๐ฎ๐น
CoreTech srl
2026-08-09 08:56:01
(2 weeks ago)
CloudLinux/Plesk alert - host=cloudlinux5 dominio=membershipworld.com ip=162.158.172.165 richieste=1 ...
show more
CloudLinux/Plesk alert - host=cloudlinux5 dominio=membershipworld.com ip=162.158.172.165 richieste=104 rischio=ALTO score=13 motivi=molte_richieste,molte_uri_uniche,path_sospetti,poco_statico,dinamico cat_id=21,19 periodo=10min
show less
Web App Attack
Bad Web Bot
๐บ๐ฆ
URAN Publishing Service
2026-07-28 16:36:00
(4 weeks ago)
162.158.172.165 - - [28/Jul/2026:19:35:59 +0300] "GET /wp-admin/maint/ HTTP/1.1" 301 659 "-" "Mozill ...
show more
162.158.172.165 - - [28/Jul/2026:19:35:59 +0300] "GET /wp-admin/maint/ HTTP/1.1" 301 659 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
162.158.172.165 - - [28/Jul/2026:19:35:59 +0300] "GET /wp-admin/js/ HTTP/1.1" 301 652 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
ph
2026-05-27 13:49:01
(2 months ago)
Bad web bot attempting to run wp-admin on non-WP site
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-04-16 12:13:46
(4 months ago)
[Thu Apr 16 14:13:45.263714 2026] [authz_core:error] [pid 10455] [client 162.158.172.165:13135] AH01 ...
show more
[Thu Apr 16 14:13:45.263714 2026] [authz_core:error] [pid 10455] [client 162.158.172.165:13135] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu Apr 16 14:13:45.294183 2026] [authz_core:error] [pid 10455] [client 162.158.172.165:13135] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu Apr 16 14:13:45.325652 2026] [authz_core:error] [pid 10455] [client 162.158.172.165:13135] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐ง๐พ
lns.bz
2026-03-25 15:15:45
(5 months ago)
Too many 404 requests [BY]
Web App Attack
๐ง๐พ
lns.bz
2026-03-20 08:35:28
(5 months ago)
.env scanning [BY]
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-03-06 00:42:58
(5 months ago)
162.158.172.165 - - [06/Mar/2026:02:42:55 +0200] "GET /wp-content/themes/admin.php HTTP/1.1" 404 287 ...
show more
162.158.172.165 - - [06/Mar/2026:02:42:55 +0200] "GET /wp-content/themes/admin.php HTTP/1.1" 404 2870 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
162.158.172.165 - - [06/Mar/2026:02:42:57 +0200] "GET /wp-content/uploads/admin.php HTTP/1.1" 404 304 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ณ๐ฑ
mawan
2025-07-13 15:19:03
(1 year ago)
Suspected of having performed illicit activity on AMS server.
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-24 04:46:12
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 162.158.172.165 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.172.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 24 00:46:05.133654 2025] [security2:error] [pid 1136825:tid 1136825] [client 162.158.172.165:63772] [client 162.158.172.165] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ruralcommunitycare.org"] [uri "/.env.save"] [unique_id "aDFPDU5D1ahsQ1uBYMtvKQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2025-05-20 15:44:17
(1 year ago)
162.158.172.165 - - [20/May/2025:18:44:14 +0300] "GET /wp-admin/user/about.php HTTP/1.1" 404 196 "-" ...
show more
162.158.172.165 - - [20/May/2025:18:44:14 +0300] "GET /wp-admin/user/about.php HTTP/1.1" 404 196 "-" "-"
162.158.172.165 - - [20/May/2025:18:44:15 +0300] "GET /wp-admin/file.php HTTP/1.1" 404 196 "-" "-"
...
show less
Web App Attack
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-05-12 10:26:37
(1 year ago)
Port probe to tcp/80 (http)
[srv125]
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2025-04-27 07:51:37
(1 year ago)
162.158.172.165 - - [27/Apr/2025:10:51:36 +0300] "GET /wp-content/uploads/ao_ccss/ HTTP/1.1" 404 274 ...
show more
162.158.172.165 - - [27/Apr/2025:10:51:36 +0300] "GET /wp-content/uploads/ao_ccss/ HTTP/1.1" 404 274 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95"
162.158.172.165 - - [27/Apr/2025:10:51:36 +0300] "GET /wp-content/uploads/2021/ HTTP/1.1" 404 274 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
...
show less
Web App Attack
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-04-05 15:39:06
(1 year ago)
Port probe to tcp/443 (https)
[srv125]
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-03 02:59:44
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 162.158.172.165 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.172.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 02 22:59:40.109982 2025] [security2:error] [pid 32373:tid 32373] [client 162.158.172.165:62834] [client 162.158.172.165] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shivermedia.com"] [uri "/.env"] [unique_id "Z-35nPdd8pRFlMQFc-RY5AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-04-01 05:48:49
(1 year ago)
Port probe to tcp/443 (https)
[srv125]
Port Scan
Brute-Force
Bad Web Bot
Web App Attack