๐บ๐ธ
TPI-Abuse
2026-03-21 01:40:55
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.62.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.62.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 21:40:51.920217 2026] [security2:error] [pid 30945:tid 30945] [client 162.158.62.65:13261] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "portraitsinblues.com"] [uri "/.env.local"] [unique_id "ab33I5jud4QSx27lyQO-qgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 00:29:12
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.62.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.62.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 20:29:05.274591 2026] [security2:error] [pid 18731:tid 18731] [client 162.158.62.65:12988] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dominionfinancialadvisors.com"] [uri "/private/.env"] [unique_id "ab3mUWwiD12uO8ymyJMDTgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 09:13:56
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.62.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.62.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 05:13:51.852947 2026] [security2:error] [pid 28120:tid 28120] [client 162.158.62.65:12960] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.marklex.com"] [uri "/.env.tmp"] [unique_id "ab0Pz3Adz0XEmGGJygpFBgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 04:06:31
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.62.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.62.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 00:06:23.768411 2026] [security2:error] [pid 28975:tid 28975] [client 162.158.62.65:11430] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.gkwire.com"] [uri "/.env.old"] [unique_id "abzHv91uVlEytsrai54WZgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 03:06:21
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.62.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.62.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 23:06:15.797138 2026] [security2:error] [pid 2522:tid 2522] [client 162.158.62.65:9897] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.anneoday.com"] [uri "/home/.env"] [unique_id "aby5p6BVKkzx84jbXpBmgQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 10:52:53
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.62.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.62.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 06:52:48.326595 2026] [security2:error] [pid 22375:tid 22375] [client 162.158.62.65:13118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "akmanoto.com"] [uri "/.env.production.bak"] [unique_id "abvVgKUBSIFbbSKpjiytxgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 10:24:38
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.62.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.62.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 06:24:35.681946 2026] [security2:error] [pid 11071:tid 11071] [client 162.158.62.65:11463] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.juca.com.mx"] [uri "/.env.production.local"] [unique_id "abvO44y3RPKv5EhPWkmSpgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 09:59:25
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.62.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.62.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 05:59:18.280010 2026] [security2:error] [pid 23252:tid 23357] [client 162.158.62.65:11014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "buyused-jomega.jomega.org"] [uri "/.env.dev"] [unique_id "abvI9pldqWOIHO4ryT8UtgAAAIE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 08:14:18
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.62.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.62.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 04:14:10.408229 2026] [security2:error] [pid 10193:tid 10193] [client 162.158.62.65:13750] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ingberinteriors.com"] [uri "/.env.staging"] [unique_id "abuwUglCHmaPY-NmCJmoJAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-18 16:40:06
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.62.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.62.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 18 12:39:57.448654 2026] [security2:error] [pid 2809:tid 2809] [client 162.158.62.65:10522] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.runnercomics.com"] [uri "/backend/.env"] [unique_id "abrVXY1VyfYxpKs-oFUJcwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-18 16:23:11
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.62.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.62.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 18 12:23:00.829236 2026] [security2:error] [pid 13029:tid 13029] [client 162.158.62.65:12283] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nauticalchristmascards.com"] [uri "/.env.development.local"] [unique_id "abrRZK01d5ZigXkGveh-TAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Sรฉfora Srl
2026-01-21 20:00:11
(8 months ago)
Failed attempt detected by Fail2Ban in plesk-wordpress jail
Web App Attack
๐บ๐ธ
mawan
2026-01-12 12:34:33
(8 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
thefoofighter
2026-01-04 09:58:20
(9 months ago)
[Sun Jan 04 09:58:14.976555 2026] [:error] [pid 1500185] [client 162.158.62.65:14241] [client 162.15 ...
show more
[Sun Jan 04 09:58:14.976555 2026] [:error] [pid 1500185] [client 162.158.62.65:14241] [client 162.158.62.65] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "93"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 8)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.cathalmcnally.com"] [uri "/cedsffes/mviewer.php"] [unique_id "aVo5turmetxu43L-gqOFbQAAAAU"]
[Sun Jan 04 09:58:20.513603 2026] [:error] [pid 1499975] [client 162.158.62.65:10861] [client 162.158.62.65] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "93"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 8)"] [severity "CRITICAL"]
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
abdubhai
2025-12-03 11:16:26
(10 months ago)
162.158.62.65 - - [03/Dec/2025:1
...
Brute-Force