Anonymous
2026-06-03 22:55:11
(2 days ago)
Bad Request a3cc8ee9
Port Scan
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
Ivan Rezinkin
2026-05-25 12:22:11
(1 week ago)
DDoS attack against sub.cocooloco.ru (181.214.231.116) - L7 connection flood, observed sustained SYN ...
show more
DDoS attack against sub.cocooloco.ru (181.214.231.116) - L7 connection flood, observed sustained SYN traffic causing TCP listen-queue overflow. Auto-banned at 5/sec threshold via iptables hashlimit. Timestamp: 2026-05-25T12:21:02Z
show less
DDoS Attack
Email Spam
๐บ๐ธ
TPI-Abuse
2026-05-15 12:42:22
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 162.158.63.165 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.63.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 08:42:18.138660 2026] [security2:error] [pid 20794:tid 20794] [client 162.158.63.165:11541] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vittaria.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vittaria.com"] [uri "/db_backup.sql"] [unique_id "agcUquXggGBbuZkJqnPSiAAAAA8"], referer: https://www.google.com/search?q=vittaria.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-06 09:19:55
(1 month ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ต๐ฑ
IROK
2026-03-31 04:04:49
(2 months ago)
Malware/WebShell Scan blocked by ModSecurity
...
Hacking
๐ฆ๐บ
oncord
2026-03-30 17:24:36
(2 months ago)
Form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2026-03-21 06:22:04
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.165 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 02:21:56.787626 2026] [security2:error] [pid 4087476:tid 4087476] [client 162.158.63.165:11296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.nagareinkpaper.com"] [uri "/.env.bak"] [unique_id "ab45BDLkGSajmzgbAeN97wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 04:25:58
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.165 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 00:25:51.827268 2026] [security2:error] [pid 9547:tid 9547] [client 162.158.63.165:13395] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.onlinesoldier.com"] [uri "/srv/.env"] [unique_id "ab4dz6d1DZufxwalHfhBCQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 07:46:30
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.165 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 03:46:25.548321 2026] [security2:error] [pid 19459:tid 19459] [client 162.158.63.165:13033] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.jchiggins.com"] [uri "/.env.prod"] [unique_id "abz7UcKYTWqODjT2lC_DnQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 06:35:12
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.165 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 02:35:06.283927 2026] [security2:error] [pid 26617:tid 26617] [client 162.158.63.165:12721] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mobresearchinc.markthwaite.com"] [uri "/.env.production"] [unique_id "abzqmpX8OIbmjXNlAhKD3QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 04:12:39
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.165 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 00:12:34.204707 2026] [security2:error] [pid 27469:tid 27469] [client 162.158.63.165:11076] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.gkwire.com"] [uri "/.env.example"] [unique_id "abzJMlsQ1RUSm0iIfNx47QAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 03:32:59
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.165 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 23:32:55.359749 2026] [security2:error] [pid 17136:tid 17136] [client 162.158.63.165:12787] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.lovelybeyondwords.com"] [uri "/.env_settings"] [unique_id "aby_5xHcV87N9BVLDwiYKQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 02:54:29
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.165 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 22:54:21.535820 2026] [security2:error] [pid 18013:tid 18013] [client 162.158.63.165:10280] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.darrow.biz"] [uri "/.env2"] [unique_id "aby23UvN8mhZstGha3bupwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 01:15:43
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.165 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 21:15:36.367985 2026] [security2:error] [pid 20170:tid 20170] [client 162.158.63.165:10231] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.bronislawsuchanek.com"] [uri "/site/.env"] [unique_id "abyfuJrziiDjbBjix_w_mgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 00:26:36
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.165 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 20:26:28.471912 2026] [security2:error] [pid 29967:tid 29967] [client 162.158.63.165:14140] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "assembliesofgodinsamoa.org"] [uri "/.git/refs/heads/master"] [unique_id "abyUNIeKJNXqdy8CHqcpfgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack