πΊπΈ
mccsoft.io
2026-06-15 06:15:20
(7 hours ago)
Web application attack / vulnerability scanning against our public nginx web server (TCP 80/443). So ...
show more
Web application attack / vulnerability scanning against our public nginx web server (TCP 80/443). Source matched a blocked-path security rule (jail nginx-444); server returned HTTP 444 (connection closed without response). TCP three-way handshake completed (full HTTP request received).
show less
Bad Web Bot
Web App Attack
π·πΊ
DZBOT
2026-06-10 13:36:29
(4 days ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-09 03:49:35
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.183.79 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.183.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 23:49:30.196473 2026] [security2:error] [pid 12834:tid 12834] [client 162.158.183.79:10657] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "settummanque.net.scoutinsignia.com"] [uri "/.git/config"] [unique_id "aieNSv1q1CPL997sG7Oj1AAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-08 22:26:22
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.183.79 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.183.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 18:26:17.658371 2026] [security2:error] [pid 29808:tid 29808] [client 162.158.183.79:12865] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "movers.ink2wear.com"] [uri "/.git/config"] [unique_id "aidBidRKI_9ODbRjm-uRrQAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
sandra361
2026-05-28 06:54:01
(2 weeks ago)
Port scan detected: 19 attempts across 1 ports (443). | Evidence: REAPER_TARPIT:IN=enp1s0f0 OUT= SRC ...
show more
Port scan detected: 19 attempts across 1 ports (443). | Evidence: REAPER_TARPIT:IN=enp1s0f0 OUT= SRC=162.158.183.79 LEN=60 TOS=0x00 PREC=0x00 TTL=54 ID=17948 DF PROTO=TCP SPT=9289 DPT=443 WINDOW=65535 RES=0x00 SYN URGP=0
show less
Port Scan
πΊπΈ
mawan
2026-02-19 13:51:41
(3 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
πΊπ¦
URAN Publishing Service
2025-11-11 14:03:21
(7 months ago)
162.158.183.79 - - [11/Nov/2025:16:01:57 +0200] "GET /wp-includes/blocks/table/int/tmpl/index.php HT ...
show more
162.158.183.79 - - [11/Nov/2025:16:01:57 +0200] "GET /wp-includes/blocks/table/int/tmpl/index.php HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0"
162.158.183.79 - - [11/Nov/2025:16:03:20 +0200] "GET /wp-content/plugins/hello.php HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3"
...
show less
Web App Attack
Anonymous
2025-08-06 09:28:21
(10 months ago)
162.158.183.79 - - [06/Aug/2025:06:28:19 -0300] "GET /wordpress/wp-admin/setup-config.php HTTP/1.1" ...
show more
162.158.183.79 - - [06/Aug/2025:06:28:19 -0300] "GET /wordpress/wp-admin/setup-config.php HTTP/1.1" 404 47 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36"
...
show less
Web App Attack
Anonymous
2025-07-19 01:52:29
(10 months ago)
162.158.183.79 - - [18/Jul/2025:22:52:24 -0300] "GET /wp-admin/setup-config.php HTTP/1.1" 404 56 "-" ...
show more
162.158.183.79 - - [18/Jul/2025:22:52:24 -0300] "GET /wp-admin/setup-config.php HTTP/1.1" 404 56 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36"
...
show less
Web App Attack
π¨π
ALPHANET
2025-07-11 16:54:22
(11 months ago)
web exploits
Hacking
Exploited Host
Web App Attack
πΊπΈ
Heath Smith
2025-06-17 09:03:37
(11 months ago)
162.158.183.79 - - [17/Jun/2025:04:03:33 -0500] "GET /wp-includes/fonts/wp-login.php HTTP/1.1" 301 5 ...
show more
162.158.183.79 - - [17/Jun/2025:04:03:33 -0500] "GET /wp-includes/fonts/wp-login.php HTTP/1.1" 301 568 "-" "-"
162.158.183.79 - - [17/Jun/2025:04:03:35 -0500] "GET /wp-admin/images/wp-login.php HTTP/1.1" 301 564 "-" "-"
162.158.183.79 - - [17/Jun/2025:04:03:36 -0500] "GET /wp-includes/sitemaps/wp-login.php HTTP/1.1" 301 574 "-" "-"
...
show less
Brute-Force
π·πΊ
john butt
2025-04-26 00:42:15
(1 year ago)
SSH brute-force attack
Blog Spam
Brute-Force
π·πΊ
john butt
2025-04-24 00:33:44
(1 year ago)
Invalid user β brute-force or recon
FTP Brute-Force
Blog Spam
Anonymous
2025-04-13 08:48:08
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
πΊπΈ
TPI-Abuse
2025-03-18 06:23:07
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 162.158.183.79 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.183.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 18 02:20:35.698016 2025] [security2:error] [pid 784:tid 784] [client 162.158.183.79:33392] [client 162.158.183.79] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gibit.me"] [uri "/v1/.git/config"] [unique_id "Z9kQs2HnQb6EVX5XUr5N-wAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack