๐บ๐ธ
mawan
2026-06-17 19:52:05
(10 hours ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ง๐ท
maviei
2026-06-11 11:44:07
(6 days ago)
2026-06-11T08:44:04.461605-03:00 srv1251771 kernel: [945074.766834] [UFW BLOCK] IN=eth0 OUT= MAC=40: ...
show more
2026-06-11T08:44:04.461605-03:00 srv1251771 kernel: [945074.766834] [UFW BLOCK] IN=eth0 OUT= MAC=40:e8:d4:b8:29:bb:44:38:39:ff:ff:41:08:00 SRC=162.158.63.101 DST=72.61.36.27 LEN=60 TOS=0x00 PREC=0x00 TTL=52 ID=26525 DF PROTO=TCP SPT=14206 DPT=8443 WINDOW=65535 RES=0x00 SYN URGP=0
2026-06-11T08:44:05.467178-03:00 srv1251771 kernel: [945075.772396] [UFW BLOCK] IN=eth0 OUT= MAC=40:e8:d4:b8:29:bb:44:38:39:ff:ff:41:08:00 SRC=162.158.63.101 DST=72.61.36.27 LEN=60 TOS=0x00 PREC=0x00 TTL=52 ID=26526 DF PROTO=TCP SPT=14206 DPT=8443 WINDOW=65535 RES=0x00 SYN URGP=0
2026-06-11T08:44:06.491145-03:00 srv1251771 kernel: [945076.796361] [UFW BLOCK] IN=eth0 OUT= MAC=40:e8:d4:b8:29:bb:44:38:39:ff:ff:41:08:00 SRC=162.158.63.101 DST=72.61.36.27 LEN=60 TOS=0x00 PREC=0x00 TTL=52 ID=26527 DF PROTO=TCP SPT=14206 DPT=8443 WINDOW=65535 RES=0x00 SYN URGP=0
...
show less
Port Scan
๐บ๐ธ
freeutka
2026-05-11 10:16:17
(1 month ago)
WordPress brute-force login attempt on wp-login.php.
Brute-Force
Web App Attack
๐บ๐ธ
freeutka
2026-05-05 00:59:00
(1 month ago)
WordPress brute-force login attempt on wp-login.php.
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-04-20 22:03:44
(1 month ago)
Auto-ban: >3000 req/min op 2026-04-20
Web App Attack
SSH
Hacking
๐บ๐ธ
wimaxnz
2026-04-19 05:28:41
(1 month ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
Anonymous
2026-04-17 12:16:11
(2 months ago)
Web App Attack
Brute-Force
Web App Attack
๐บ๐ธ
octageeks.com
2026-03-30 04:09:50
(2 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 05:53:47
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 01:53:41.851779 2026] [security2:error] [pid 2002:tid 2002] [client 162.158.63.101:14119] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.styxwamworld.com"] [uri "/.env.backup"] [unique_id "ab4yZSelcBKkKfJd8ZQBFQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 02:51:31
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 22:51:27.010237 2026] [security2:error] [pid 12738:tid 12738] [client 162.158.63.101:12674] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jmms.mx"] [uri "/core/.env"] [unique_id "ab4Hr_Lht9EjGEkBjqFdJAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 01:48:17
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 21:48:10.789988 2026] [security2:error] [pid 19332:tid 19332] [client 162.158.63.101:12484] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eta-mct.com"] [uri "/.env.save"] [unique_id "ab342nKgjVl3ngzPv7oNnwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 08:41:39
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 04:41:32.581992 2026] [security2:error] [pid 21283:tid 21283] [client 162.158.63.101:10930] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stormstrips.stormstrips.com"] [uri "/config/.env"] [unique_id "ab0IPFhArcxbF4Ulm4yGKQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 08:20:19
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 04:20:15.550292 2026] [security2:error] [pid 14743:tid 14743] [client 162.158.63.101:10785] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.indigo17.com"] [uri "/private/.env"] [unique_id "ab0DP0pgyIkHMyzQ9L8wdgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 07:23:00
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 03:22:52.747792 2026] [security2:error] [pid 8356:tid 8356] [client 162.158.63.101:9744] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.dunnretired.com"] [uri "/.env_secret"] [unique_id "abz1zKYTFLy_JuAoAFKFYQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 01:14:52
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 21:14:47.832391 2026] [security2:error] [pid 12255:tid 12317] [client 162.158.63.101:12731] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.store.stonyp.com"] [uri "/.env.orig"] [unique_id "abyfhyac-Mrg0fXnzQBzUwAAAdU"]
show less
Brute-Force
Bad Web Bot
Web App Attack