๐ฉ๐ช
DEV-DNS
2026-07-29 01:06:48
(13 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
Anonymous
2026-05-21 04:52:29
(2 months ago)
(caddyscan) Scanner path probe from 162.158.238.201 (FI/Finland/-): 5 in the last 3600 secs; Ports: ...
show more
(caddyscan) Scanner path probe from 162.158.238.201 (FI/Finland/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 162.158.238.201 - - [21/May/2026:04:05:53 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 162.158.238.201 - - [21/May/2026:04:07:04 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 162.158.238.201 - - [21/May/2026:04:49:14 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 162.158.238.201 - - [21/May/2026:04:52:18 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 162.158.238.201 - - [21/May/2026:04:52:22 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-21 02:45:55
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.238.201 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.238.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 22:45:48.602449 2026] [security2:error] [pid 29294:tid 29294] [client 162.158.238.201:13086] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mikekornrich.com"] [uri "/.git/config"] [unique_id "ag5x3K0OCQ9Pjhx2i6QkEAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 06:53:41
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.238.201 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.238.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 02:53:34.202464 2026] [security2:error] [pid 25906:tid 25948] [client 162.158.238.201:9576] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bmx3.de"] [uri "/.git/config"] [unique_id "ag1abuNTzi16nPR0e8B2FwAAAMM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-17 22:06:12
(2 months ago)
Auto-ban: >3000 req/min op 2026-05-17
Web App Attack
SSH
Hacking
Anonymous
2026-05-14 04:42:36
(2 months ago)
(caddyscan) Scanner path probe from 162.158.238.201 (FI/Finland/-): 5 in the last 3600 secs; Ports: ...
show more
(caddyscan) Scanner path probe from 162.158.238.201 (FI/Finland/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 162.158.238.201 - - [14/May/2026:03:51:07 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 162.158.238.201 - - [14/May/2026:04:12:41 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 162.158.238.201 - - [14/May/2026:04:24:23 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 162.158.238.201 - - [14/May/2026:04:24:23 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 162.158.238.201 - - [14/May/2026:04:42:31 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
Anonymous
2026-05-14 02:52:15
(2 months ago)
(caddyscan) Scanner path probe from 162.158.238.201 (FI/Finland/-): 5 in the last 3600 secs; Ports: ...
show more
(caddyscan) Scanner path probe from 162.158.238.201 (FI/Finland/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 162.158.238.201 - - [14/May/2026:02:11:53 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 162.158.238.201 - - [14/May/2026:02:29:31 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 162.158.238.201 - - [14/May/2026:02:50:22 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 162.158.238.201 - - [14/May/2026:02:50:29 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 162.158.238.201 - - [14/May/2026:02:52:13 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
Anonymous
2026-03-29 16:05:37
(3 months ago)
invalid request
Bad Web Bot
Web App Attack
๐ฉ๐ช
acadeova
2026-02-18 13:19:31
(5 months ago)
๐จ Recon detected (nft drop)
SRC=162.158.238.201
Observed=TCP dpt=80 in=enp0s6 ttl=56
Time=recent(jou ...
show more
๐จ Recon detected (nft drop)
SRC=162.158.238.201
Observed=TCP dpt=80 in=enp0s6 ttl=56
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
Anonymous
2025-11-19 04:30:49
(8 months ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
Anonymous
2025-05-24 22:15:58
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-04-27 05:33:38
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-04-21 05:14:10
(1 year ago)
[Mon Apr 21 07:14:06.538415 2025] [authz_core:error] [pid 18379] [client 162.158.238.201:64216] AH01 ...
show more
[Mon Apr 21 07:14:06.538415 2025] [authz_core:error] [pid 18379] [client 162.158.238.201:64216] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon Apr 21 07:14:10.395013 2025] [authz_core:error] [pid 26186] [client 162.158.238.201:51154] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon Apr 21 07:14:10.334420 2025] [authz_core:error] [pid 18379] [client 162.158.238.201:64216] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
Anonymous
2025-04-18 05:16:49
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-02-20 09:35:16
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 162.158.238.201 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.238.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 20 04:35:04.161608 2025] [security2:error] [pid 13034:tid 13034] [client 162.158.238.201:27260] [client 162.158.238.201] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shubil.com"] [uri "/flock/.git/config"] [unique_id "Z7b3SIN4TALFv_vu8uuXfAAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack