๐ง๐ช
madeit
2026-08-23 02:34:03
(2 days ago)
Web App Attack
๐ฌ๐ง
OptimusGO
2026-08-01 08:22:22
(3 weeks ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-08-01 09:22:22 UTC
Log evidence:
08/01/2026-09:22:18.684702 [**] [1:1000103:1] SECURITY Management Port Probe - CRITICAL [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 162.158.63.148:9291 -> 185.127.18.66:8443
show less
Port Scan
Brute-Force
๐บ๐ธ
octageeks.com
2026-03-31 04:09:19
(4 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 06:15:52
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.148 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 02:15:46.691407 2026] [security2:error] [pid 4084991:tid 4084991] [client 162.158.63.148:10114] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.nagareinkpaper.com"] [uri "/.env.development"] [unique_id "ab43kgOcNFZvUYduZXvutQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 03:33:54
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.148 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 23:33:49.064007 2026] [security2:error] [pid 2347:tid 2347] [client 162.158.63.148:13238] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.farmers123.com"] [uri "/.env_config"] [unique_id "ab4RnS-VqeGblnsJYQZi3AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 02:12:44
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.148 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 22:12:36.081698 2026] [security2:error] [pid 2987:tid 2987] [client 162.158.63.148:11393] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.scrood.fm"] [uri "/config/.env"] [unique_id "ab3-lJSRXAv2c8ZuHjm5DgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 00:38:34
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.148 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 20:38:06.436231 2026] [security2:error] [pid 17079:tid 17079] [client 162.158.63.148:13085] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.st-johns.us"] [uri "/server/.env"] [unique_id "abyW7gml67-dyO3jUyotTgAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 08:36:57
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.148 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 04:36:53.767298 2026] [security2:error] [pid 22829:tid 22829] [client 162.158.63.148:14005] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.anayjosecollectionclub.com"] [uri "/.env.production.bak"] [unique_id "abu1pdzPuz7ea5l4OsLo3gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 07:32:49
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.148 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 03:32:39.300977 2026] [security2:error] [pid 4044:tid 4044] [client 162.158.63.148:11113] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.luxievintage.com"] [uri "/.env.php"] [unique_id "abumlwhF5Y76mcGIm2FMzQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 07:06:28
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.148 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 03:06:21.918176 2026] [security2:error] [pid 416:tid 524] [client 162.158.63.148:10710] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "denverdermatologist.aafm.us"] [uri "/admin/.env"] [unique_id "abugbT024X2TifNHRk7sVgAAAhA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 03:03:22
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.148 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 18 23:03:16.171348 2026] [security2:error] [pid 18564:tid 18564] [client 162.158.63.148:13056] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "guitarwisdom.benshermanguitar.com"] [uri "/.env.production"] [unique_id "abtndL8ISq_640y0qZzXCwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-18 14:43:03
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.148 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 18 10:42:58.817074 2026] [security2:error] [pid 24381:tid 24381] [client 162.158.63.148:14020] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.gregdember.com"] [uri "/.env.tmp"] [unique_id "abq58tfJlXN_9cLinViKkAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
HJ5Ss4Ju
2023-02-24 08:11:01
(3 years ago)
WordPress XMLRPC scan :: 162.158.63.148 - - [24/Feb/2023:08:11:01 0000] "GET /xmlrpc.php?rsd HTTP/1 ...
show more
WordPress XMLRPC scan :: 162.158.63.148 - - [24/Feb/2023:08:11:01 0000] "GET /xmlrpc.php?rsd HTTP/1.1" 200 322 "https://www.[censored_1]/knowledge-base/html/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36 Vivaldi/5.3.2679.68"
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
HJ5Ss4Ju
2023-02-23 01:34:31
(3 years ago)
WordPress XMLRPC scan :: 162.158.63.148 - - [23/Feb/2023:01:34:30 0000] "POST /xmlrpc.php HTTP/1.1" ...
show more
WordPress XMLRPC scan :: 162.158.63.148 - - [23/Feb/2023:01:34:30 0000] "POST /xmlrpc.php HTTP/1.1" 503 18968 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:96.0) Gecko/20100101 Firefox/96"
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
HJ5Ss4Ju
2023-02-14 06:04:09
(3 years ago)
WordPress XMLRPC scan :: 162.158.63.148 - - [14/Feb/2023:06:04:08 0000] "POST /xmlrpc.php HTTP/1.1" ...
show more
WordPress XMLRPC scan :: 162.158.63.148 - - [14/Feb/2023:06:04:08 0000] "POST /xmlrpc.php HTTP/1.1" 503 18968 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:96.0) Gecko/20100101 Firefox/96"
show less
Hacking
Brute-Force
Web App Attack