πΊπΈ
TPI-Abuse
2026-09-29 07:04:31
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 162.158.159.183 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.159.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 03:04:24.579951 2026] [security2:error] [pid 21820:tid 21820] [client 162.158.159.183:9763] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||christineohlman.net|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "christineohlman.net"] [uri "/index.php.bak"] [unique_id "arti-AIrWs5lcVQqzwjIdwAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 02:23:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.183 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 22:23:20.799588 2026] [security2:error] [pid 21926:tid 21926] [client 162.158.159.183:9500] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "neff.family.name"] [uri "/.htaccess"] [unique_id "arshGHzzksJEBzE_djUReQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-28 18:25:37
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.183 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 14:25:32.990019 2026] [security2:error] [pid 2100:tid 2100] [client 162.158.159.183:12406] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.limosnapa.com"] [uri "/wp-config.php.bak"] [unique_id "arqxHGENUVbM5BLsIYGstgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πΎ
lns.bz
2026-09-23 14:43:30
(1 week ago)
.env scanning [BY]
Web App Attack
π―π΅
S.O.B.A. Dev.
2026-08-12 13:57:02
(1 month ago)
Persistent port scanning or vulnerability scanning
Port Scan
Anonymous
2026-03-31 12:18:50
(5 months ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
π©πͺ
acadeova
2026-03-30 11:12:44
(6 months ago)
π¨ Recon detected (nft drop)
SRC=162.158.159.183
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(jou ...
show more
π¨ Recon detected (nft drop)
SRC=162.158.159.183
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-03-20 09:20:16
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.183 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 05:20:10.278129 2026] [security2:error] [pid 28984:tid 28984] [client 162.158.159.183:12488] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.surviquo.com"] [uri "/web/.env"] [unique_id "ab0RSqLbFSnMlKv96amSowAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 07:08:21
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.183 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 03:08:15.400717 2026] [security2:error] [pid 1021:tid 1021] [client 162.158.159.183:9664] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.gmroyalties.com"] [uri "/root/.env"] [unique_id "abzyX6xwJGLvttQxPbNSfwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 04:33:38
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.183 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 00:33:33.044015 2026] [security2:error] [pid 26644:tid 26644] [client 162.158.159.183:12319] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.huboon.com"] [uri "/site/.env"] [unique_id "abzOHcCT29SesZTlE4Mh_QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 02:39:38
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.183 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 22:39:34.605503 2026] [security2:error] [pid 22271:tid 22271] [client 162.158.159.183:9230] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "reneehill.mydobdate.net"] [uri "/.env.dev"] [unique_id "abyzZlXeCTPNbYze0aWhRQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 02:24:05
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.183 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 22:23:58.357530 2026] [security2:error] [pid 31899:tid 31899] [client 162.158.159.183:13860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.jacobunderwoodmusic.com"] [uri "/.env.json"] [unique_id "abyvvqGNdNgK0ZBBJ6kVfAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-19 11:23:10
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.183 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:23:05.308021 2026] [security2:error] [pid 6114:tid 6114] [client 162.158.159.183:10019] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oceanrich.aquascapes.net"] [uri "/.env~"] [unique_id "abvcmcibboqvlc8-oes6xAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-19 10:36:19
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.183 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 06:36:11.567142 2026] [security2:error] [pid 30595:tid 30595] [client 162.158.159.183:13665] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "breezentry.com"] [uri "/.env.php"] [unique_id "abvRm425ACajq1LwW-LZ7gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-19 10:13:23
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.183 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 06:13:17.359986 2026] [security2:error] [pid 25099:tid 25099] [client 162.158.159.183:11314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.designamb.com"] [uri "/private/.env"] [unique_id "abvMPTWprl29FmdF7CmMLwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack