๐ต๐ฑ
IROK
2026-03-30 20:30:06
(2 months ago)
Malware/WebShell Scan blocked by ModSecurity
...
Hacking
๐บ๐ธ
TPI-Abuse
2026-03-22 00:31:42
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.62.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.62.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 20:31:36.835607 2026] [security2:error] [pid 21469:tid 21469] [client 162.158.62.221:13961] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.briannalls.com"] [uri "/srv/.env"] [unique_id "ab84aNlT5ZWs48hkID6xPQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 08:34:10
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.62.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.62.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 04:33:59.735085 2026] [security2:error] [pid 16232:tid 16232] [client 162.158.62.221:11861] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.celltechs.net"] [uri "/.env.dev.local"] [unique_id "ab0Gd4DServqAfJnw43GWAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 07:47:59
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.62.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.62.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 03:47:48.634955 2026] [security2:error] [pid 2071:tid 2071] [client 162.158.62.221:11750] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.enlightened-workplace.com"] [uri "/.env.development.local"] [unique_id "abz7pNmlHRlFrSgrA1KNPgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 11:49:50
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.62.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.62.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:49:40.845224 2026] [security2:error] [pid 12133:tid 12133] [client 162.158.62.221:14232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kathyquan.com"] [uri "/config/.env"] [unique_id "abvi1FczLkrGwnU8iIcE8wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 04:15:20
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.62.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.62.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 00:15:02.201419 2026] [security2:error] [pid 20875:tid 20875] [client 162.158.62.221:11349] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.reservations.passy.us"] [uri "/.env.old"] [unique_id "abt4RhAvSRO31wjWNXgN2QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-18 18:54:12
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.62.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.62.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 18 14:53:54.213776 2026] [security2:error] [pid 2954:tid 2954] [client 162.158.62.221:9350] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.stationrestaurant.ca"] [uri "/core/.env"] [unique_id "abr0wtZb0luAZQrQSw05AwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-18 16:29:26
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.62.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.62.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 18 12:29:21.922057 2026] [security2:error] [pid 32649:tid 32667] [client 162.158.62.221:11899] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rosendalsateri.com"] [uri "/.env.dev"] [unique_id "abrS4Qg0z40A7UiOli2swQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-18 14:53:46
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.62.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.62.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 18 10:53:42.248001 2026] [security2:error] [pid 32079:tid 32102] [client 162.158.62.221:11177] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "certifiedfinancialmanager.aafm.us"] [uri "/.env.save"] [unique_id "abq8dkhfjWhKpfrF0re_qAAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-18 14:31:43
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.62.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.62.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 18 10:31:30.390383 2026] [security2:error] [pid 21727:tid 21727] [client 162.158.62.221:13455] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "appliedcam.com"] [uri "/.env.production.local"] [unique_id "abq3QsD748lvsxVHTHpCBwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-14 08:47:37
(6 months ago)
[Fri Nov 14 09:47:36.677983 2025] [authz_core:error] [pid 13761] [client 162.158.62.221:13787] AH016 ...
show more
[Fri Nov 14 09:47:36.677983 2025] [authz_core:error] [pid 13761] [client 162.158.62.221:13787] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri Nov 14 09:47:37.002760 2025] [authz_core:error] [pid 13761] [client 162.158.62.221:13787] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri Nov 14 09:47:37.324346 2025] [authz_core:error] [pid 13761] [client 162.158.62.221:13787] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2025-10-11 04:21:02
(7 months ago)
162.158.62.221 - - [11/Oct/2025:07:21:00 +0300] "GET /wp-content/themes/aahana/json.php HTTP/1.1" 40 ...
show more
162.158.62.221 - - [11/Oct/2025:07:21:00 +0300] "GET /wp-content/themes/aahana/json.php HTTP/1.1" 404 196 "-" "-"
162.158.62.221 - - [11/Oct/2025:07:21:01 +0300] "GET /wp-admin/js/about.php HTTP/1.1" 404 196 "-" "-"
...
show less
Web App Attack
Anonymous
2025-10-09 15:49:56
(7 months ago)
[Thu Oct 09 17:49:55.659038 2025] [authz_core:error] [pid 22115] [client 162.158.62.221:62774] AH016 ...
show more
[Thu Oct 09 17:49:55.659038 2025] [authz_core:error] [pid 22115] [client 162.158.62.221:62774] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu Oct 09 17:49:55.895866 2025] [authz_core:error] [pid 22115] [client 162.158.62.221:62774] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu Oct 09 17:49:56.140839 2025] [authz_core:error] [pid 22115] [client 162.158.62.221:62774] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐บ๐ธ
octageeks.com
2025-09-23 04:07:41
(8 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack
Anonymous
2025-07-24 22:36:35
(10 months ago)
Fail2Ban apache-noscript
Bad Web Bot