๐ซ๐ท
dynamix
2026-10-09 19:46:52
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ง๐ช
madeit
2026-09-30 14:16:55
(1 week ago)
Web App Attack
Anonymous
2026-09-26 19:45:33
(2 weeks ago)
"Packet Flood; Triggered WAF; Persistent 404 Attempts"
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 12:53:42
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.33 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 08:53:35.856594 2026] [security2:error] [pid 7345:tid 7345] [client 162.158.158.33:11540] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lockyers.com"] [uri "/.git/HEAD"] [unique_id "arfATyS-0E8gpCOQyn7gZAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-09-22 20:53:48
(2 weeks ago)
Web App Attack
๐ง๐ช
madeit
2026-08-06 04:07:39
(2 months ago)
Web App Attack
๐ฌ๐ง
OptimusGO
2026-07-26 13:02:24
(2 months ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-26 14:02:24 UTC
Log evidence:
162.158.158.33 - - [26/Jul/2026:14:02:23 +0100] "GET / HTTP/1.1" 200 409 "-" "Python/3.11 aiohttp/3.12.13"
07/26/2026-14:02:23.330005 [**] [1:2064326:1] ET INFO Python aiohttp User-Agent Observed Inbound [**] [Classification: A Network Trojan was detected] [Priority: 1] {TCP} 162.158.158.33:11127 -> 185.127.18.66:80
07/26/2026-14:02:23.330005 [**] [1:1000201:1] SCANNER: Bot-like User-Agent Detected [**] [Classification: Attempted Information Leak] [Priority: 2] {TCP} 162.158.158.33:11127 -> 185.127.18.66:80
show less
Port Scan
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-20 19:54:03
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 162.158.158.33 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.158.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 15:53:55.110363 2026] [security2:error] [pid 773185:tid 773185] [client 162.158.158.33:21826] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.albionglobalmarketing.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.albionglobalmarketing.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "al5806tf4MjeTR77AKmXbwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
slay3r9903
2026-06-09 04:54:48
(4 months ago)
Web app scanning
Brute-Force
Port Scan
๐ฎ๐ช
eyesilyurt
2026-05-18 02:12:34
(4 months ago)
p- login authenticator failed Incorrect authentication data
Brute-Force
SSH
Anonymous
2026-04-25 03:54:53
(5 months ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ฌ๐ง
OptimusGO
2026-04-04 16:25:01
(6 months ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-04-04 17:25:01 UTC
Log evidence:
Binary file /var/log/suricata/fast.log matches
show less
Port Scan
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-03-21 04:39:02
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.33 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 00:38:56.944160 2026] [security2:error] [pid 27135:tid 27135] [client 162.158.158.33:11488] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.jerusalem-korczak-home.com"] [uri "/.git/logs/HEAD"] [unique_id "ab4g4Ax7Slz2SSxBtGew3gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 00:07:50
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.33 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 20:07:41.996276 2026] [security2:error] [pid 14690:tid 14690] [client 162.158.158.33:10014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.businessvaluationapp.com"] [uri "/.env.local"] [unique_id "ab3hTaQlf74qD0EHvsh5VgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 07:07:20
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.158.33 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.158.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 03:07:16.332544 2026] [security2:error] [pid 28778:tid 28778] [client 162.158.158.33:12153] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.gmroyalties.com"] [uri "/.env.prod"] [unique_id "abzyJAX9QBr_ruqCUn_QUwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack