๐บ๐ธ
xxkodedxx
2026-07-11 02:17:02
(1 week ago)
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1ร honeypot-get in 10m window.
...
show more
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1ร honeypot-get in 10m window.
Active: 02:16:08 UTC
Volume: 2 honeypot probe(s)
Bait taken: /wp-login.php, /wp-admin/install.php?step=1
UA: "http://zvxlabs.com/wp-admin/install.php?step=1"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
Anonymous
2026-07-04 12:29:18
(2 weeks ago)
162.158.182.149 - - [04/Jul/2026:14:29:08 +0200] "GET /google-credentials.json HTTP/1.1" 403 183 "-" ...
show more
162.158.182.149 - - [04/Jul/2026:14:29:08 +0200] "GET /google-credentials.json HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.2987.133 Safari/537.36"
162.158.182.149 - - [04/Jul/2026:14:29:08 +0200] "GET /cloud.json HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.90 Safari/537.36"
162.158.182.149 - - [04/Jul/2026:14:29:08 +0200] "GET /api/aws.json HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.100 Safari/537.36"
162.158.182.149 - - [04/Jul/2026:14:29:09 +0200] "GET /application.properties HTTP/1.1" 404 184 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2876.0 Safari/537.36"
162.158.182.149 - - [04/Jul/2026:14:29:09 +0200] "GET /api/database.yml HTTP/1.1" 403 567 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows CE; IEMobile
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-02 13:52:21
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.158.182.149 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.182.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 09:52:17.528381 2026] [security2:error] [pid 4216:tid 4216] [client 162.158.182.149:11013] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pointillistic.com"] [uri "/.git/config"] [unique_id "akZtEfJOU06Rs0EnntuH9QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-02 04:03:54
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.158.182.149 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.182.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 00:03:51.629711 2026] [security2:error] [pid 12977:tid 12998] [client 162.158.182.149:14146] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "scribblism.com"] [uri "/.git/config"] [unique_id "akXjJy5EVZrRWIg8zkLQHQAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-15 05:05:07
(1 month ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐ซ๐ฎ
inlink.ltd
2026-06-11 07:22:09
(1 month ago)
Known malicious PHP file or CMS probe
Web App Attack
๐บ๐ธ
mnsf
2026-06-06 20:05:24
(1 month ago)
Too many Status 50X (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-25 09:00:51
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.182.149 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.182.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 25 05:00:46.883910 2026] [security2:error] [pid 9900:tid 9900] [client 162.158.182.149:13672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "armandselmwoodpark.com"] [uri "/.git/config"] [unique_id "ahQPvuzoBRF8zD0Cget0jwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-23 10:06:05
(1 month ago)
Trying to access config files
Web App Attack
๐จ๐ญ
backslash
2026-05-23 05:18:03
(1 month ago)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-21 01:41:27
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.182.149 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.182.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 21:41:24.478946 2026] [security2:error] [pid 25310:tid 25310] [client 162.158.182.149:14244] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "integrabroadcast.com"] [uri "/.env.local"] [unique_id "ag5ixABelllwlfgFrApLUAAAAAk"], referer: https://www.google.com/search?q=integrabroadcast.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-16 00:30:30
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.182.149 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.182.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 20:30:23.848520 2026] [security2:error] [pid 15902:tid 15902] [client 162.158.182.149:10323] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pandahh.com"] [uri "/.env.save"] [unique_id "age6n6_EToCk13AzN6mlYwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-12 19:38:05
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.182.149 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.182.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 15:38:00.112093 2026] [security2:error] [pid 28504:tid 28525] [client 162.158.182.149:13092] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wealthmanagementcommission.com.aafm.us"] [uri "/.git/config"] [unique_id "agOBmMZVhB7s20yhjQEDJAAAARM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
oncord
2026-04-12 12:35:36
(3 months ago)
Form spam
Web Spam
๐ฉ๐ช
eishoof
2026-03-27 17:00:00
(3 months ago)
162.158.182.149 - - [27/Mar/2026:13:54:17 +0100] "GET /bless5.php HTTP/1.1" 404 236
162.158.182.149 ...
show more
162.158.182.149 - - [27/Mar/2026:13:54:17 +0100] "GET /bless5.php HTTP/1.1" 404 236
162.158.182.149 - - [27/Mar/2026:13:54:17 +0100] "GET /wp-act.php HTTP/1.1" 404 236
162.158.182.149 - - [27/Mar/2026:13:54:17 +0100] "GET /xqq.php HTTP/1.1" 404 236
...
show less
Port Scan
Brute-Force
Web App Attack