๐ท๐บ
DZBOT
2026-07-28 16:53:48
(2 days ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-11 08:21:02
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.158.182.170 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.182.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 11 04:20:56.599817 2026] [security2:error] [pid 4196:tid 4196] [client 162.158.182.170:12769] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sarahgrammer.austingrammer.com"] [uri "/.git/HEAD"] [unique_id "alH86OAdJO4jXxVSzIBemQAAAAE"], referer: https://www.google.com/search?q=www.sarahgrammer.austingrammer.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-07-04 02:46:33
(3 weeks ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ง๐ช
voormedia
2026-06-19 02:10:54
(1 month ago)
Accessed trap at '/.git/config'
Web App Attack
๐ท๐บ
DZBOT
2026-06-05 14:18:49
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
Anonymous
2026-05-14 16:37:22
(2 months ago)
Probing for known exploit paths (.env, .git, wp-admin, shell files, etc.). Single-strike ban policy ...
show more
Probing for known exploit paths (.env, .git, wp-admin, shell files, etc.). Single-strike ban policy โ zero tolerance for exploit scanning. Banned May 14, 16:37 UTC. Origin: Sweden, Stockholm.
show less
Hacking
Bad Web Bot
Web App Attack
๐ท๐ด
ReporTR
2026-02-11 23:27:10
(5 months ago)
Repeated malicious activity detected by Fail2Ban jail 'plesk-panel'. TCP connection completed. IP ba ...
show more
Repeated malicious activity detected by Fail2Ban jail 'plesk-panel'. TCP connection completed. IP banned.
show less
Hacking
๐ฉ๐ช
hbrks
2025-09-14 11:24:46
(10 months ago)
1 attack(s) detected since 2025-09-14T11:11:35.440Z, such as these: {"event":"nginx_block","ip":"162 ...
show more
1 attack(s) detected since 2025-09-14T11:11:35.440Z, such as these: {"event":"nginx_block","ip":"162.158.182.170","host":"intellicis.art","request":"GET /wp-admin/setup-config.php HTTP/1.1","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36","reason":"service:unknow","timestamp":"2025-09-14T11:11:35 00:00","logentry":"intellicis.art 162.158.182.170 - - [14/Sep/2025:11:11:35 0000] \"GET /wp-admin/setup-config.php HTTP/1.1\" 444 0 \"-\" \"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36\" \"-\" \"matched:service:unknow\""} Report Details: https://p4u.xyz/SNFPOX55U3Y/1IP Details: https://p4u.xyz/SNFPOX55U3Y/2
show less
Web Spam
Hacking
Bad Web Bot
๐จ๐ญ
ALPHANET
2025-09-08 15:52:47
(10 months ago)
web exploits
Hacking
Exploited Host
Web App Attack
๐ฎ๐ช
eyesilyurt
2025-08-31 06:30:36
(10 months ago)
p- login authenticator failed Incorrect authentication data
Brute-Force
SSH
๐จ๐ณ
ThreatBook.io
2025-07-05 00:13:41
(1 year ago)
2025-07-04 03:46:16 /wp-admin/setup-config.php
Web App Attack
๐บ๐ธ
Heath Smith
2025-06-17 01:37:23
(1 year ago)
162.158.182.170 - - [16/Jun/2025:20:34:39 -0500] "GET /wp-content/upgrade-temp-backup/wp-login.php H ...
show more
162.158.182.170 - - [16/Jun/2025:20:34:39 -0500] "GET /wp-content/upgrade-temp-backup/wp-login.php HTTP/1.1" 301 594 "-" "-"
162.158.182.170 - - [16/Jun/2025:20:36:41 -0500] "GET /wp-includes/Text/Diff/Engine/wp-login.php HTTP/1.1" 301 590 "-" "-"
162.158.182.170 - - [16/Jun/2025:20:37:23 -0500] "GET /xmlrpc.php HTTP/1.1" 301 528 "-" "-"
...
show less
Brute-Force
๐ซ๐ฎ
oh.mg
2025-06-03 15:33:28
(1 year ago)
[Tue Jun 03 17:33:28.439170 2025] [security2:error] [pid 2085089:tid 2085098] [client 162.158.182.17 ...
show more
[Tue Jun 03 17:33:28.439170 2025] [security2:error] [pid 2085089:tid 2085098] [client 162.158.182.170:36190] [client 162.158.182.170] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "mailboxes.mrman.net"] [uri "/wetty/socket.io/"] [unique_id "aD8VyFk6SJ4Db_jn7Bu3vwAAAEc"], referer: https://mailboxes.mrman.net/wetty/
[Tue Jun 03 17:33:28.500902 2025] [security2:error] [pid 2085089:tid 2085098] [client 162.158.182.170:36190] [client 162.158.182.170] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomal
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ฎ
oh.mg
2025-06-03 14:14:43
(1 year ago)
[Tue Jun 03 16:14:41.847739 2025] [security2:error] [pid 2261306:tid 2261327] [client 162.158.182.17 ...
show more
[Tue Jun 03 16:14:41.847739 2025] [security2:error] [pid 2261306:tid 2261327] [client 162.158.182.170:65496] [client 162.158.182.170] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "mailboxes.mrman.net"] [uri "/wetty/socket.io/"] [unique_id "aD8DUS_PGCgp1r0PQBnC4QAAANM"], referer: https://mailboxes.mrman.net/wetty/
[Tue Jun 03 16:14:41.913056 2025] [security2:error] [pid 2261306:tid 2261325] [client 162.158.182.170:65496] [client 162.158.182.170] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomal
...
show less
Bad Web Bot
Web App Attack
Anonymous
2025-05-11 03:46:40
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH