๐บ๐ธ
mnsf
2026-04-05 00:05:46
(2 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐ณ๐ฑ
wolfemium
2026-03-28 23:15:46
(2 months ago)
162.158.159.62 - - [29/Mar/2026:01:15:43 +0200] "GET /56c53.php HTTP/1.1" 502 150 "-" "-"
162.158.15 ...
show more
162.158.159.62 - - [29/Mar/2026:01:15:43 +0200] "GET /56c53.php HTTP/1.1" 502 150 "-" "-"
162.158.159.62 - - [29/Mar/2026:01:15:43 +0200] "GET /bo.php HTTP/1.1" 502 150 "-" "-"
162.158.159.62 - - [29/Mar/2026:01:15:43 +0200] "GET /5b9ac.php HTTP/1.1" 502 150 "-" "-"
162.158.159.62 - - [29/Mar/2026:01:15:44 +0200] "GET /bolt.php HTTP/1.1" 502 150 "-" "-"
162.158.159.62 - - [29/Mar/2026:01:15:45 +0200] "GET /hplfuns.php HTTP/1.1" 502 150 "-" "-"
162.158.159.62 - - [29/Mar/2026:01:15:46 +0200] "GET /install.php HTTP/1.1" 502 150 "-" "-"
...
show less
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 00:28:22
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.62 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.62 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 20:28:15.141683 2026] [security2:error] [pid 14510:tid 14510] [client 162.158.159.62:11044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.tradersworldmarket.com"] [uri "/.env.development"] [unique_id "ab3mH6bhnK0Q8CXGEZ7D8gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 07:35:13
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.62 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.62 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 03:35:07.293645 2026] [security2:error] [pid 22653:tid 22653] [client 162.158.159.62:9722] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mlsdirect.xyz"] [uri "/.env.docker"] [unique_id "abz4q6iFh1YKIYDIZi3MOAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 06:18:37
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.62 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.62 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 02:18:31.119152 2026] [security2:error] [pid 7559:tid 7559] [client 162.158.159.62:12238] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.oxford-gliding-club.co.uk"] [uri "/var/www/.env"] [unique_id "abzmt5x3uVwkVOH_-w_xhQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 02:49:04
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.62 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.62 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 22:48:51.786158 2026] [security2:error] [pid 6927:tid 6927] [client 162.158.159.62:12782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.zost.net"] [uri "/.env.save"] [unique_id "aby1k_r9QhITxNk-XTyJ7AAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 02:06:34
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.62 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.62 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 22:06:28.613847 2026] [security2:error] [pid 9413:tid 9413] [client 162.158.159.62:9695] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "realtorpaul.com"] [uri "/.env.example"] [unique_id "abyrpJfMK7N9SqtaMoNjugAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 00:29:51
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.62 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.62 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 20:29:47.761854 2026] [security2:error] [pid 22803:tid 22803] [client 162.158.159.62:12501] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.frenosilent.net.ar"] [uri "/.env.local.backup"] [unique_id "abyU-9EURKVi1zxxV-M4LQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 11:30:39
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.62 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.62 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:30:32.150453 2026] [security2:error] [pid 8170:tid 8170] [client 162.158.159.62:10763] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.peakagronomysolutions.com"] [uri "/srv/.env"] [unique_id "abveWIt3vHufVPzzn5lhnQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 09:45:53
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.62 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.62 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 05:45:47.618620 2026] [security2:error] [pid 21102:tid 21102] [client 162.158.159.62:13787] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.laurengardner.org"] [uri "/core/.env"] [unique_id "abvFy8Dyle7dlnZTBzjKTQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 09:26:22
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.62 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.62 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 05:26:16.389169 2026] [security2:error] [pid 1209:tid 1209] [client 162.158.159.62:11455] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.kalvannastudios.com"] [uri "/.env.staging"] [unique_id "abvBOMT_aRqDKPo5ltT_UAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 09:08:15
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.62 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.62 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 05:08:08.089700 2026] [security2:error] [pid 23696:tid 23696] [client 162.158.159.62:13631] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.clearlightcarwash.com"] [uri "/admin/.env"] [unique_id "abu8-G5aTJSgMdnUFsAI5QAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 08:46:03
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.62 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.62 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 04:45:55.673919 2026] [security2:error] [pid 26864:tid 26864] [client 162.158.159.62:11302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.jpfamilyllc.com"] [uri "/.env.tmp"] [unique_id "abu3w1fEZcxUb7bxm8C11QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 08:16:21
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.62 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.62 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 04:16:16.758712 2026] [security2:error] [pid 5233:tid 5233] [client 162.158.159.62:11546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.cdromline.com"] [uri "/.env.test"] [unique_id "abuw0F5NNeUgVB_d4tdhBwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 07:51:19
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.62 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.62 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 03:51:13.366368 2026] [security2:error] [pid 8797:tid 8900] [client 162.158.159.62:12550] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.kd9uri.com"] [uri "/.env.json"] [unique_id "abuq8Qr2c6M_BsIUbwGpyQAAAIU"]
show less
Brute-Force
Bad Web Bot
Web App Attack