๐บ๐ธ
TPI-Abuse
2026-09-28 19:33:42
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.22 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 15:33:36.992205 2026] [security2:error] [pid 26087:tid 26087] [client 162.158.158.22:10252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "divineadventures.org"] [uri "/.htaccess"] [unique_id "arrBEIV05R6D0id7TkaOVQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
securejdprop
2026-08-24 22:41:17
(1 month ago)
This IP was detected by CrowdSec triggering custom/vpatch-bad-cloudflare.
Hacking
๐ง๐ช
madeit
2026-08-23 03:31:19
(1 month ago)
Web App Attack
๐บ๐ธ
wimaxnz
2026-05-16 04:55:36
(4 months ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
๐ฉ๐ช
acadeova
2026-04-28 17:51:44
(5 months ago)
๐จ Recon detected (nft drop)
SRC=162.158.158.22
Observed=TCP dpt=8443 in=enp0s6 ttl=57
Time=recent(jo ...
show more
๐จ Recon detected (nft drop)
SRC=162.158.158.22
Observed=TCP dpt=8443 in=enp0s6 ttl=57
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐บ๐ธ
wimaxnz
2026-04-18 08:10:16
(5 months ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
๐บ๐ธ
HJ5Ss4Ju
2026-04-16 08:47:24
(5 months ago)
WordPress XMLRPC scan :: 162.158.158.22 - - [16/Apr/2026:08:47:23 0000] "GET /xmlrpc.php HTTP/1.1" ...
show more
WordPress XMLRPC scan :: 162.158.158.22 - - [16/Apr/2026:08:47:23 0000] "GET /xmlrpc.php HTTP/1.1" 405 53 "https://www.[censored_1]/knowledge-base/wordpress/using-wordpress-wp_nav_menu_items-php-filter/" "Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36"
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-04-02 03:06:30
(5 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐ณ๐ฑ
wolfemium
2026-03-27 19:59:45
(6 months ago)
162.158.158.22 - - [27/Mar/2026:21:59:43 +0200] "GET /gifclass.php HTTP/1.1" 502 150 "-" "-"
162.158 ...
show more
162.158.158.22 - - [27/Mar/2026:21:59:43 +0200] "GET /gifclass.php HTTP/1.1" 502 150 "-" "-"
162.158.158.22 - - [27/Mar/2026:21:59:44 +0200] "GET /zsaow.php HTTP/1.1" 502 150 "-" "-"
162.158.158.22 - - [27/Mar/2026:21:59:44 +0200] "GET /themes.php HTTP/1.1" 502 150 "-" "-"
162.158.158.22 - - [27/Mar/2026:21:59:44 +0200] "GET /8.php HTTP/1.1" 502 150 "-" "-"
162.158.158.22 - - [27/Mar/2026:21:59:44 +0200] "GET /great.php HTTP/1.1" 502 150 "-" "-"
162.158.158.22 - - [27/Mar/2026:21:59:45 +0200] "GET /init.php HTTP/1.1" 502 150 "-" "-"
...
show less
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 05:50:27
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.22 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 01:50:22.710584 2026] [security2:error] [pid 15199:tid 15199] [client 162.158.158.22:11656] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rokket.com"] [uri "/docker/.env.local"] [unique_id "abzgHqX_mwA9efYgijOfhAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 04:17:23
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.22 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 00:17:16.106082 2026] [security2:error] [pid 30277:tid 30277] [client 162.158.158.22:11483] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.susanleeward.com"] [uri "/.env.development.local"] [unique_id "abzKTH5pVe7OHd5_5cZ2nAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
octageeks.com
2026-03-20 04:09:15
(6 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 03:35:31
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.22 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 23:35:26.808176 2026] [security2:error] [pid 30854:tid 30854] [client 162.158.158.22:10068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.tevalaur.com"] [uri "/.env.prod"] [unique_id "abzAfgeAs9I-bGrtrSAIiwAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 03:02:37
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.22 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 23:02:31.121757 2026] [security2:error] [pid 19803:tid 19803] [client 162.158.158.22:14018] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mezensen.com"] [uri "/home/.env"] [unique_id "aby4x1aWU8k8tzarSQEqmAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 11:34:05
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.22 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:33:59.940774 2026] [security2:error] [pid 26511:tid 26511] [client 162.158.158.22:13555] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.kingfish.bet"] [uri "/config/.env.local"] [unique_id "abvfJ6LfZH-aLKXAEbS6MgAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack