πΊπΈ
TPI-Abuse
2026-09-26 14:28:08
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 10:28:03.915989 2026] [security2:error] [pid 19812:tid 19820] [client 162.158.159.193:11876] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "geoception.com"] [uri "/wp-config.php"] [unique_id "arfWc71zer0LE5nwKwuTmQAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-26 10:15:04
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 06:14:55.019893 2026] [security2:error] [pid 3357:tid 3357] [client 162.158.159.193:11044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lakewoodranchhairsalon.com"] [uri "/.htaccess"] [unique_id "arebHzF8wyKJmov9nfxZ6AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
yitzhaq
2026-08-21 12:34:12
(1 month ago)
162.158.159.193 - - [21/Aug/2026:14:34:09 +0200] "GET /wp-includes/css/wp-conflg.php HTTP/2.0" 404 3 ...
show more
162.158.159.193 - - [21/Aug/2026:14:34:09 +0200] "GET /wp-includes/css/wp-conflg.php HTTP/2.0" 404 357 "-" "-"
show less
Web App Attack
Brute-Force
πΊπΈ
mawan
2026-08-20 08:40:58
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
π§πͺ
madeit
2026-08-11 08:00:06
(1 month ago)
Web App Attack
π―π΅
S.O.B.A. Dev.
2026-07-30 03:29:08
(1 month ago)
Persistent port scanning or vulnerability scanning
Port Scan
π―π΅
S.O.B.A. Dev.
2026-07-26 13:11:26
(2 months ago)
Persistent port scanning or vulnerability scanning
Port Scan
π©πͺ
todix
2026-04-15 03:35:48
(5 months ago)
Web App Attack Exploid from 162.158.159.193
Web App Attack
π¨π¦
yukon.ca
2026-04-08 16:49:21
(5 months ago)
Web Server Enforcement Violation: Web Server Exposed Git Repository Information Disclosure
Port:80
Hacking
Exploited Host
πΊπΈ
TPI-Abuse
2026-03-21 06:04:28
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 02:04:21.872098 2026] [security2:error] [pid 5219:tid 5219] [client 162.158.159.193:14021] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.microbikinitop.com"] [uri "/www/.env"] [unique_id "ab405VsPfHno6qtUwMCUJAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 07:19:38
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 03:19:31.545744 2026] [security2:error] [pid 31510:tid 31510] [client 162.158.159.193:12652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.daisydoesoap.com"] [uri "/.env.php"] [unique_id "abz1A-Gz6FHUX0wuEDw4zAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 06:18:39
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 02:18:31.544003 2026] [security2:error] [pid 21245:tid 21245] [client 162.158.159.193:14233] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kittencream.com.mykelmilur.com"] [uri "/.env.docker"] [unique_id "abzmt72VMz4tdt8S4CJdEwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 05:07:05
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 01:07:00.576909 2026] [security2:error] [pid 2445523:tid 2445523] [client 162.158.159.193:11546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.register-yacht-dubai.com"] [uri "/private/.env"] [unique_id "abzV9DQRQ5oOmZfb_RxO_AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 02:56:29
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 22:56:23.466940 2026] [security2:error] [pid 11145:tid 11145] [client 162.158.159.193:11066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.backspaced.com"] [uri "/var/www/html/.env"] [unique_id "aby3V2wh7CKBDuQQIbzqvwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 00:12:31
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 20:12:25.706445 2026] [security2:error] [pid 25124:tid 25124] [client 162.158.159.193:13342] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "linnardfinancial.com"] [uri "/var/www/.env"] [unique_id "abyQ6ak3nLOjTPRCCsAh4gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack