๐บ๐ธ
TPI-Abuse
2026-05-16 09:44:44
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.158.6.48 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.6.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 05:44:41.162580 2026] [security2:error] [pid 1782:tid 1782] [client 162.158.6.48:13713] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pappakotis.net.pappakotis.com"] [uri "/sftp-config.json"] [unique_id "agg8icbsuLvqzpW-60BEOwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-16 09:25:26
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.158.6.48 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.6.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 05:25:17.494589 2026] [security2:error] [pid 10468:tid 10468] [client 162.158.6.48:14068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.dezdezero.com"] [uri "/.env.local"] [unique_id "agg3_caQ9AeN8XduwbubKQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-14 09:18:50
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.158.6.48 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.6.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 05:18:41.399059 2026] [security2:error] [pid 13408:tid 13408] [client 162.158.6.48:9684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.seacorre.com"] [uri "/.env"] [unique_id "agWTcQ-yeYuvUC_W-fC3dAAAAAw"], referer: https://www.google.com/search?q=webdisk.seacorre.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-13 22:01:29
(3 weeks ago)
Auto-ban: >3000 req/min op 2026-05-13
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-14 05:57:48
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.6.48 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.6.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 14 01:57:41.207784 2026] [security2:error] [pid 1705870:tid 1705870] [client 162.158.6.48:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.webuildbeaches.com"] [uri "/.git/config"] [unique_id "ad3XVa_vYY8V_chXcMU-VQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Campus France
2026-01-21 13:50:56
(4 months ago)
[Wed Jan 21 14:50:56.289435 2026] [php:error] [pid 2906624] [client 162.158.6.48:12361] script '/var ...
show more
[Wed Jan 21 14:50:56.289435 2026] [php:error] [pid 2906624] [client 162.158.6.48:12361] script '/var/www/html/info.php' not found or unable to stat
[Wed Jan 21 14:50:56.327456 2026] [php:error] [pid 2906624] [client 162.158.6.48:12361] script '/var/www/html/about.php' not found or unable to stat
[Wed Jan 21 14:50:56.403596 2026] [php:error] [pid 2906624] [client 162.158.6.48:12361] script '/var/www/html/ss1.php' not found or unable to stat
[Wed Jan 21 14:50:56.484507 2026] [php:error] [pid 2906624] [client 162.158.6.48:12361] script '/var/www/html/goods.php' not found or unable to stat
[Wed Jan 21 14:50:56.522780 2026] [php:error] [pid 2906624] [client 162.158.6.48:12361] script '/var/www/html/admin.php' not found or unable to stat
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
petardimic
2025-11-29 13:30:25
(6 months ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
Heath Smith
2025-09-06 18:46:20
(8 months ago)
162.158.6.48 - - [06/Sep/2025:13:46:14 -0500] "GET /wp-includes/fonts/wp-login.php HTTP/1.1" 404 673 ...
show more
162.158.6.48 - - [06/Sep/2025:13:46:14 -0500] "GET /wp-includes/fonts/wp-login.php HTTP/1.1" 404 673 "-" "-"
162.158.6.48 - - [06/Sep/2025:13:46:15 -0500] "GET /.wp-cli/wp-login.php HTTP/1.1" 404 673 "-" "-"
162.158.6.48 - - [06/Sep/2025:13:46:20 -0500] "GET /wp-includes/IXR/wp-login.php HTTP/1.1" 404 673 "-" "-"
...
show less
Brute-Force
Anonymous
2025-09-03 15:57:44
(9 months ago)
Web Probe / Attack
Web App Attack
๐ณ๐ฑ
mawan
2025-08-31 16:26:27
(9 months ago)
Suspected of having performed illicit activity on AMS server.
Web App Attack
๐บ๐ธ
Heath Smith
2025-08-30 15:35:18
(9 months ago)
162.158.6.48 - - [30/Aug/2025:10:34:23 -0500] "GET /xmlrpc.php HTTP/1.1" 404 673 "-" "-"
162.158.6.4 ...
show more
162.158.6.48 - - [30/Aug/2025:10:34:23 -0500] "GET /xmlrpc.php HTTP/1.1" 404 673 "-" "-"
162.158.6.48 - - [30/Aug/2025:10:34:25 -0500] "GET /wp-login.php HTTP/1.1" 404 673 "-" "-"
162.158.6.48 - - [30/Aug/2025:10:35:18 -0500] "GET /wp-admin/css/wp-login.php HTTP/1.1" 404 673 "-" "-"
...
show less
Brute-Force
๐ณ๐ฑ
mawan
2025-08-28 16:42:48
(9 months ago)
Suspected of having performed illicit activity on AMS server.
Web App Attack
๐บ๐ธ
Heath Smith
2025-08-25 22:44:01
(9 months ago)
162.158.6.48 - - [25/Aug/2025:17:43:57 -0500] "GET /wp-includes/ID3/wp-login.php HTTP/1.1" 404 673 " ...
show more
162.158.6.48 - - [25/Aug/2025:17:43:57 -0500] "GET /wp-includes/ID3/wp-login.php HTTP/1.1" 404 673 "-" "-"
162.158.6.48 - - [25/Aug/2025:17:43:59 -0500] "GET /wp-admin/user/wp-login.php HTTP/1.1" 404 673 "-" "-"
162.158.6.48 - - [25/Aug/2025:17:44:00 -0500] "GET /wp-includes/images/wp-login.php HTTP/1.1" 404 673 "-" "-"
...
show less
Brute-Force
๐บ๐ธ
Heath Smith
2025-08-20 18:38:42
(9 months ago)
162.158.6.48 - - [20/Aug/2025:13:38:30 -0500] "GET /wp-admin/images/wp-login.php HTTP/1.1" 301 614 " ...
show more
162.158.6.48 - - [20/Aug/2025:13:38:30 -0500] "GET /wp-admin/images/wp-login.php HTTP/1.1" 301 614 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36"
162.158.6.48 - - [20/Aug/2025:13:38:38 -0500] "GET /wp-includes/images/wp-login.php HTTP/1.1" 301 620 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.5735.199 Safari/537.36"
162.158.6.48 - - [20/Aug/2025:13:38:41 -0500] "GET /wp-content/languages/themes/wp-login.php HTTP/1.1" 301 638 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.2 Safari/605.1.15"
...
show less
Brute-Force
๐ณ๐ฑ
mawan
2025-08-20 12:51:05
(9 months ago)
Suspected of having performed illicit activity on AMS server.
Web App Attack