Anonymous
2026-06-07 14:05:57
(2 days ago)
Web App Attack
πΊπΈ
drewf.ink
2026-06-07 03:31:54
(2 days ago)
[03:31] Port scanning. Port(s) scanned: TCP/2086
Port Scan
π΅π±
IROK
2026-04-02 09:51:32
(2 months ago)
Malware/WebShell Scan blocked by ModSecurity
...
Hacking
πΊπΈ
TPI-Abuse
2026-03-20 05:35:11
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.150 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 01:35:04.770895 2026] [security2:error] [pid 4876:tid 4876] [client 162.158.63.150:13755] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.wickliffehof.org"] [uri "/.env.development"] [unique_id "abzciDhrfr37EF_xIBlNzQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 05:13:03
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.150 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 01:12:58.592159 2026] [security2:error] [pid 8591:tid 8591] [client 162.158.63.150:11144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.nowell.net"] [uri "/.env.dist"] [unique_id "abzXWjfeEqy4WAdb3qPKOgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 03:13:59
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.150 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 23:13:54.047128 2026] [security2:error] [pid 6275:tid 6275] [client 162.158.63.150:11067] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thectegroup.chapa.net"] [uri "/.env.test"] [unique_id "aby7cknNSQ6o8fwpA1-A-QAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-19 11:38:48
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.150 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:38:41.669316 2026] [security2:error] [pid 15635:tid 15635] [client 162.158.63.150:11180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.moonlightmotel.com"] [uri "/web/.env"] [unique_id "abvgQVV7bzSPmD0RJVw09QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-19 11:13:16
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.150 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:13:08.494733 2026] [security2:error] [pid 30861:tid 30861] [client 162.158.63.150:9748] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.belgiophar.com"] [uri "/.env~"] [unique_id "abvaRB3lXSaPcH12dF0KrgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-19 09:15:56
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.150 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 05:15:50.801611 2026] [security2:error] [pid 18871:tid 18871] [client 162.158.63.150:9619] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.actionrev.mainstreetofficesuites.com"] [uri "/.env.staging"] [unique_id "abu-xq3Z7Y0ToC1eeSzw2gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-19 08:43:23
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.150 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 04:43:13.975079 2026] [security2:error] [pid 17874:tid 17874] [client 162.158.63.150:9949] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.celebrationofmike.com"] [uri "/config/.env.local"] [unique_id "abu3IZgInAgCurr0B4iXAAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-19 07:18:53
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.150 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 03:18:45.808327 2026] [security2:error] [pid 3710:tid 3710] [client 162.158.63.150:11905] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.knoxbestos.com"] [uri "/.env_secret"] [unique_id "abujVU58vS_iKMk3U7PGuwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-18 14:50:45
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.150 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 18 10:50:28.138765 2026] [security2:error] [pid 32214:tid 32219] [client 162.158.63.150:14013] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "certifiedfinancialmanager.aafm.us"] [uri "/.env_backup"] [unique_id "abq7tJ4dCihpmZilkBIK0QAAAQI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-18 13:42:41
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.150 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 18 09:42:36.981802 2026] [security2:error] [pid 6445:tid 6445] [client 162.158.63.150:9480] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.imprintednapkins.com"] [uri "/api/.env"] [unique_id "abqrzB2Ew0xxMl4OAFEciwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-18 13:11:23
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.150 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 18 09:11:12.697747 2026] [security2:error] [pid 14644:tid 14644] [client 162.158.63.150:14254] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abq4you.com"] [uri "/.env2"] [unique_id "abqkcChTtbRSiSQLUyTA3QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
wimaxnz
2026-02-28 00:18:19
(3 months ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan