05:13:33
(22 hours ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 02:16:42
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:16:34.901581 2026] [security2:error] [pid 8230:tid 8230] [client 162.158.158.164:11112] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.barreda.org"] [uri "/.git/config"] [unique_id "apJBAm5y5hSv1x9zTkk6iQAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 14:27:52
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 162.158.158.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.158.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 10:27:46.717831 2026] [security2:error] [pid 19243:tid 19243] [client 162.158.158.164:10101] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.mayflowersgifts.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.mayflowersgifts.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "aljqYlCKdNSEs2t2mLbMLQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-05-06 12:40:12
(4 months ago)
162.158.158.164 - - [06/May/2026:15:40:10 +0300] "GET /wp-content/plugins/ckeditor4/filemanager/brow ...
show more
162.158.158.164 - - [06/May/2026:15:40:10 +0300] "GET /wp-content/plugins/ckeditor4/filemanager/browser/default/browser.html HTTP/1.1" 404 3349 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)"
162.158.158.164 - - [06/May/2026:15:40:11 +0300] "GET /wp-content/plugins/ckeditor-for-wordpress/filemanager/browser/default/browser.html HTTP/1.1" 404 789 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)"
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-04-21 16:54:50
(5 months ago)
162.158.158.164 - - [21/Apr/2026:19:46:56 +0300] "GET /wp-content/plugins/ubh/ HTTP/1.1" 404 768 "-" ...
show more
162.158.158.164 - - [21/Apr/2026:19:46:56 +0300] "GET /wp-content/plugins/ubh/ HTTP/1.1" 404 768 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
162.158.158.164 - - [21/Apr/2026:19:54:49 +0300] "GET /wp-includes/blocks/ HTTP/1.1" 404 768 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
octageeks.com
2026-03-30 04:08:56
(5 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 03:14:02
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 23:13:56.934458 2026] [security2:error] [pid 16800:tid 16800] [client 162.158.158.164:11958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.geriterry.com"] [uri "/var/www/html/.env"] [unique_id "ab4M9LxLGJlCkyjE-WxBJQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 09:25:14
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 05:25:10.363442 2026] [security2:error] [pid 5938:tid 5938] [client 162.158.158.164:14125] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "highgroundsconsulting.com"] [uri "/.env2"] [unique_id "ab0SdsXx0Jn5Klv04-vzCQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 08:03:45
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 04:03:38.042932 2026] [security2:error] [pid 5025:tid 5025] [client 162.158.158.164:13870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.cultiplant.com"] [uri "/.env.old"] [unique_id "abz_WuAlNcjw8sI0ILifnwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 07:15:29
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 03:15:16.448009 2026] [security2:error] [pid 13133:tid 13133] [client 162.158.158.164:12220] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.peggyannjones.us"] [uri "/.env.production.bak"] [unique_id "abz0BBw_ZgLZHV96r-6wiQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 06:33:14
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 02:33:05.236381 2026] [security2:error] [pid 15951:tid 15951] [client 162.158.158.164:10974] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ruthbalser.org"] [uri "/.env.bak"] [unique_id "abzqIbnBh5tP3HuGsKUueQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 04:37:09
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 00:37:02.538715 2026] [security2:error] [pid 372:tid 372] [client 162.158.158.164:10019] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.peaksalesnw.com"] [uri "/.env.dev"] [unique_id "abzO7phJueHC84buTokCaAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 02:19:58
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 22:19:51.449011 2026] [security2:error] [pid 25555:tid 25555] [client 162.158.158.164:13411] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "astariafilms.com"] [uri "/config/.env.local"] [unique_id "abyuxw0YrGVPUKQVX6pQjAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
lnklnx
2026-03-19 23:31:04
(6 months ago)
www.lnklnx.com:80 162.158.158.164 - - [19/Mar/2026:18:30:28 -0500] "GET /site/.env HTTP/1.1" 301 569 ...
show more
www.lnklnx.com:80 162.158.158.164 - - [19/Mar/2026:18:30:28 -0500] "GET /site/.env HTTP/1.1" 301 569 "-" "-"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 11:52:21
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:52:15.066972 2026] [security2:error] [pid 27417:tid 27417] [client 162.158.158.164:13325] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.plazahacienda.com"] [uri "/var/www/.env"] [unique_id "abvjbxxpWQb265NmXT-fnQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack