πΊπΈ
mawan
2026-05-23 13:01:58
(2 weeks ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
πΊπΈ
mawan
2026-05-22 01:24:26
(2 weeks ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
Anonymous
2026-03-30 23:00:00
(2 months ago)
Aggressive web scan
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-21 04:41:54
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 00:41:45.712845 2026] [security2:error] [pid 18123:tid 18123] [client 162.158.63.12:11262] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sellingcarshandbook.com"] [uri "/.env.json"] [unique_id "ab4hiZlQTxPwC71PSI9DiwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-21 00:52:32
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 20:52:23.271911 2026] [security2:error] [pid 30575:tid 30575] [client 162.158.63.12:10935] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.thenolangroup.llc"] [uri "/.env.save"] [unique_id "ab3rxxtrVF64tfmIfAS5hAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 06:56:23
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 02:56:17.217728 2026] [security2:error] [pid 25460:tid 25460] [client 162.158.63.12:12198] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.monmouthbottleshop.com"] [uri "/.env.local.backup"] [unique_id "abzvkcieyrdgIlIus039WAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 02:12:55
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 22:12:50.937704 2026] [security2:error] [pid 3043:tid 3043] [client 162.158.63.12:12433] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.globalhotels.com.co"] [uri "/.env.tmp"] [unique_id "abytIl9gVK6LMoH86pFPZAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-19 10:10:44
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 06:10:39.237822 2026] [security2:error] [pid 32272:tid 32272] [client 162.158.63.12:13083] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.vanemby.com"] [uri "/.env_secret"] [unique_id "abvLn_GHjIDoeUHCr8QY7AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-19 09:26:39
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 05:26:34.457145 2026] [security2:error] [pid 416:tid 529] [client 162.158.63.12:12475] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chaoticperception.cynosureinternetservices.com"] [uri "/.git/logs/HEAD"] [unique_id "abvBSj024X2TifNHRk73GgAAAhU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-19 09:03:04
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 05:02:57.275266 2026] [security2:error] [pid 29437:tid 29437] [client 162.158.63.12:14050] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.presucad.com"] [uri "/.env.docker"] [unique_id "abu7wTotRmZHQ5Xp1DGbAwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-19 08:41:34
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 04:41:28.773016 2026] [security2:error] [pid 10562:tid 10562] [client 162.158.63.12:9538] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.entertainer-review.com.exotic-dancers-los-angeles.com"] [uri "/.env.local.backup"] [unique_id "abu2uAqc2wLZQFqQRuR4GwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-19 08:01:01
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 04:00:51.312592 2026] [security2:error] [pid 3495:tid 3495] [client 162.158.63.12:9517] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ikutabukkyokai.com"] [uri "/private/.env"] [unique_id "abutMxH1TJbK-Yvw-m3r_gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-18 23:08:26
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 18 19:08:18.633024 2026] [security2:error] [pid 8124:tid 8124] [client 162.158.63.12:11484] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.weddingcakenapkins.com"] [uri "/.env.json"] [unique_id "abswYtDQ-Fnwflnx5kbdfwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-18 14:44:08
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 18 10:43:59.905038 2026] [security2:error] [pid 20928:tid 20928] [client 162.158.63.12:9638] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.gregdember.com"] [uri "/site/.env"] [unique_id "abq6Ly5W7awjnCQHPkjUnAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
octageeks.com
2025-07-25 04:14:22
(10 months ago)
Wordpress malicious attack:[octaxmlrpc]
Web App Attack