๐ฏ๐ต
S.O.B.A. Dev.
2026-09-20 13:55:36
(48 minutes ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐ณ๐ฑ
homeshowdomain.nl
2026-09-08 22:03:23
(1 week ago)
Auto-ban: >3000 req/min op 2026-09-08
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-07 03:03:27
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.158.162.136 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.162.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 23:03:13.703312 2026] [security2:error] [pid 28625:tid 28625] [client 162.158.162.136:10343] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dryprodrain.com"] [uri "/.git/config"] [unique_id "ap4pcUPNDScx4hN2q4tw7AAAAAY"], referer: https://www.google.com/search?q=dryprodrain.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 09:41:27
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.162.136 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.162.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 05:41:23.913604 2026] [security2:error] [pid 2028:tid 2028] [client 162.158.162.136:12846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.1derfulwaysrv.com"] [uri "/.git/HEAD"] [unique_id "aoLXQ87PB54fpOso9oyt6QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 05:30:30
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.162.136 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.162.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 01:30:21.208659 2026] [security2:error] [pid 28306:tid 28306] [client 162.158.162.136:11563] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.kontikimotorcycles.com"] [uri "/.git/HEAD"] [unique_id "aoKcbW7bEAgymLzdr3EpmAAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 23:55:08
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.162.136 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.162.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 19:55:02.823156 2026] [security2:error] [pid 23966:tid 23966] [client 162.158.162.136:10560] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gld.cmabiblequizzing.org"] [uri "/.git/HEAD"] [unique_id "aoJN1g1CuyWp-UsjetBtGwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-16 22:38:08
(1 month ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 08:16:27
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.162.136 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.162.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 04:16:21.895263 2026] [security2:error] [pid 20916:tid 20916] [client 162.158.162.136:11231] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.surf-sci-eng.com"] [uri "/.git/config"] [unique_id "aoFx1XHo1sEznXgkXT5ELQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-13 21:20:55
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.162.136 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.162.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 17:20:48.092358 2026] [security2:error] [pid 896937:tid 896937] [client 162.158.162.136:14039] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.chrismoratz.com"] [uri "/.git/HEAD"] [unique_id "an41MLMRWEXdI9onfqDRiAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-06 12:15:38
(1 month ago)
Web App Attack
๐บ๐ธ
mawan
2026-07-28 13:05:46
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
mawan
2026-07-21 07:46:52
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
Anonymous
2026-06-11 07:02:52
(3 months ago)
162.158.162.136 - - [11/Jun/2026:09:02:08 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 43 ...
show more
162.158.162.136 - - [11/Jun/2026:09:02:08 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 436 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
162.158.162.136 - - [11/Jun/2026:09:02:08 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 243 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
162.158.162.136 - - [11/Jun/2026:09:02:10 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 436 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
162.158.162.136 - - [11/Jun/2026:09:02:10 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 243 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
162.158.162.136 - - [11/Jun/2026:09:02:51 +0200] "GET //2019/wp-includes/wlwmanifest.xml HTTP/1.1"
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
abdubhai
2026-05-28 11:18:45
(3 months ago)
162.158.162.136 - - [28/May/2026
...
Brute-Force
๐ฉ๐ช
acadeova
2026-05-19 00:42:47
(4 months ago)
๐จ Recon detected (nft drop)
SRC=162.158.162.136
Observed=TCP dpt=80 in=enp0s6 ttl=56
Time=recent(jou ...
show more
๐จ Recon detected (nft drop)
SRC=162.158.162.136
Observed=TCP dpt=80 in=enp0s6 ttl=56
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan