πΊπ¦
URAN Publishing Service
2026-06-20 17:59:23
(17 hours ago)
162.158.159.105 - - [20/Jun/2026:20:59:21 +0300] "GET /wp-admin/css/colors/index.php HTTP/1.1" 404 7 ...
show more
162.158.159.105 - - [20/Jun/2026:20:59:21 +0300] "GET /wp-admin/css/colors/index.php HTTP/1.1" 404 791 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
162.158.159.105 - - [20/Jun/2026:20:59:22 +0300] "GET /wp-includes/js/ HTTP/1.1" 404 791 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-17 00:12:05
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.105 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.105 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 20:12:01.556389 2026] [security2:error] [pid 7083:tid 7083] [client 162.158.159.105:24976] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "summitartists.summithost.com"] [uri "/.env.production"] [unique_id "ajHmUcqcU4t_dAnC_pJlGwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-06-16 10:38:08
(5 days ago)
162.158.159.105 - - [16/Jun/2026:13:38:01 +0300] "GET /wp-content/admin.php HTTP/1.1" 404 791 "-" "M ...
show more
162.158.159.105 - - [16/Jun/2026:13:38:01 +0300] "GET /wp-content/admin.php HTTP/1.1" 404 791 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
162.158.159.105 - - [16/Jun/2026:13:38:08 +0300] "GET /wp-admin/js/ HTTP/1.1" 404 791 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
Anonymous
2026-06-01 21:54:02
(2 weeks ago)
[Mon Jun 01 23:53:57.206695 2026] [authz_core:error] [pid 14129] [client 162.158.159.105:13978] AH01 ...
show more
[Mon Jun 01 23:53:57.206695 2026] [authz_core:error] [pid 14129] [client 162.158.159.105:13978] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon Jun 01 23:54:01.460340 2026] [authz_core:error] [pid 14129] [client 162.158.159.105:13978] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon Jun 01 23:54:01.699140 2026] [authz_core:error] [pid 14129] [client 162.158.159.105:13978] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
Anonymous
2026-04-28 20:20:44
(1 month ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
πΊπ¦
URAN Publishing Service
2026-04-23 17:17:11
(1 month ago)
162.158.159.105 - - [23/Apr/2026:20:16:53 +0300] "GET /wp-admin/css/ HTTP/1.1" 404 770 "-" "Mozlila/ ...
show more
162.158.159.105 - - [23/Apr/2026:20:16:53 +0300] "GET /wp-admin/css/ HTTP/1.1" 404 770 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
162.158.159.105 - - [23/Apr/2026:20:17:11 +0300] "GET /wp-admin/ALFA_DATA/ HTTP/1.1" 404 770 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
...
show less
Web App Attack
πΊπΈ
octageeks.com
2026-03-23 04:07:45
(2 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-21 00:40:49
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.105 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.105 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 20:40:43.054936 2026] [security2:error] [pid 26650:tid 26650] [client 162.158.159.105:14154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.nmposters.com"] [uri "/.env.development"] [unique_id "ab3pC4S0Ys71JunNp55uUAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 07:59:17
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.105 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.105 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 03:59:12.955458 2026] [security2:error] [pid 15651:tid 15651] [client 162.158.159.105:10565] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.boat-registration-croatia.com"] [uri "/config/.env"] [unique_id "abz-UPfOR41ENFWO5xesxwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 05:46:46
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.105 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.105 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 01:46:42.565224 2026] [security2:error] [pid 15199:tid 15199] [client 162.158.159.105:10932] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rokket.com"] [uri "/root/.env"] [unique_id "abzfQqX_mwA9efYgijOfcgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 05:06:16
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.105 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.105 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 01:06:09.509399 2026] [security2:error] [pid 7586:tid 7586] [client 162.158.159.105:12797] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.rhkglobal.com"] [uri "/.env.json"] [unique_id "abzVwR58_Y143hgTGEfOkQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 03:20:14
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.105 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.105 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 23:20:09.372374 2026] [security2:error] [pid 22798:tid 22798] [client 162.158.159.105:11029] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "innovacionesnimba.com"] [uri "/.envrc"] [unique_id "aby86bZikHK5sC-azlDS2AAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-19 11:55:05
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.105 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.105 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:54:59.439658 2026] [security2:error] [pid 5526:tid 5526] [client 162.158.159.105:9957] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.awcadvocate.com"] [uri "/.env.production"] [unique_id "abvkE99zv5fSRaoH28F94gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-19 11:31:37
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.105 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.105 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:31:29.709926 2026] [security2:error] [pid 31508:tid 31508] [client 162.158.159.105:12986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.lockdownclaim.com"] [uri "/.env.container"] [unique_id "abvekQIl96zdvq2kzfbzFAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-19 11:05:54
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.105 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.105 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:05:46.180601 2026] [security2:error] [pid 9638:tid 9638] [client 162.158.159.105:9630] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.gkerby.com"] [uri "/.env.backup"] [unique_id "abvYiipHjFImsFVpCMMOXQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack