๐บ๐ธ
TPI-Abuse
2026-06-17 20:31:16
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.183.48 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.183.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 16:31:12.927218 2026] [security2:error] [pid 2197:tid 2197] [client 162.158.183.48:13935] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "old.renju.net"] [uri "/.git/config"] [unique_id "ajMEEEXyxgrYlxMy210g7gAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-12 19:35:51
(1 month ago)
(caddyscan) Scanner path probe from 162.158.183.48 (SE/Sweden/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 162.158.183.48 (SE/Sweden/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 162.158.183.48 - - [12/May/2026:19:32:31 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 162.158.183.48 - - [12/May/2026:19:33:06 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 162.158.183.48 - - [12/May/2026:19:34:59 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 162.158.183.48 - - [12/May/2026:19:35:12 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 162.158.183.48 - - [12/May/2026:19:35:44 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
๐ณ๐ฑ
homeshowdomain.nl
2026-01-19 22:59:44
(5 months ago)
Auto-ban: >3000 req/min op 2026-01-19
Hacking
Web App Attack
SSH
๐บ๐ธ
mnsf
2026-01-09 03:05:16
(5 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐บ๐ธ
octageeks.com
2025-12-23 05:07:05
(5 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐จ๐ญ
ALPHANET
2025-08-26 09:22:01
(9 months ago)
web exploits
Hacking
Exploited Host
Web App Attack
๐จ๐ญ
ALPHANET
2025-08-11 21:55:58
(10 months ago)
web exploits
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
kosada.com
2025-08-04 19:08:02
(10 months ago)
Web vulnerability probing
Web App Attack
Anonymous
2025-08-02 11:42:35
(10 months ago)
162.158.183.48 - - [02/Aug/2025:08:42:34 -0300] "GET /wp-admin/setup-config.php HTTP/1.1" 404 47 "-" ...
show more
162.158.183.48 - - [02/Aug/2025:08:42:34 -0300] "GET /wp-admin/setup-config.php HTTP/1.1" 404 47 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36"
...
show less
Web App Attack
Anonymous
2025-07-09 23:58:02
(11 months ago)
IP banned by Fail2Ban due to multiple malicious requests on Nginx
Brute-Force
Web App Attack
SSH
Anonymous
2025-07-08 16:42:15
(11 months ago)
162.158.183.48 - - [08/Jul/2025:13:42:13 -0300] "GET /wp-admin/setup-config.php HTTP/1.1" 404 56 "-" ...
show more
162.158.183.48 - - [08/Jul/2025:13:42:13 -0300] "GET /wp-admin/setup-config.php HTTP/1.1" 404 56 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36"
...
show less
Web App Attack
Anonymous
2025-06-29 16:08:24
(11 months ago)
162.158.183.48 - - [29/Jun/2025:13:08:22 -0300] "GET /wp-admin/setup-config.php HTTP/1.1" 404 56 "-" ...
show more
162.158.183.48 - - [29/Jun/2025:13:08:22 -0300] "GET /wp-admin/setup-config.php HTTP/1.1" 404 56 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ซ๐ฎ
oh.mg
2025-06-03 15:31:05
(1 year ago)
[Tue Jun 03 17:31:04.891508 2025] [security2:error] [pid 2085089:tid 2085106] [client 162.158.183.48 ...
show more
[Tue Jun 03 17:31:04.891508 2025] [security2:error] [pid 2085089:tid 2085106] [client 162.158.183.48:33060] [client 162.158.183.48] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "mailboxes.mrman.net"] [uri "/wetty/socket.io/"] [unique_id "aD8VOFk6SJ4Db_jn7Bu2uQAAAE8"], referer: https://mailboxes.mrman.net/wetty/
[Tue Jun 03 17:31:04.952918 2025] [security2:error] [pid 2085089:tid 2085099] [client 162.158.183.48:33060] [client 162.158.183.48] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Sc
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ฎ
oh.mg
2025-06-03 13:24:01
(1 year ago)
[Tue Jun 03 15:24:01.160562 2025] [security2:error] [pid 2261306:tid 2261309] [client 162.158.183.48 ...
show more
[Tue Jun 03 15:24:01.160562 2025] [security2:error] [pid 2261306:tid 2261309] [client 162.158.183.48:39240] [client 162.158.183.48] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "mailboxes.mrman.net"] [uri "/wetty/socket.io/"] [unique_id "aD73cS_PGCgp1r0PQBm4CwAAAME"], referer: https://mailboxes.mrman.net/wetty/
[Tue Jun 03 15:24:01.256476 2025] [security2:error] [pid 2261306:tid 2261324] [client 162.158.183.48:39240] [client 162.158.183.48] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Sc
...
show less
Bad Web Bot
Web App Attack
Anonymous
2025-05-04 13:08:20
(1 year ago)
IP banned by Fail2Ban due to multiple malicious requests on Nginx
Brute-Force
Web App Attack
SSH