๐บ๐ธ
TPI-Abuse
2026-09-06 07:28:26
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 162.158.38.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.38.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 03:28:23.151313 2026] [security2:error] [pid 26739:tid 26739] [client 162.158.38.80:12255] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "susansambou.org"] [uri "/.env"] [unique_id "ap0WF-v_U4lP-NdzRXbJ9QAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 00:02:46
(1 day ago)
(caddyscan) Scanner path probe from 162.158.38.80 (IE/Ireland/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 162.158.38.80 (IE/Ireland/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 0 162.158.38.80 - - [05/Sep/2026:00:02:40 +0000] "HEAD /.git/HEAD HTTP/1.1"
[REDACTED] 200 0 162.158.38.80 - - [05/Sep/2026:00:02:40 +0000] "HEAD /.env HTTP/1.1"
[REDACTED] 200 2627 162.158.38.80 - - [05/Sep/2026:00:02:43 +0000] "GET /.aws/credentials HTTP/1.1"
[REDACTED] 200 2627 162.158.38.80 - - [05/Sep/2026:00:02:43 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 162.158.38.80 - - [05/Sep/2026:00:02:43 +0000] "GET /.git/HEAD HTTP/1.1"
show less
Port Scan
๐ฉ๐ช
pltcldvlpr
2026-09-04 06:06:58
(2 days ago)
CMS/framework probe: 162.158.38.80 - - [04/Sep/2026:08:06:57 +0200] "GET /.env.backup HTTP/2.0" 301 ...
show more
CMS/framework probe: 162.158.38.80 - - [04/Sep/2026:08:06:57 +0200] "GET /.env.backup HTTP/2.0" 301 178 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.4 Safari/605.1.15" asn=13335 org="Cloudflare, Inc." country=IE
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 15:05:21
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.38.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.38.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 11:05:15.396938 2026] [security2:error] [pid 8794:tid 8794] [client 162.158.38.80:9569] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "linneus.com"] [uri "/.env.test"] [unique_id "apmMqx_nSIXIoGnno-w_pAAAAAc"], referer: https://www.google.com/search?q=linneus.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-13 16:05:16
(2 months ago)
Abuse Detected (11)
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-13 22:04:05
(3 months ago)
Auto-ban: >3000 req/min op 2026-05-13
Web App Attack
SSH
Hacking
๐ฉ๐ช
big-cloud.nl
2026-05-13 21:01:54
(3 months ago)
Try to access /.git/config
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-13 11:48:17
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.38.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.38.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 07:48:09.298891 2026] [security2:error] [pid 23605:tid 23605] [client 162.158.38.80:11588] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.stoneybluff.com"] [uri "/.env.development"] [unique_id "agRk-VB9hg1QohgNhW_KeAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-13 09:05:32
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.38.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.38.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 05:05:29.127300 2026] [security2:error] [pid 1608:tid 1608] [client 162.158.38.80:13601] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.adorbespokehomes.com.globalsolutions.technology"] [uri "/sftp-config.json"] [unique_id "agQ-2ZaeEEQH0LkEgfbUrAAAACA"], referer: https://www.google.com/search?q=www.adorbespokehomes.com.globalsolutions.technology
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-04-23 11:05:28
(4 months ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-04-12 11:05:09
(4 months ago)
Too many Status 40X (12)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-04-05 02:05:13
(5 months ago)
Too many Status 40X (13)
Brute-Force
Web App Attack
๐ฉ๐ช
Blexyel
2026-04-03 15:49:01
(5 months ago)
162.158.38.80 - - [03/Apr/2026:17:49:00 +0200] "GET /wp-includes/theme-compat/wp-login.php HTTP/1.1" ...
show more
162.158.38.80 - - [03/Apr/2026:17:49:00 +0200] "GET /wp-includes/theme-compat/wp-login.php HTTP/1.1" 404 153 "-" "-" "136.243.2.38"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-03-31 01:05:18
(5 months ago)
Too many Status 40X (12)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-03-03 11:05:10
(6 months ago)
Too many Status 40X (14)
Brute-Force
Web App Attack